Environment Setup Overview
Choose the environment setup that matches your domain and device architecture. This page explains the two supported environment types for deploying Enterprise Passkey with HYPR Passkey.
Important: Core Enterprise Passkey Setup is the Same
The core Enterprise Passkey setup process is identical for both Entra-only and Hybrid environments. Both require:
- Microsoft Entra ID tenant with verified domains and users
- HYPR Control Center™ integration with Entra (app registration, API permissions)
- Required feature flags enabled (e.g.,
FIDO2_MOBILE_AUTHENTICATOR,AZURE_PROVISION_API) - FIDO2/Enterprise Passkey authentication enabled in Entra
- Device and user registration via HYPR Mobile App
The only difference is how Windows workstations are joined to your domain:
Entra-only Environment
Use this path for cloud-first environments where Windows devices are joined directly to Microsoft Entra ID and managed entirely in the cloud.
- Device Join Type: Microsoft Entra join (direct to Microsoft Entra ID)
- User Account Type: Cloud-only Microsoft Entra ID accounts
- Device Join Process: Join directly to Microsoft Entra ID via Settings > Accounts > Access work or school
- Best for: Simpler deployments and cloud-managed fleets
For what Microsoft Entra join involves, see Microsoft's device identity overview.
Go to Entra-only Administrator Setup →
Hybrid Environment
Use this path for environments where Windows devices are Microsoft Entra hybrid joined. Microsoft Entra hybrid join is set up and managed through Microsoft; for prerequisites, planning, and configuration, see Microsoft's Microsoft Entra hybrid join documentation.
- Device Join Type: Microsoft Entra hybrid join
- User Account Type: Hybrid or cloud-only Microsoft Entra ID accounts
- Device Join Process: Configure Microsoft Entra hybrid join following Microsoft's guidance, then complete device join
- Best for: Enterprises that manage Windows devices through Microsoft Entra hybrid join
Go to Hybrid Administrator Setup →
Setup Order
For Entra-only: Complete device join to Microsoft Entra ID, then proceed with common Enterprise Passkey/HYPR integration steps.
For Hybrid: Complete the Microsoft Entra hybrid join process first, following Microsoft's guidance, then proceed with common Enterprise Passkey/HYPR integration steps.
What to do next
After completing your environment-specific device join setup, continue with the Administrator Configuration for the common HYPR Control Center™ integration and Enterprise Passkey setup steps.