A cloud-based identity and access management service for securing user authentication and resource access
The provided information does not describe how Microsoft Entra ID or Microsoft account sign-in endpoints gate passkey experiences at the protocol level (for example, whether they key off user agent strings vs. actual WebAuthn/FIDO2 capability detection).
From the context, only the following is documented:
- Passkeys are supported on specific OS versions and browsers (for example, Edge/Chrome/Safari 16+/109+ on supported platforms).
- To use a passkey, the user selects Other ways to sign in → Face, fingerprint, PIN, or security key, and the device/browser then opens the platform security UI.
- Known issues mention Bluetooth requirements and orphaned passkeys, but not the gating logic.
There is no explicit statement in the context about whether the appearance of the "Face, fingerprint, PIN, or security key" option is controlled by UA sniffing, by WebAuthn/FIDO2 feature detection, or by some combination of both plus policy.
References: