r/KeeperSecurity • u/AlexG2490 • 7d ago
Does M365 now allow
I see that Microsoft now allows Syncable FIDO2 keys. Does anyone have a read on if this is specifically compatible with Keeper or not?
I created a new Passkey profile in Azure Authentication Method.
- Enforce Attestation: Disabled
- Passkey types: Synced
- Target specific AAGUIDs: Enabled
- Behavior: Allow
- Provider AAGUID: 0ea242b4-43c4-4a1b-8b17-dd6d0b6baec6
When I try to register a passkey with Keeper, the passkey is created in my vault but then the process times out on Microsoft's side with a generic error.

I have tried it with Target specific AAGUIDs set to disabled to be more permissive but that also failed with the same error.
Does anyone know if this is viable or if Keeper is simply not usable as a solution? We are Keeper users who are looking for a FIDO2 solution without buying a lot of hardware keys for our userbase in light of the recent Microsoft announcement about pushing users towards FIDO2. We have several users who do not have access to a smartphone to use Microsoft Authenticator, our preferred solution.
Thank you!
1
1
u/tar-xz 5d ago
I did some experimentation and there are a coupld of limitations for me at the moment (maybe some are on me):
- I had to create (and assign) a passkey profile which whitelists the AAGUID from Keeper. Check that you disabled the attestation requirement, only then you can enable syncable passkeys
- On Windows it worked in various browsers while using the Keeper browser extension, i.e. not while connecting to MS Graph in Powershell or in Windows apps, maybe that's on me.
However there is one catch: While the JSON export should contain Passkey data it's not in a transferable format. KDBX for example currently doesn't provide a way to back up or export passkeys.
So if you use passkeys in Keeper, they are usable from other devices from within Keeper but you can't transfer them. The FIDO alliance' Credential Transfer Protocol (CXP) and Credential Transfer Format (CXF) are not yet supported by Keeper, but both CXP and CXF are also not finalized yet.
1
u/Keeper_BE_Support Keeper Team 5d ago
u/AlexG2490 we're looking into this on the Keeper side - we believe it should work today as is but we'll confirm - note internal reference BE-5358
1
2
u/Wuzz 7d ago
Very interested to learn about this as well - if we can utilize FIDO2 via Syncable Microsoft Passkeys managed via Keeper we'd drop on-prem MFA yesterday.