Forum Discussion
GeorgJ
May 11, 2026Copper Contributor
Web-signin 3rd party IDP not working
We have a working Entra ID SAML federation to a third-party IdP that uses FIDO2/WebAuthn (IdP as Relying Party) for browser sign-in, and we are trying to use the same federation through Windows Web s...
Kidd_Ip
May 11, 2026MVP
WebAuthn inside Windows Web Sign-in WebView does not currently broker authentication to third‑party IdPs acting as their own FIDO2 Relying Party but only Microsoft Entra ID scenarios such as TAP, Authenticator, SAML‑P federation are supported. There is no published roadmap for enabling external IdPs’ WebAuthn flows in Web sign-in yet. The supported path for passwordless Windows sign-in with federated IdPs is to use Entra ID as the RP (via FIDO2 security keys or passkeys), not the IdP’s own WebAuthn stack.
https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune
https://learn.microsoft.com/en-us/graph/api/resources/passkeyprofilestructure?view=graph-rest-beta