Why don’t Microsoft Authenticator passkeys restore to a new phone?

0
2
Asked By VelvetMango42 On

I'm testing passkeys in Microsoft Entra ID. I created a passkey authentication policy for a test user with attestation enforcement disabled and the passkey type set to "Synced." I then registered a passkey in Microsoft Authenticator.

However, Authenticator only offers backup through a personal Microsoft account, not a work or school account. After restoring Authenticator on a second test phone from that backup, the passkey itself was missing. Microsoft's documentation appears to explain that passkeys stored in Authenticator are device-bound and aren't currently synchronized, even when the Entra policy allows synced passkeys.

Is this expected behavior? If so, what is the purpose of selecting "Synced" passkeys when Microsoft Authenticator doesn't sync them? Is Microsoft planning to support passkey backup to work or school accounts? At the moment, I had to require MFA re-registration for the test user before registering a new passkey.

2 Answers

Answered By QuietHarbor7 On

Yes, that is currently expected. Authenticator passkeys are device-bound, so restoring the app’s backup does not restore the passkey credential. The “Synced” setting describes the credential type Entra ID accepts; it does not mean Microsoft Authenticator will synchronize that credential between phones.

Answered By BreezyCactus19 On

Authenticator backup is not a passkey migration mechanism. It can restore supported app data and registrations, but the private key for a device-bound passkey remains tied to the original device. Make sure every account has a recovery method or a second registered device before wiping or replacing a phone; otherwise account recovery can become a lengthy support process.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.