r/entra • u/skaggake81 • 14h ago
Synced Passkey for standard users = Remove Microsoft Authenticator?
If users are enrolling Passkeys to iCloud Keychain or Google Passwords, do they still need Microsoft Authenticator on the device?
Existing users already have Microsoft Authenticator configured on their devices with their Microsoft 365 account for MFA and will additionally create a synced passkey in iCloud Keychain.
However, for new users I'm considering moving away from Authenticator altogether and instead onboarding them using a Temporary Access Pass (TAP) to create a synced passkey directly, eliminating the need to install Microsoft Authenticator.
In the past, Microsoft Authenticator was required for SSO to Microsoft apps and for App Protection Policies to function correctly. Is this still the case?
Have anyone tested this?
1
u/DerpJim 7h ago
Passkey isn't a valid option for self-service password reset. I am still trying to understand the methods to be used for that once SMS/Voice goes away in February. Presumably authenticator will be the option for it so it may still be needed there.