Comments on: Using Entra ID Support for Passkey Authentication with Microsoft 365 https://practical365.com/entra-id-support-for-passkey-authentication/ Practical Office 365 News, Tips, and Tutorials Tue, 13 Aug 2024 13:03:15 +0000 hourly 1 https://wordpress.org/?v=6.6.1 By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_296688'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_296688"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/entra-id-support-for-passkey-authentication/#comment-296688 Thu, 11 Jul 2024 04:44:27 +0000 https://practical365.com/?p=60763#comment-296688 In reply to Greg.

I have no knowledge of how Microsoft plans to develop passkey support further. They have invested a lot in the Authenticator app and for now that seems to be the only game in town…

]]>
By: Greg https://practical365.com/entra-id-support-for-passkey-authentication/#comment-296685 Thu, 11 Jul 2024 03:37:10 +0000 https://practical365.com/?p=60763#comment-296685 For windows devices I understand you can use WHfB as a phishing resistant MFA method for Entra ID, and so if you combine that with using passkeys for mobile device signin, I expect you could avoid the cross-device signin experience that seems to be the part the users might struggle with?

Ideally you could sync your passkey to your desktop, but as MS Authenticator & iCloud are primarily mobile first apps i’m not sure how this would work unless there was a desktop (or web browser) component. I see LastPass has passkey support coming so potentially that would be a way to sign into both platforms using passkey synced to the browser plugin, rather than having to use the cross device flow?

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_294126'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_294126"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/entra-id-support-for-passkey-authentication/#comment-294126 Thu, 16 May 2024 08:40:21 +0000 https://practical365.com/?p=60763#comment-294126 In reply to Tshk.

Yep. I’ve lived through a couple of migrations to new phones and it hasn’t been a wonderful experience. https://office365itpros.com/2023/01/04/microsoft-authenticator-app-qr/

]]>
By: Tshk https://practical365.com/entra-id-support-for-passkey-authentication/#comment-294111 Thu, 16 May 2024 00:33:08 +0000 https://practical365.com/?p=60763#comment-294111 Also.. using Authenticator could be great but the migration of Authenticator to newer phones is a big pain, even worst if you have a few tenants registered.

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_293601'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_293601"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/entra-id-support-for-passkey-authentication/#comment-293601 Tue, 07 May 2024 09:33:26 +0000 https://practical365.com/?p=60763#comment-293601 In reply to rinku vaghela.

I have no idea. I cannot see your tenant details and I don’t know if you set everything up correctly. Check everything and retry…

]]>
By: rinku vaghela https://practical365.com/entra-id-support-for-passkey-authentication/#comment-293590 Tue, 07 May 2024 07:44:57 +0000 https://practical365.com/?p=60763#comment-293590 not able to login with passkey error received from windows security that ” something went wrong” what can i do now

]]>
By: Mikey https://practical365.com/entra-id-support-for-passkey-authentication/#comment-293105 Sat, 27 Apr 2024 20:36:46 +0000 https://practical365.com/?p=60763#comment-293105 So we train users to scan a QR code to login? Hard pass.

]]>
By: Henrik Elmsjö https://practical365.com/entra-id-support-for-passkey-authentication/#comment-292957 Thu, 25 Apr 2024 06:59:32 +0000 https://practical365.com/?p=60763#comment-292957 In reply to Tony Redmond.

Indeed, but no BT pairing is needed beforehand, you just have to be in proximity of the device you are authenticating on. I know you do not state this so there is nothing wrong in the article, I just want to clarify this so people don’t interpret Microsofts docs wrong. 🙂

]]>
By: Tony Redmond https://practical365.com/entra-id-support-for-passkey-authentication/#comment-292911 Wed, 24 Apr 2024 15:06:48 +0000 https://practical365.com/?p=60763#comment-292911 In reply to Henrik Elmsjö.

From the Microsoft documentation: https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-sign-in-passkey-authenticator?tabs=iOS

Bluetooth and an internet connection are required for this step and must both be enabled on your mobile and remote device.

]]>
By: Henrik Elmsjö https://practical365.com/entra-id-support-for-passkey-authentication/#comment-292884 Wed, 24 Apr 2024 08:14:09 +0000 https://practical365.com/?p=60763#comment-292884 The implication of this is pretty heavy though. It means that passkey logins cannot be done remotely. This may be good or bad, but it will exclude a lot of remote client scenarios (vdi, VMs…) unless the authentication is done locally.]]> This part may be a bit misleding: “The phone must be connected to the workstation via Bluetooth to allow the challenge flow to proceed.”
It may be good to know that yhey do not have to be “Bluetooth paired” in a technical sense, the CTAP 2.2 solution uses Bluetooth BLE simply as a proximity check. 🍺
The implication of this is pretty heavy though. It means that passkey logins cannot be done remotely. This may be good or bad, but it will exclude a lot of remote client scenarios (vdi, VMs…) unless the authentication is done locally.

]]>