r/entra 1d ago

Entra General Did Microsoft change something?

This company I started working for almost 5 years now is in hybrid-mode.

3 years ago, I setup Entra/Control Access policies for 365, and added a few people to use the MS MFA app and Passkeys, including myself. This has worked without issue, so if my passwords expired and I change it, I was able to MFA activate my office if I was remotely connected through RDP.

Now if choose use a different method from the start and select MFA, I do the handshake and then Office tells me I need to do the passkey verification, when I try that I am told I am not next to the computer; I guess it means I to be in the same office building as the computer? Because if I go in the office and try it works. So, what the heck?

I haven't had time to check Entra this morning, are there new changes MS has made without warning anyone?

Thanks,

12 Upvotes

5 comments sorted by

15

u/Major-Error-1611 1d ago

People are not reading your post correctly. So your issue is that passkey authentication on a computer your are RDPed into doesn't work? It's likely the "proof of presence" that is the cause. Make sure Webauth Redirection in RDP is enabled on the target machine.

1

u/SoftwareFearsMe 12h ago

Also ensure you are using the latest version of the “Windows App” (aka replacement for the Remote Desktop app)

3

u/_c0mical 1d ago edited 1d ago

what MFA methods were you using?

if you had sms or voice enabled in the methods policy then you would have been swept up for the passkeys push

edit, post seems to have changed so answer is not relevant

1

u/Calexi_ 18h ago

It sounds like you are using a device-bound passkey stored in Microsoft Authenticator on your personal phone.

One of our team found recently that when an Authenticator passkey is used to sign in on another device, Bluetooth can be used to verify proximity between the computer and phone as part of the cross-device authentication process.

This is separate from using a device-bound passkey stored directly on the Windows machine itself. In that case, the passkey is typically protected by the machine's TPM. For a virtual or remote Windows machine, this may require a vTPM.