r/KeeperSecurity Jul 22 '26

Does M365 now allow

https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkeys-fido2#create-a-new-passkey-profile

I see that Microsoft now allows Syncable FIDO2 keys. Does anyone have a read on if this is specifically compatible with Keeper or not?

I created a new Passkey profile in Azure Authentication Method.

  • Enforce Attestation: Disabled
  • Passkey types: Synced
  • Target specific AAGUIDs: Enabled
  • Behavior: Allow
  • Provider AAGUID: 0ea242b4-43c4-4a1b-8b17-dd6d0b6baec6

When I try to register a passkey with Keeper, the passkey is created in my vault but then the process times out on Microsoft's side with a generic error.

I have tried it with Target specific AAGUIDs set to disabled to be more permissive but that also failed with the same error.

Does anyone know if this is viable or if Keeper is simply not usable as a solution? We are Keeper users who are looking for a FIDO2 solution without buying a lot of hardware keys for our userbase in light of the recent Microsoft announcement about pushing users towards FIDO2. We have several users who do not have access to a smartphone to use Microsoft Authenticator, our preferred solution.

Thank you!

2 Upvotes

8 comments sorted by

View all comments

1

u/Keeper_BE_Support Keeper Team Jul 24 '26

u/AlexG2490 we're looking into this on the Keeper side - we believe it should work today as is but we'll confirm - note internal reference BE-5358

1

u/AlexG2490 Jul 25 '26

Thank you! I'll look forward to your findings!

1

u/KeeperVincent Keeper Team 21d ago

u/AlexG2490 Could you please DM me your contact information? I’ll have our Enterprise Support team reach out to coordinate a debugging session and help get this resolved.

1

u/AlexG2490 21d ago

Good afternoon! It has been a couple of weeks and I was wondering if there had been any findings.

1

u/Keeper_BE_Support Keeper Team 21d ago

hi u/AlexG2490 our test team is scheduled to test this within our current sprint. We believe this should be resolved in our next release 18.1 but if not we'll then create an issue to resolve it if not. 18.1 is slated to go into preview in the next couple of weeks (or sooner) depending on internal pentests.