Our company recently began receiving Microsoft passkey enrollment prompts, and the rollout messaging has created a lot of confusion. We originally understood that employees using the Microsoft Authenticator app could bypass passkey setup, while users relying on SMS or other methods would be required to enroll. However, some people who only use Authenticator are still being prompted to create a PIN, and the prompts seem increasingly difficult to dismiss.
My understanding is that Windows Hello may require a local PIN, fingerprint, facial recognition, or security key to protect a passkey stored on the device. Users may still be able to choose "Sign-in options" and select a password or another method, but it is unclear whether that will remain available or whether the organization's authentication policies are forcing enrollment.
Can someone clarify what triggers these prompts, whether Authenticator users can actually avoid passkey enrollment, and how Windows Hello, Authenticator, SMS, and FIDO2 security keys differ in this situation? We need to explain the process clearly to nontechnical staff before the help desk gets overwhelmed.
4 Answers
The PIN is usually not a new cloud password. Windows Hello uses the PIN, fingerprint, or face unlock to protect a credential stored locally on that particular computer. Edge or another passkey provider may also require a PIN the first time it creates or stores a passkey. Once configured, the user normally unlocks the credential with that local method rather than typing the PIN as their Microsoft account password.
The prompt does not necessarily mean that everyone must immediately use a passkey to sign in. Microsoft can prompt users to register one based on the authentication methods allowed or enabled on their account. SMS and voice registration appear to be important triggers, even if the person rarely or never uses them. Tenant policies, rollout settings, and device eligibility can also affect who sees the prompt, so there may not be one universal answer for every organization.
That is why simply saying “Authenticator users can bypass it” is risky. You need to check which methods are registered and what passkey registration or authentication policies are enabled for the tenant.
A regular Authenticator approval or number match is not automatically a passkey. It is another form of multifactor authentication. Authenticator can also store a passkey on supported devices, but that has to be configured separately. SMS, ordinary passwords, and standard Authenticator approvals are generally not phishing-resistant in the same way as Windows Hello for Business, a FIDO2 security key, or a passkey stored in a supported authenticator or password manager.
Before sending another announcement, check the actual Entra authentication-method, passkey, registration campaign, and Windows Hello for Business policies, along with each user’s registered methods. Test with accounts that have only Authenticator, Authenticator plus SMS, and a FIDO2 key. Then state separately whether enrollment is being requested, whether passkey use is required, and which fallback methods will remain available. Those are different questions, and combining them is what makes the rollout sound contradictory.

If Windows Hello for Business is required by device or domain policy, employees may be forced to create the PIN before they can use that sign-in method. A “use another method” or password option might still appear, but policy can determine whether it remains available.