Is Microsoft's passkey gating is UA-based, not capability-based?

Aman Kumar 0 Reputation points
2026-04-30T15:24:32.46+00:00

Is Microsoft's passkey gating is UA-based, not capability-based?

Test: ship the UA patch to a TestFlight build, sign in with a test account, observe whether the "Face, fingerprint, PIN or security key" option appears.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-30T15:24:43.47+00:00

    The provided information does not describe how Microsoft Entra ID or Microsoft account sign-in endpoints gate passkey experiences at the protocol level (for example, whether they key off user agent strings vs. actual WebAuthn/FIDO2 capability detection).

    From the context, only the following is documented:

    • Passkeys are supported on specific OS versions and browsers (for example, Edge/Chrome/Safari 16+/109+ on supported platforms).
    • To use a passkey, the user selects Other ways to sign inFace, fingerprint, PIN, or security key, and the device/browser then opens the platform security UI.
    • Known issues mention Bluetooth requirements and orphaned passkeys, but not the gating logic.

    There is no explicit statement in the context about whether the appearance of the "Face, fingerprint, PIN, or security key" option is controlled by UA sniffing, by WebAuthn/FIDO2 feature detection, or by some combination of both plus policy.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.