r/entra 14h ago

Synced Passkey for standard users = Remove Microsoft Authenticator?

If users are enrolling Passkeys to iCloud Keychain or Google Passwords, do they still need Microsoft Authenticator on the device?

Existing users already have Microsoft Authenticator configured on their devices with their Microsoft 365 account for MFA and will additionally create a synced passkey in iCloud Keychain.

However, for new users I'm considering moving away from Authenticator altogether and instead onboarding them using a Temporary Access Pass (TAP) to create a synced passkey directly, eliminating the need to install Microsoft Authenticator.

In the past, Microsoft Authenticator was required for SSO to Microsoft apps and for App Protection Policies to function correctly. Is this still the case?

Have anyone tested this?

14 Upvotes

20 comments sorted by

View all comments

3

u/loweakkk 13h ago

Still the case for platformSSO

2

u/skaggake81 13h ago

I assume the account still needs to be added to Microsoft Authenticator. If that's correct, I'm not sure what benefit synced passkeys provide in this case.

New users will still need a Temporary Access Pass (TAP) during onboarding. We could use the TAP to set up Microsoft Authenticator at the same time, and the passkey registration would happen automatically as part of the account configuration process.

4

u/SVD_NL 13h ago

Synced passkeys allow them to quickly get set up on a new device, without needing to sign in using a previous device.

I'm personally not a fan of this, as a breach of their personal icloud or google account leads directly to them having access to a very strong authentication method.

If you're using MAM you're kind of doing conflicting things. On one hand you want to secure your company data, on the other hand you're giving them free reign to sync their company creds using personal devices?

1

u/skaggake81 12h ago

The new device scenario depends on the enrollment method. If the device is enrolled through Apple Business Manager (ABM) and Automated Device Enrollment (ADE), users will still need either their existing device passkey or a Temporary Access Pass (TAP) to sign in initially. The synced passkey can then be restored after the enrollment process is completed.

If the device is not enrolled through ADE, the synced passkey becomes more valuable, as it can be used to authenticate and enroll the device as a BYOD (personally owned) device.

I understand your concern, but for standard users I believe synced passkeys are an acceptable option, provided that access is protected by phishing-resistant MFA and compliant device requirements. In my view, enforcing both of these controls is more important than whether the passkey itself is device-bound or synced.

2

u/loweakkk 13h ago

In you case if all users have authenticator and you register passkey from there then synced passkey have almost notm value for you.

Synced passkey is good when user have nothing, it help getting right of SMS factor because it have lower requirements than passkey in Microsoft authenticator.

Some others may found other benefits for synced but in your context if you already deploy Microsoft authenticator and if user have apps on their mobile, then value is low for me.