Forum Discussion

CharlieAD's avatar
CharlieAD
Tin Contributor
Jul 22, 2026

Passkey best practices for Windows 365 users on unmanaged devices (BYOD)?

I have global contractors who work from home so spinning up Windows 365 Enterprise Cloud PCs are ideal.  The contractors work from from either their personal Mac or personal Windows PC using the Microsoft Windows app so each user can access their dedicated Windows 365 Cloud PC and everything has been working well so far using standard MFA.  We are looking to move everyone to passkeys but there is no intuitive documentation on how end users are expected to adopt it so they can use passkeys to 1) access the virtual PC and then use passkeys while in the virtual PC itself.  Seems Microsoft explains everything under the hood except how to practically roll it out to reliably replace standard MFA.  What is the recommended path forward to migrate my BYOD virtual PC users to passkeys? 

Thanks,

Charlie

 

1 Reply

  • Treat Cloud PC access and passkey use inside the Cloud PC as separate rollout paths. Start with a pilot contractor group, enable passkeys for that group in the Entra authentication methods policy, and use a Temporary Access Pass to bootstrap registration when users lack a strong method. For personal devices, decide whether you accept a device-bound passkey on the contractor’s device; otherwise issue organization-controlled FIDO2 security keys. Before requiring phishing-resistant authentication, verify that the Windows App versions and host platforms complete the initial Cloud PC sign-in. Then test WebAuthn redirection inside the session, because in-session passkey use depends on the client, redirection configuration, and target application. Keep a recovery method during migration and do not remove MFA until both stages work. Finally, apply a Conditional Access authentication-strength requirement to the pilot, monitor sign-in logs, expand gradually, and retain protected emergency administrator accounts outside the contractor policy.