Entra

How to create a Microsoft 365 device-bound passkey on macOS

· 2 min read · Entra

I did a discovery today, and I want to share it, because I did not know this was an option. Up until now, I always thought that device-bound passkeys where limited to Windows Hello for Business, FIDO2 security keys, and the Microsoft Authenticator App.

But today I learned you can also store a passkey on macOS, which is registered as a device-bound passkey. It works for both Edge and Chrome, and is backed with a specific AAGUID.

771b48fd-d3d4-4f74-9232-fc157ab0507a for Edge on Mac
adce0002-35bc-c60a-648b-0b25f1f05503 for Chrome on Mac

Passkey registration options in a Mac browser

It’s different from Platform Credential for macOS, which requires another AAGUID (7FD635B3-2EF9-4542-8D9D-164F2C771EFC)

To enroll a device-bound passkeys is pretty straightforward, but your users might need some guidance, as you need to skip out of the regular flow. The regular flow (which works great) prompts to store the passkey in the iCloud keychain, which results in a synced passkey instead.

Start as usual by adding a new sign-in method:

Adding a new sign-in method

Select Next

Now you will be prompted to provide your Touch ID or password to enroll for a synced passkey, but you need to cancel out of that.

Click Cancel.

Canceling synced passkey registration

Depending on which browser you are using, select either Your Microsoft Edge profile or Your Chrome profile.

Confirm by clicking Continue.

Give your passkey a name. By default Edge on Mac and Chrome on Mac are used.

Naming a device-bound passkey

As you can see, both passkeys are shown as device-bound.

Device-bound passkeys in Entra ID

From the device, the passkeys can be found in the profile you’ve created them in.

For Edge: edge://settings/autofill/passwords (how ironic)
For Chrome: chrome://settings/passkeys

Similar to storing passkeys in the TPM chip ( Windows Hello), these types of device-bound passkeys do not support attestation. If you have enforced attestation in Entra ID, the enrolment will fail, showing this error:

Passkey not registered. This might be due to a timeout, a canceled request, or a private browsing window.

Passkey registration error caused by attestation requirements

Here’s a quick video from the entire enrolment experience.

If you want to use your new, device-bound passkey, the browser will prompt you automatically.

Using a device-bound passkey in a browser

Let’s wrap up#

Synced passkeys are the way to go for most people. It’s easy, fast, and secure. Regardless of type, device-bound or synced, passkeys represent a significant security upgrade over phishable MFA methods.\

Some persona’s, like admins might require device-bound passkeys. In highly regulated environments, the accounts are probably using FIDO2 security keys, or Microsoft Authenticator app from managed mobile devices, but if you don’t have control over all the devices, storing device-bound passkeys in Windows Hello or Edge/Chrome on Mac might be a good alternative.

Stay safe!

Comments

Comments load when you scroll here.