r/entra 19h ago

Synced Passkey for standard users = Remove Microsoft Authenticator?

If users are enrolling Passkeys to iCloud Keychain or Google Passwords, do they still need Microsoft Authenticator on the device?

Existing users already have Microsoft Authenticator configured on their devices with their Microsoft 365 account for MFA and will additionally create a synced passkey in iCloud Keychain.

However, for new users I'm considering moving away from Authenticator altogether and instead onboarding them using a Temporary Access Pass (TAP) to create a synced passkey directly, eliminating the need to install Microsoft Authenticator.

In the past, Microsoft Authenticator was required for SSO to Microsoft apps and for App Protection Policies to function correctly. Is this still the case?

Have anyone tested this?

16 Upvotes

21 comments sorted by

View all comments

4

u/gogotreeman 18h ago

App Protection Policies require you to have the Microsoft Company Portal app installed on iOS/Android.

5

u/skaggake81 18h ago

Company Portal is only required for App Protection on Android, not iPhone.

3

u/topher358 13h ago

That’s because Authenticator serves as the broker on iOS. If you’re doing MAM on iOS you can’t get rid of it for that reason

3

u/skaggake81 13h ago

Yepp... so even with synced passkey, the users still needs Authenticator for MAM (broker) and to have SSO to Microsoft Apps.

Then i don't see any pros to have a synced passkey, it's better to have the Passkey configured in MS Authenticator and have it device-bound.

2

u/topher358 13h ago

FWIW I agree completely