Signing back into the Community for the first time? You'll need to reset your password to access your account. Find out more.
Forum Discussion
wavesound
2 years agoFrequent Contributor
Passkeys do not work with Microsoft 365
When I go to add PassKeys to my MIcrosoft 365 portal it fails at the last step.
https://mysignins.microsoft.com/security-info
Same error in Chrome and Brave.
I was able to cancel the 1Password enrollment process and enroll a YubiKey just fine.
1Password Version: 1Password for Mac 8.10.7 (81007041)
Extension Version: 2.12.0
OS Version: 13.4
Browser:_ Brave
- duscuNew Contributor
Nothing has really changed, it's still limited to device bound passkeys except if you want to use the Microsoft Auth app.
The only thing that changed recently, is that passkeys on Microsoft Auth app has also been enabled for tenants who do don't enforce key restrictions. - portland80New Contributor
aared Same behavior with my tenant I tested it. Normally I have a key restriction enabled but I have same message with and without restriction. I let you know if it should work in my tenant.
- aaredNew Contributor
According to the post from Backspaze on Page 2, it should be ready by now (estimated mid-Jan 2025). I'm 99% there but then it fails:
Microsoft admin can enable passkeys through the portal on entra.microsoft.com
and can avoid enabling key restrictions (disabled by default)which allows non-microsoft-authenticator passkey creation
and it gets to the last step
but then it fails- DominicTechNew Contributor
March 1st tomorrow. Still the same problem...
- GlobalNew Contributor
The update I have from Microsoft support is the following:
"Microsoft is committed to securing customers and users with passkeys. We are investing in both synced and device-bound passkeys for work accounts."
The TDLR is that it is coming, but a date has not yet been set.
- GlobalNew Contributor
It does look like Passkeys are currently just limited to Microsoft Authenticator.
Having said the above, I have put in a query to Microsoft Support to see if there is any movement on this on the horizon, as a synched Passkey would be very helpful for a lot of us.
- wavesoundFrequent Contributor
This appears to limit Passkeys to Microsoft Authenticator so we still won't be able to use these in 1Password, no?
- BackspazeFrequent Contributor
Microsoft has released more information.
Microsoft Entra: Enablement of Passkeys in Authenticator for passkey (FIDO2) organizations with no key restrictions
Beginning mid-January 2025, after the General Availability of passkeys in the Microsoft Authenticator app, organizations with the passkey (FIDO2) authentication methods policy enabled with no key restrictions will be enabled for passkeys in the Microsoft Authenticator app in addition to FIDO2 security keys. This update aligns with the broader availability of passkeys in Entra ID, extending from device-bound passkeys on security keys to device-bound passkeys also on user devices. Users who navigate to aka.ms/MySecurityInfo will see "Passkey in Microsoft Authenticator" as an authentication method they can add. Additionally, when Conditional Access (CA) authentication strengths policy is used to enforce passkey authentication, users who don't yet have any passkey will be prompted inline to register passkeys in Authenticator to meet the CA requirements. If an organization prefers not to enable this change for their users, they can work around it by enabling key restrictions in the passkey (FIDO2) policy. This change will not impact organizations with existing key restrictions or organizations that have not enabled the passkey (FIDO2) policy.
When this will happen:
General Availability (Worldwide, GCC, GCC High, DoD): Rollout will happen mid-January 2025.
How this will affect your organization:
Who will be impacted: Organizations with the passkey (FIDO2) authentication methods policy enabled with no key restrictions set.
Who will not be impacted: Organizations that do not have the passkey (FIDO2) authentication methods policy enabled and organizations that have the passkey (FIDO2) authentication methods policy enabled and have key restrictions set.
What you need to do to prepare:
This rollout will happen automatically with no admin action required. You may want to notify your users about this change and update any relevant documentation as appropriate.
- PiebasNew Contributor
Is there any update about the availability of the passkey at Microsoft 365 work/school accounts?
- dszpOccasional Contributor
It looks like people have said that iOS 18 Beta includes the ability to have at least 3 Passkey-enabled apps including their own, which would allow 1Password and the Microsoft Authenticator app to co-exist as Passkey providers on the same iPhone. Yay! At least, when iOS 18 goes GA this Fall...