I'm testing passkeys in Microsoft Entra ID. I created a passkey authentication policy for a test user with attestation enforcement disabled and the passkey type set to "Synced." I then registered a passkey in Microsoft Authenticator.
However, Authenticator only offers backup through a personal Microsoft account, not a work or school account. After restoring Authenticator on a second test phone from that backup, the passkey itself was missing. Microsoft's documentation appears to explain that passkeys stored in Authenticator are device-bound and aren't currently synchronized, even when the Entra policy allows synced passkeys.
Is this expected behavior? If so, what is the purpose of selecting "Synced" passkeys when Microsoft Authenticator doesn't sync them? Is Microsoft planning to support passkey backup to work or school accounts? At the moment, I had to require MFA re-registration for the test user before registering a new passkey.
2 Answers
Yes, that is currently expected. Authenticator passkeys are device-bound, so restoring the app’s backup does not restore the passkey credential. The “Synced” setting describes the credential type Entra ID accepts; it does not mean Microsoft Authenticator will synchronize that credential between phones.
Authenticator backup is not a passkey migration mechanism. It can restore supported app data and registrations, but the private key for a device-bound passkey remains tied to the original device. Make sure every account has a recovery method or a second registered device before wiping or replacing a phone; otherwise account recovery can become a lengthy support process.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures