A passkey tied to one physical device, such as a FIDO2 security key or Microsoft Authenticator, which generates its private key and never lets it leave. Synced passkeys work differently, with a passkey provider copying them from device to device.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Device-bound passkey in context, with comparison tables and the common traps.
Terms in this definition
- Passkey
A passwordless sign-in credential based on FIDO that resists phishing. The private half of the key pair never leaves the person's device or hardware key, while the website or app stores just the public half; a passkey may be synced across devices or tied to a single one.
- Physical
Describes the concrete, real-world parts that put a logical architecture into effect.
- FIDO2 security key
Passwordless hardware authenticator that resists phishing. Push-based methods show a number to match and the sign-in location; this one shows neither.
- Microsoft Authenticator
App for mobile devices offering one-time codes, push notifications that use number matching, and passwordless sign-in by phone.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Provider
The organisation that shares data in OpenSharing. Recipients also see a provider as a Unity Catalog securable, from which shares can be mounted as catalogs.