How to Configure Passkeys in Microsoft Entra ID
Add Your Seedkeeper PRO as a Security Key to Your Work or School Account
Mobile and Web
From your Microsoft Entra Security info page, add a new sign-in method, choose Security key, then register your Seedkeeper PRO as a FIDO2 passkey.
Overview
Microsoft Entra ID (formerly Azure AD) is Microsoft's identity platform for work and school accounts - different from a personal Microsoft/Outlook account. Organizations use it to manage sign-in and security policies for their users. If your employer or school uses Entra ID, you can register your Seedkeeper PRO as a FIDO2 security key the same way you would a passkey on any personal account.
This guide covers adding a security key to your own Entra ID account. If you're an IT admin looking to roll out FIDO2 security keys across an organization, see Deploying FIDO2 Passkeys via Microsoft Entra ID instead.
Prerequisites
- Your organization's admin must have enabled the Passkey (FIDO2) authentication method in the Microsoft Entra admin center.
- Self-service registration must be allowed for your account.
If either of these isn't enabled, check with your IT admin - see Deploying FIDO2 Passkeys via Microsoft Entra ID for what that setup looks like on their end.
The default your browser offers - Face ID, Touch ID, Windows Hello, or a synced credential manager - creates a perfectly valid passkey.
Choosing your Seedkeeper PRO instead changes three things:
- The key exists in one place only. A synced passkey is copied across every device on your cloud account, and that account is usually protected by a password. A hardware passkey is generated inside a certified secure element and physically cannot leave it.
- Nobody else is in the chain. No provider account, no cloud, no vendor login standing between you and your own credentials.
- It travels. The same card or ring works on your phone, your laptop, and a machine that isn't yours - a work computer, a shared workstation - leaving nothing behind.
See "Not All Passkeys Are Stored the Same Way" for the full comparison.
Step-by-Step Instructions
Step 1: Open your Security info page
Go to your Microsoft Entra Security info page in a web browser.
Step 2: Sign in
Sign in using your current authentication method (password, MFA, etc.).
Step 3: Add a sign-in method
Click Add method (or Add sign-in method).
Step 4: Choose Security key
Select Security key (or Passkey) from the dropdown.
Step 5: Continue
Click Add or Next.
Step 6: Connect your Seedkeeper PRO
Insert your Seedkeeper PRO if using a contact reader, or tap it against an NFC reader.
Step 7: Set or enter your PIN
Follow the on-screen prompts to set up (or enter) your passkey PIN, then confirm with a physical touch on your device.
Step 8: Name your key
Give your key a descriptive name so you can recognize it later, then finish the registration.
Your Seedkeeper PRO is now registered as a security key on your Microsoft Entra ID account.
Official Microsoft Resources
- Register a passkey with a security key
- Set up a security key as your verification method
- Sign in to your account with a security key
FAQ
What if I don't see the Security key option?
Your admin may not have enabled the Passkey (FIDO2) method yet, or self-service registration may be turned off. See Prerequisites above.
Is this the same as a personal Microsoft/Outlook account passkey?
No - Entra ID is for work or school accounts, managed by your organization. See the Overview above.
I'm an admin - how do I roll this out to my whole organization?
Why register a Seedkeeper PRO instead of my phone's built-in passkey?
Both defeat phishing, so the honest answer is that it depends what the account is worth. A synced passkey is copied to every device on your cloud account, and that account is the new target. A Seedkeeper PRO passkey exists on one certified chip that cannot export it, with no provider in the chain - which matters when the account guards your organisation systems. See Not All Passkeys Are Stored the Same Way.