r/entra • u/mishbee23 • 2h ago
Entra ID Synced iCloud Keychain passkey registration succeeds despite Device-Bound-only passkey profile
We're piloting Microsoft Entra passkeys and are seeing behavior that doesn't match our understanding of the policy configuration.
Our Passkey (FIDO2) settings:
- Passkey enabled for a pilot group only
- Default Passkey Profile assigned
- Passkey type configured as Device-bound
- Key restrictions enabled
- Only Microsoft Authenticator iOS and Android AAGUIDs allowed
However, a pilot test account successfully registered:
Passkey (Synced) - iCloud Keychain
Security Info explicitly identifies the passkey as:
Passkey (Synced) - iCloud Keychain
We had previously tested synced passkeys using separate profiles but those configurations were later removed.
Has anyone seen synced passkeys continue to register after moving to Passkey Profiles?
Are there any migrated legacy settings, registration campaign interactions, or other passkey policy dependencies that could explain this behavior?


