In a recent LinkedIn post, Mark Russinovich discusses a significant engineering achievement by his team at Microsoft, addressing a long-standing challenge in the adoption of passkeys: secure synchronization across devices. Russinovich highlights how Microsoft Password Manager now utilizes confidential computing to overcome the inherent trade-off between security and convenience.
He explains the core problem: “The challenge with passkeys has always been the trade-off between ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ and ๐ฐ๐ผ๐ป๐๐ฒ๐ป๐ถ๐ฒ๐ป๐ฐ๐ฒ: how do you move them between devices without exposing them to the underlying OS or the cloud provider?”
Russinovich reveals that his team has implemented a novel solution to this dilemma.
“Weโve implemented a secure passkey sync for the ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐ฟ using ๐ฐ๐ผ๐ป๐ณ๐ถ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ฐ๐ผ๐บ๐ฝ๐๐๐ถ๐ป๐ด.”
This breakthrough, as detailed by Russinovich, relies on hardware-isolated Trusted Execution Environments (TEEs). He elaborates on the security implications of this approach.
Leveraging Confidential Computing for Enhanced Security
Mark Russinovich emphasizes that the use of TEEs is central to the security model of this new passkey sync feature. These environments are designed to protect data even from the system’s administrator or the cloud provider itself.
“By leveraging hardware-isolated Trusted Execution Environments (TEEs), we ensure that your passkeys are only ever decrypted within a secure, verifiable enclave. Not even Microsoft can see them.”
According to Russinovich, this architectural choice directly addresses the security concerns that have previously hindered widespread passkey adoption. The ability to keep passkeys encrypted and only decrypted within a secure enclave means that potential threats from the operating system or cloud infrastructure are significantly mitigated.
Enabling Seamless Device Roaming
The security enhancements enabled by confidential computing are not at the expense of user experience, according to Russinovich. The new system is designed to facilitate easy passkey management across multiple devices.
“This allows for seamless ‘roaming’ across your devices while maintaining the highest level of cryptographic security,” Russinovich states in his post. This implies that users can expect a smooth transition when setting up or using passkeys on new phones, laptops, or tablets, without compromising the safety of their credentials.
Real-World Application of Confidential Computing
Russinovich frames this development as a practical application of confidential computing technology, moving it from a theoretical concept to a tangible solution for everyday users. He highlights the significance of this transition.
“This is a great example of how we are moving beyond just ‘confidential computing’ as a concept and applying it to solve real-world problems for our customers.”
The journalist notes that this implementation by Microsoft underscores the growing importance of advanced security technologies in protecting user data in an increasingly interconnected digital world. The detailed technical explanation, available via a link in the original post, promises further insights into the engineering behind this innovative feature.
📝 About This Content
This article is based on insights shared by Mark Russinovich on LinkedIn.
📅 Originally posted on April 23, 2026 | View original post on LinkedIn โ