Skip to content

Commit 5360b69

Browse files
Merge pull request #5666 from Justinha/passkey-ios
moved note
2 parents ef61d3a + 3a958cc commit 5360b69

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

docs/identity/authentication/how-to-enable-authenticator-passkey.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,6 @@ ms.reviewer: mjsantani
1919

2020
This article lists steps to enable and enforce use of passkeys in Authenticator for Microsoft Entra ID. First, you update the Authentication methods policy to allow end users to register and sign in with passkeys in Authenticator. Then you can use Conditional Access authentication strengths policies to enforce passkey sign-in when users access a sensitive resource.
2121

22-
>[!NOTE]
23-
>Support for registering passkeys in Authenticator when attestation is enforced is currently rolling out to iOS Authenticator app users. Support for registering attested passkeys in Authenticator on Android devices is available to all users in the latest version of the app.
24-
2522
## Requirements
2623

2724
- [Microsoft Entra multifactor authentication (MFA)](howto-mfa-getstarted.md)
@@ -50,7 +47,10 @@ An Authentication Policy Administrator needs to consent to allow Authenticator i
5047
When attestation is enabled in the passkey (FIDO) policy, Microsoft Entra ID tries to verify the legitimacy of the passkey being created. When the user is registering a passkey in the Authenticator, attestation verifies that the legitimate Microsoft Authenticator app created the passkey by using Apple and Google services. Here’s more details:
5148

5249
- iOS: Authenticator attestation uses the [iOS App Attest service](https://developer.apple.com/documentation/devicecheck/preparing-to-use-the-app-attest-service) to ensure the legitimacy of the Authenticator app before registering the passkey.
53-
50+
51+
>[!NOTE]
52+
>Support for registering passkeys in Authenticator when attestation is enforced is currently rolling out to iOS Authenticator app users. Support for registering attested passkeys in Authenticator on Android devices is available to all users in the latest version of the app.
53+
5454
- Android:
5555
- For Play Integrity attestation, Authenticator attestation uses the [Play Integrity API](https://developer.android.com/google/play/integrity/overview) to ensure the legitimacy of the Authenticator app before registering the passkey.
5656
- For Key attestation, Authenticator attestation uses [key attestation by Android](https://developer.android.com/privacy-and-security/security-key-attestation) to verify that the passkey being registered is hardware-backed.

0 commit comments

Comments
 (0)