Microsoft's Passkey Push Needs Better Ecosystem Support
Microsoft made a big passkeys announcement: later this year, passkeys will become the default authentication experience for Entra. This makes sense, while passkeys do have some downsides, approaches like it are the future of secure access to resources.
However, one of the biggest downsides of passkeys is inflexibility in how to use them. Unlike passwords that 𝗰𝗮𝗻 but 𝘀𝗵𝗼𝘂𝗹𝗱 𝗻𝗼𝘁 𝗯𝗲 written on a Post-It under your keyboard, passkeys require a hardware device or app to manage them. Using a passkey does not work by just sending off a fixed value into a password field, they are a unique calculated response based on a challenge sent to your device from the resource you are trying to access.
Back in November 2025, Microsoft made another big passkeys announcement. They were opening up access to the native passkeys management interface in Windows so that third-party password managers with passkey capabilities could become passkey providers for Windows. Major password managers 1Password and Bitwarden were announced as launch partners.
There are two reasons I think this is important, one to do with how we use passkeys, and one to do with how they secure systems.
First, creating passkeys is easy, but managing them is a bit of mess. Passkeys initially were device-bound and not portable. Synced passkeys has fixed this, but still your ability to use a passkey created in one place somewhere else is entirely dependent on what the service holding that synced passkey can plug into.
Second, as AI and other technologies increasingly push many users onto cloud-based VMs or services like W365, managing credentials on remote devices becomes more important. Microsoft's Windows app can drive passkey authentication to remote systems directly from the local device, but only to the extent that Windows is able to access those passkeys locally. Your password manager in Edge isn't much help to that use case, and you 𝗱𝗼 𝗻𝗼𝘁 want your password vault in the instance of Edge your agent is using.
It is very disappointing that more than half a year later, the only provider that has adopted this Windows-based passkey integration is 1Password. Bitwarden's efforts seem to have stalled. Microsoft's own passkey management through Authenticator or MSPM in Edge haven't been upgraded to make use of this tooling (though there is a blog that says it's coming soon and progress for MSAs). And other major providers like Apple or Google are conspicuously absent.
There are other approaches that make passkeys easier. The QR-code-based login flow that relies on a phone-based passkey manager is the one I've adopted the most. But compared to Windows own in-built passkeys protected behind Windows Hello, it is clunky.
I'm all for the advance of passkeys. I just think that within the Microsoft ecosystem there's more to making this a truly pleasant usage experience than making it the default approach in Entra.
Am I missing something? It seems harder than it should be.
First posted on Linkedin on 07/27/2026 → View Linkedin Post Here