We currently use Microsoft's default passkey configuration, supporting both synced and device-bound passkeys without attestation. I'm trying to work out whether we should create different authentication strengths and passkey policies for different user groups.
For highly privileged administrators, I'm considering attested YubiKey flows, Microsoft Authenticator on iOS and Android, or a one-time Temporary Access Pass. For other administrators, staff, and guests, I'm considering Windows Hello, Microsoft Authenticator, Temporary Access Pass, or password plus Authenticator push notifications.
Users may have both an iCloud Keychain passkey and a Windows or Microsoft Authenticator passkey, so I'm also wondering whether synced and attested/device-bound passkeys can coexist under separate policies.
My understanding is that I would target passkey or FIDO2 policies to the appropriate groups, then use Conditional Access policies with authentication strengths tailored to each user type. Is that the correct model? For a company with fewer than 15 users, is this level of separation worthwhile, or would a simpler setup provide enough security without creating unnecessary administrative work?
2 Answers
The general approach is sound, but the design is probably more complex than necessary for a 15-person organization. Synced passkeys are generally suitable for ordinary staff and guest accounts, while highly privileged accounts should use phishing-resistant, device-bound credentials such as properly managed security keys. You still need Conditional Access for enforcement, but authentication strengths and system-preferred authentication can usually handle the selection without creating a large number of overlapping policies.
This sounds like overengineering for such a small environment. Start with a simple baseline: require phishing-resistant authentication for privileged administrators, use passkeys or Authenticator for everyone else, keep strong recovery methods available, and apply the policies to clearly defined groups. Add attestation or separate authentication strengths only if you have a specific compliance or risk requirement that justifies the extra maintenance.

So the practical split would be synced passkeys for staff, guests, and less-privileged administrators, with device-bound or attested keys reserved for the most privileged accounts?