Signing back into the Community for the first time? You'll need to reset your password to access your account. Find out more.
Forum Discussion
wavesound
2 years agoFrequent Contributor
Passkeys do not work with Microsoft 365
When I go to add PassKeys to my MIcrosoft 365 portal it fails at the last step.
https://mysignins.microsoft.com/security-info
Same error in Chrome and Brave.
I was able to cancel the 1Password enrollment process and enroll a YubiKey just fine.
1Password Version: 1Password for Mac 8.10.7 (81007041)
Extension Version: 2.12.0
OS Version: 13.4
Browser:_ Brave
- wraithOccasional Contributor
leonardder https://support.yubico.com/hc/en-us/articles/360016648959-YubiKey-Hardware-FIDO2-AAGUIDs
Of course I haven't actually been successful in making this work (despite following the poorly worded guidance in the MS Article).
- leonardderOccasional Contributor
This opens the question whether 1Password passkeys are considered device bound. Furthermore, how to determine the Authenticator Attestation GUID (AAGUID) needed to approve 1Password passkeys?
- Former Member
"Beginning January 2024, Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in public preview, in addition to the existing support for FIDO2 security keys. This enables your users to perform phishing-resistant authentication using the devices that they already have."
- Former Member
"Beginning January 2024, Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in public preview, in addition to the existing support for FIDO2 security keys. This enables your users to perform phishing-resistant authentication using the devices that they already have."
- Former Member
"Beginning January 2024, Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in public preview, in addition to the existing support for FIDO2 security keys. This enables your users to perform phishing-resistant authentication using the devices that they already have."
- Former Member
"Beginning January 2024, Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in public preview, in addition to the existing support for FIDO2 security keys. This enables your users to perform phishing-resistant authentication using the devices that they already have."
- Former Member
Just hopping in to add my experience with this as well. Like others, I am unable to use iOS or MacOS (Safari) to add a passkey for my personal Microsoft account. Considering 1Password knows that I only use Apple devices, it would be nice to have the alert in 1Password to add a passkey removed until such a time as 1Password has verified support for my devices with the account in question! steph_giles
- Former Member
Confirming same issue as above.
Edge: Version 119.0.2151.44 (x64)
1Password for Windows 8.10.20 (81020020)
Windows 10 22H2, 11 22H2 and 11 22H3, all recent updates applied. - BackspazeFrequent Contributor
I'd say that, just like wavesound mentioned, Microsoft stills doesn't support passkeys for work or school accounts in Microsoft 365, and that's what's causing the issue shown in detail in sukka's post.
I went through exactly the same flow and got the same error earlier this year when I tried to register a physical security key which turned out to be incompatible. Once I had a key that was compatible, I was able to add it without issue.
Also, some other services, like Google, makes a clear difference between physical keys and passkeys already in the settings menu where you choose which method configure. I expect Microsoft to distinguish between the two by adding a method called Passkey in addition to the already present Security key method. It's just confusing to choose the Security key method and then choose between a USB device and NFC device when it's neither.
- Former Member
Confirming I have the exact same problem following the steps sukka mentioned.