Reviewed by Brian Kinane · SetupPasskeys product author · 16 August 2026
Samsung Pass with Microsoft Entra passkeys
Samsung's current UK support guidance describes a Samsung Pass passkey as stored only on the Galaxy device in encrypted storage. Treat this rollout path as device-bound: a replacement phone needs a fresh registration. Samsung's regional documentation is not fully consistent, so validate the exact Galaxy model, One UI version and Samsung Pass build during the pilot.
What users need
A supported Samsung Galaxy device running One UI 6 or later, a Samsung account, a screen lock and Samsung Pass configured with biometrics. Device and software support should be confirmed during the pilot.
Entra configuration
Enable passkeys (FIDO2) for a pilot group. If the passkey policy restricts authenticators, confirm the provider metadata and AAGUID before adding it to an allow-list. Test the full registration and sign-in path rather than relying on the provider name alone.
Conditional Access
Use an authentication strength that requires phishing-resistant MFA. Create the policy in report-only mode, target all resources, and exclude emergency access accounts before evaluating impact.
User communication
Tell Galaxy users exactly which provider to choose. Microsoft’s current Entra support table excludes Google Password Manager on Samsung devices, so its appearance in a picker is not proof that it is a supported work-passkey route. Use Microsoft Authenticator or Samsung Pass only when the organisation’s passkey policy and device pilot approve that route. Before a device-bound passkey becomes unavailable, register a tested recovery method or approved replacement.
Sources: Microsoft’s supported synced-passkey provider table and Samsung's passkey guidance for Samsung Pass. Because Samsung publishes different wording in some regions, the pilot result is the authority for your supported device baseline.
Related: passkey troubleshooting.