Forum Discussion
Passkey best practices for Windows 365 users on unmanaged devices (BYOD)?
Treat Cloud PC access and passkey use inside the Cloud PC as separate rollout paths. Start with a pilot contractor group, enable passkeys for that group in the Entra authentication methods policy, and use a Temporary Access Pass to bootstrap registration when users lack a strong method. For personal devices, decide whether you accept a device-bound passkey on the contractor’s device; otherwise issue organization-controlled FIDO2 security keys. Before requiring phishing-resistant authentication, verify that the Windows App versions and host platforms complete the initial Cloud PC sign-in. Then test WebAuthn redirection inside the session, because in-session passkey use depends on the client, redirection configuration, and target application. Keep a recovery method during migration and do not remove MFA until both stages work. Finally, apply a Conditional Access authentication-strength requirement to the pilot, monitor sign-in logs, expand gradually, and retain protected emergency administrator accounts outside the contractor policy.