Skip to main content

How to Configure Passkeys in Microsoft Entra ID

Add Your Seedkeeper PRO as a Security Key to Your Work or School Account

Mobile and Web

From your Microsoft Entra Security info page, add a new sign-in method, choose Security key, then register your Seedkeeper PRO as a FIDO2 passkey.

Overview

Microsoft Entra ID (formerly Azure AD) is Microsoft's identity platform for work and school accounts - different from a personal Microsoft/Outlook account. Organizations use it to manage sign-in and security policies for their users. If your employer or school uses Entra ID, you can register your Seedkeeper PRO as a FIDO2 security key the same way you would a passkey on any personal account.

This covers your own account

This guide covers adding a security key to your own Entra ID account. If you're an IT admin looking to roll out FIDO2 security keys across an organization, see Deploying FIDO2 Passkeys via Microsoft Entra ID instead.

Prerequisites

If either of these isn't enabled, check with your IT admin - see Deploying FIDO2 Passkeys via Microsoft Entra ID for what that setup looks like on their end.

Why choose the security key option?

The default your browser offers - Face ID, Touch ID, Windows Hello, or a synced credential manager - creates a perfectly valid passkey.

Choosing your Seedkeeper PRO instead changes three things:

  • The key exists in one place only. A synced passkey is copied across every device on your cloud account, and that account is usually protected by a password. A hardware passkey is generated inside a certified secure element and physically cannot leave it.
  • Nobody else is in the chain. No provider account, no cloud, no vendor login standing between you and your own credentials.
  • It travels. The same card or ring works on your phone, your laptop, and a machine that isn't yours - a work computer, a shared workstation - leaving nothing behind.

See "Not All Passkeys Are Stored the Same Way" for the full comparison.

Step-by-Step Instructions

Step 1: Open your Security info page

Go to your Microsoft Entra Security info page in a web browser.

Step 2: Sign in

Sign in using your current authentication method (password, MFA, etc.).

Step 3: Add a sign-in method

Click Add method (or Add sign-in method).

Step 4: Choose Security key

Select Security key (or Passkey) from the dropdown.

Step 5: Continue

Click Add or Next.

Step 6: Connect your Seedkeeper PRO

Insert your Seedkeeper PRO if using a contact reader, or tap it against an NFC reader.

Step 7: Set or enter your PIN

Follow the on-screen prompts to set up (or enter) your passkey PIN, then confirm with a physical touch on your device.

Step 8: Name your key

Give your key a descriptive name so you can recognize it later, then finish the registration.

Your Seedkeeper PRO is now registered as a security key on your Microsoft Entra ID account.

Official Microsoft Resources

FAQ

What if I don't see the Security key option?

Your admin may not have enabled the Passkey (FIDO2) method yet, or self-service registration may be turned off. See Prerequisites above.

Is this the same as a personal Microsoft/Outlook account passkey?

No - Entra ID is for work or school accounts, managed by your organization. See the Overview above.

I'm an admin - how do I roll this out to my whole organization?
Why register a Seedkeeper PRO instead of my phone's built-in passkey?

Both defeat phishing, so the honest answer is that it depends what the account is worth. A synced passkey is copied to every device on your cloud account, and that account is the new target. A Seedkeeper PRO passkey exists on one certified chip that cannot export it, with no provider in the chain - which matters when the account guards your organisation systems. See Not All Passkeys Are Stored the Same Way.