Enable external identity provider passkeys, browser single sign-on, and modern web authentication for brokered Microsoft app sign-ins on Android, iOS, and managed macOS.
Organizations that use an external identity provider to authenticate Microsoft 365 users can now extend browser-based passkeys, security keys, and eligible single sign-on sessions to supported Microsoft app sign-ins—including Outlook, Teams, OneDrive, Word, Excel, PowerPoint, and Microsoft To Do—on Android, iOS, and managed macOS.
Previously, some Microsoft app sign-ins used an embedded web view that couldn’t provide the browser capabilities required to support passkeys (FIDO2) issued by external identity providers. As a result, some users couldn’t use a passkey or security key or complete sign-in when the identity provider required passkeys or blocked embedded web views.
Browser authentication for external identity providers addresses this limitation by opening only the external identity provider step in the system browser. After authentication, the user returns to the Microsoft identity broker—the trusted Microsoft component that coordinates app sign-in—and the originating app completes sign-in.
Browser authentication opens the external identity provider’s sign-in step in the system browser.
Extend your passkey strategy to Microsoft app sign-ins
Organizations federated through WS-Fed or SAML 2.0 can use this capability to extend supported external identity provider authentication methods to Microsoft app sign-ins. Users can authenticate with passkeys or FIDO2 security keys in the system browser, and eligible browser sessions can reduce repeated prompts.
With this capability, you can:
- Use external identity provider passkeys and FIDO2 security keys. The external identity provider authentication step runs in a browser surface that supports WebAuthn, so users can use FIDO credentials registered with that identity provider instead of falling back to a password-only experience.
- Enable single sign-on from native apps to web apps. The system browser provides a shared web surface and can reuse an eligible identity provider session, reducing unnecessary sign-in prompts.
- Support identity providers that reject embedded web views. Organizations can maintain identity provider policies that require a system browser without creating a separate authentication path for supported Microsoft apps.
- Roll out with platform-level control. Administrators enable the experience in the relevant federation configuration and select the platforms where it applies.
This creates a more consistent experience across web and supported Microsoft app sign-ins without requiring a separate authentication approach for embedded sign-in surfaces.
Keep the brokered app experience
The Microsoft identity broker—a trusted Microsoft component that coordinates app sign-in and token acquisition—continues to manage the sign-in flow. Depending on the platform, the broker is Microsoft Authenticator, Intune Company Portal, or another supported Microsoft broker app. Only the external identity provider step opens in the system browser; a trusted app link or universal link then returns the user to the broker.
In practice, a user starts sign-in in a Microsoft app, authenticates with the external identity provider in the system browser, and returns to the app through the broker to finish sign-in.
Sign-in flow: Microsoft app → Microsoft identity broker → system browser and external identity provider → Microsoft identity broker → Microsoft app.
Available platforms and scenarios
|
Platform |
Browser and requirements |
|
Android |
Chrome configured as the default browser, with a supported Microsoft broker |
|
Android shared device mode |
Chrome, with a supported Microsoft broker |
|
iOS |
Safari, with Microsoft Authenticator as the broker |
|
Managed macOS |
Safari, with Intune Company Portal as the broker |
The capability supports domains federated through WS-Fed or SAML 2.0. Windows already supports third-party FIDO authentication through its native experience and doesn’t use this flow. Linux, unmanaged macOS, and OAuth 2.0/OpenID Connect (OIDC) social identity provider flows aren’t supported at this time.
Direct sign-in to the Intune Company Portal app on Android continues to use an embedded WebView. Company Portal can still act as the broker for other supported Android app scenarios.
For current broker and component minimum versions, see Browser authentication for external identity providers in Microsoft Entra ID.
What general availability delivers
General availability brings the system-browser-based third-party FIDO experience to supported Android, Android shared device mode, iOS, and managed macOS scenarios. It supports the WS-Fed and SAML 2.0 federation frameworks. A broker app, such as Microsoft Authenticator or Intune Company Portal, must be installed on the device for applicable platforms.
Get started
To get started, confirm that your domain uses a supported federation protocol, then enable browser authentication for the selected platforms.
For current prerequisites, configuration steps, validation guidance, and known limitations, see the feature documentation. For configuration details, see the Microsoft Graph internalDomainFederation resource.
Help users take the next step toward passwordless
Passkeys and FIDO2 security keys provide phishing-resistant authentication without relying on shared secrets. Browser authentication for external identity providers extends the value of those investments by connecting supported Microsoft app sign-ins to the browser capabilities and identity provider sessions that federated users already use.
Review the prerequisites, enable the platforms that fit your environment, and validate the experience with your external identity provider. We welcome your feedback as you bring browser-based passkey and single sign-on experiences to your users.
—Justin Ploegert
Additional resources
- Browser authentication for external identity providers in Microsoft Entra ID
- Configure federation with the Microsoft Graph internalDomainFederation resource
Learn more about Microsoft Entra
Prevent identity attacks, ensure least-privilege access, unify access controls, and improve the user experience with comprehensive identity and network access solutions across on-premises and cloud environments.