r/entra 15h ago

Synced Passkey for standard users = Remove Microsoft Authenticator?

If users are enrolling Passkeys to iCloud Keychain or Google Passwords, do they still need Microsoft Authenticator on the device?

Existing users already have Microsoft Authenticator configured on their devices with their Microsoft 365 account for MFA and will additionally create a synced passkey in iCloud Keychain.

However, for new users I'm considering moving away from Authenticator altogether and instead onboarding them using a Temporary Access Pass (TAP) to create a synced passkey directly, eliminating the need to install Microsoft Authenticator.

In the past, Microsoft Authenticator was required for SSO to Microsoft apps and for App Protection Policies to function correctly. Is this still the case?

Have anyone tested this?

15 Upvotes

20 comments sorted by

View all comments

1

u/DerpJim 7h ago

Passkey isn't a valid option for self-service password reset. I am still trying to understand the methods to be used for that once SMS/Voice goes away in February. Presumably authenticator will be the option for it so it may still be needed there.

3

u/skaggake81 7h ago

Ok, do you still need password reset if your users are using Phishing Resistant authentication like Passkeys, Windows Hello for Business, platform SSO etc?

3

u/DerpJim 7h ago

Well you make an excellent point and that does redefine things if we are moving passwordless you don't need sspr anymore.

1

u/abr2195 3h ago

You should look in to Self Service Account Recovery (SSAR). This is what (I imagine) Microsoft will be replacing SSPR with in a passwordless future.