Skip to main content
Version: 11.3.0

Environment Setup Overview

Choose the environment setup that matches your domain and device architecture. This page explains the two supported environment types for deploying Enterprise Passkey with HYPR Passkey.

Important: Core Enterprise Passkey Setup is the Same

The core Enterprise Passkey setup process is identical for both Entra-only and Hybrid environments. Both require:

  • Microsoft Entra ID tenant with verified domains and users
  • HYPR Control Center™ integration with Entra (app registration, API permissions)
  • Required feature flags enabled (e.g., FIDO2_MOBILE_AUTHENTICATOR, AZURE_PROVISION_API)
  • FIDO2/Enterprise Passkey authentication enabled in Entra
  • Device and user registration via HYPR Mobile App

The only difference is how Windows workstations are joined to your domain:

Entra-only Environment

Use this path for cloud-first environments where Windows devices are joined directly to Microsoft Entra ID and managed entirely in the cloud.

  • Device Join Type: Microsoft Entra join (direct to Microsoft Entra ID)
  • User Account Type: Cloud-only Microsoft Entra ID accounts
  • Device Join Process: Join directly to Microsoft Entra ID via Settings > Accounts > Access work or school
  • Best for: Simpler deployments and cloud-managed fleets

For what Microsoft Entra join involves, see Microsoft's device identity overview.

Go to Entra-only Administrator Setup →

Hybrid Environment

Use this path for environments where Windows devices are Microsoft Entra hybrid joined. Microsoft Entra hybrid join is set up and managed through Microsoft; for prerequisites, planning, and configuration, see Microsoft's Microsoft Entra hybrid join documentation.

  • Device Join Type: Microsoft Entra hybrid join
  • User Account Type: Hybrid or cloud-only Microsoft Entra ID accounts
  • Device Join Process: Configure Microsoft Entra hybrid join following Microsoft's guidance, then complete device join
  • Best for: Enterprises that manage Windows devices through Microsoft Entra hybrid join

Go to Hybrid Administrator Setup →

Setup Order

For Entra-only: Complete device join to Microsoft Entra ID, then proceed with common Enterprise Passkey/HYPR integration steps.

For Hybrid: Complete the Microsoft Entra hybrid join process first, following Microsoft's guidance, then proceed with common Enterprise Passkey/HYPR integration steps.

What to do next

After completing your environment-specific device join setup, continue with the Administrator Configuration for the common HYPR Control Center™ integration and Enterprise Passkey setup steps.

Proceed to Administrator Configuration →