
[E 5] Passkeys, WHfB, and Phishing-Resistant Credentials
A small portfolio of phishing-resistant credentials, held one device-bound and one portable, chosen deliberately.

A small portfolio of phishing-resistant credentials, held one device-bound and one portable, chosen deliberately.

Authentication is becoming a ranking the system enforces, steering every user to their strongest credential and asking for the password only when nothing better exists. One policy, system-preferred authentication, registration as the real work, and retiring the weak on purpose.

The shape of a directory is decided before the first policy and ages badly when improvised. One tenant or several, the population-versus-entitlement group model, and the restricted management administrative unit that protects your core from your own administrators.

Every account arrived from somewhere, and where it came from decides where you can change it. Source of authority, the three origins of an identity, the Connect-Sync-to-Cloud-Sync transition now underway, and the slow migration of authority to the cloud.

Microsoft has moved the Entra ID security baseline from recommendations you implement to a floor it enforces. Getting started in 2026 is knowing what is already switched on, and deciding everything the floor does not: privilege, structure, break-glass done the new way, and access that expires.

An Entra-joined device signs in without a domain controller, but opening a file share is a different transaction. How cloud Kerberos trust exchanges a partial ticket for a full one, what it needs, where line of sight actually matters, and what it will never solve.

The tenant-wide Windows Hello toggle only fires at enrollment, cannot be scoped, and does nothing to devices you already manage. The controlled rollout uses targeted policy, device rings, and an understanding of which settings you genuinely cannot gate per user.

The Conditional Access framework leans on phishing-resistant credentials in every tier. This is the design paper for the credential itself: what Windows Hello for Business actually is, the trust decision most tenants do not need to make, and where it sits in a passkey world.