Forum Discussion
sba_ur
Oct 08, 2026Copper Contributor
Synced iCloud Keychain passkey registration succeeds despite Device-Bound-only passkey profile
a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; } We have Microsoft Entra passkeys enabled only for a pilot group. The as...
sba_ur
Oct 09, 2026Copper Contributor
Thank you.
I am noticing on the second tenant that we manage, we don't have SMS or voice enabled for all users. Passkey (FIDO2) is also not enabled on that tenant. But users are still getting nudged and I see the same message there as well for auto-enablement.
Passkey auto-enablement will apply to this tenant
All users enabled for SMS or voice authentication are in scope for passkey auto-enablement. These users will be assigned to a system-managed passkey profile that allows all passkey types without restrictions.
--
Do I need to opt out on both the tenants? How do I get the passkey profiles that we have honored? It seems like system-managed is auto-enabling for all profiles, but we'd like to control this better.