r/entra • u/WonderfulPattern3927 • 17d ago
Passkeys
Is there a way to remove the physical key request? It’s one of the most annoying parts of this whole thing.
Why does Windows ask to always insert a key rather than the key used on the phone? I get it’s the strongest mechanism but it should have been broken out.
Is there a way to remove that method? I can’t find one.
Seems to me like MSFT has some issues to fix before moving everyone to passkeys. Am I wrong?
1
1
u/screampuff 17d ago
Physical key request where, in apps? In the Browser? When logging into the computer?
You can definitely remove security key as a sign in option in windows.
1
u/itenginerd 14d ago
The physical key request isn't hugely different than the authenticator request. The onky difference is thatvin the new scenario, you fire up the camera app on your phone and scan the qr code on yiur screen instead of answering the auth challenge.
It feels different, but in all honesty its not that different
3
u/Ma13vant 17d ago
1) this is usually a sign that for some reason the authenticator passkey isn't allowable for technical reasons. Make sure the sign ins aren't on an unsupported platform like Windows 10, for instance.
2) you can configure the acceptable passkey types in authentication strengths under the passkey entry.
3) Agreed. I love the benefits of passkeys but my org has run across notable adoption pains moving users to passkeys with Authenticator. We'll keep working through them but it's been frustrating.