Adding a Bitwarden Synced Passkey to an Entra ID account

Huzzah! Finally! Just in time for Christmas…

Microsoft recently announced the Public Preview of Synced Passkeys. Prior to this announcement, Microsoft only supported Passkeys that were tied to a device (Device Bound) and did not support the use of Passkeys which could be synchronised between platforms such as Bitwarden, 1Password or platforms without Microsoft Authenticator.

I know from being present and active on the Bitwarden forums that people are crying out for this. So, in this guide, I’ll show you how to configure Entra ID Authentication Methods to utilise Preview Authentication Profiles and enable Synced Passkeys. After which, I’ll demonstrate how to utilise Bitwarden to host a Passkey and use it across multiple devices.

Without further ado…

How to Enable Synced Passkey Support in Entra ID

Login to Microsoft Entra.

Click on Authentication Methods from the left-hand menu.

Click on Passkey (FIDO2).

You’ll notice at the top of the Passkey (FIDO2) settings page you have the option to “Begin opting-in to public preview“. You’ll need to click on this, as without Preview Support, you’ll not be able to utilise Synced Passkeys.

With the Preview functionality enabled, we now get “Passkey Profiles” under the Configure tab. You’ll also notice you have the “Allow self-service set-up” option, which is probably best being ticked. Without this enabled, users will not be able to register Passkeys.

What we need to do now is click on Add Profile and complete the Profile settings as desired. Whether you want to Target Specific AAGUID’s or not, is up to you. Enabling this option allows you to be a bit stricter on which Sync’able providers can be used.

Note: Ticking “Enforce Attestation” will prevent “Synced (Preview)” from being selectable in the Target Types drop down. For now, we cannot leverage attestation, which may put some larger enterprises or more risk-averse off.

Remember though, this is a Preview. So it’s unlikely you’re going to want this in production right now.

In the example below I have ticked “Target specific AAGUIDs” and limited this Profile to ONLY the Bitwarden AAGUID to the Model/Provider list.

The FIDO2 specification requires each security key vendor to provide an Authenticator Attestation GUID (AAGUID) during registration. An AAGUID is a 128-bit identifier indicating the key type, such as the make and model. Passkey (FIDO2) providers on desktop and mobile devices are also expected to provide an AAGUID during registration.

The Bitwarden AAGUID is: d548826e-79b4-db40-a3d8-11116f7e8349 (Reference).

And that’s all there is to the Profile configuration. So, after hitting Save, all you then need to do, is assign the profile. In the image below, I have a Security Group named “James Vincent (User)” with only my User Account assigned (purely for testing).

After assigning the Profile, I made a cup of tea and then returned to set about trying to register a shiny new “Synced Passkey”.

Registering a Synced Passkey to your Entra ID account

For sanity purposes, I launched an InPrivate session in Edge and hit up https://myaccount.microsoft.com/

I proceeded to Sign In.

From My Account, click on Security Info down the left hand menu.

Click Add sign-in method

Select “Passkey“. (Not, the option “Passkey in Microsoft Authenticator”)

Click Next on the “Sign in faster” prompt.

At this point, the Bitwarden extension should jump into play, and ask you which account you want to save this passkey to. Make sure you choose the correct account; else fun could ensue.

Give your Passkey a name/reference to help identify where this Passkey lives or originates from.

And where normally, you’d have had an error, you now get a pat on the back and a lovely “Passkey created” confirmation.

In Security Info you’ll now see the “Synced” Passkey – hurrah!

If we look in our Bitwarden Vault now, we can see the Passkey registered against the login details.

Using the Passkey stored in Bitwarden

The beauty of using a Private Browser session, is that closing it down, means all cookies etc are long gone.

I fired up another Private Session, and revisited https://myaccount.microsoft.com/

Immediately click “Sign-in Options

And then select “Face, Fingerprint, PIN or Security Key

Bitwarden should now kick in asking you to select a Passkey (registered to login.microsoft.com, of which I have many) that you wish to use to Sign-in.

…and there you have it!

Just for good measure, I also tested the synced aspect and attempted to login to https://myaccount.microsoft.com/ using my iPhone – with the same success.

It’s been a long time coming, but finally. I can store my Entra ID Passkeys in Bitwarden.

Yay!

James avatar

8 responses to “Adding a Bitwarden Synced Passkey to an Entra ID account”

  1. Hany E

    Hi James,

    Great article, I have followed it and it works up to the point of saving the passkey; after Bitwarden saves the passkey, Microsoft asks to name the passkey and this is when it comes up with an error “Passkey not registered” “This might be due to a timeout, a canceled request or a private browsing window.” … have you faced this issue or know what the solution is ? Is it Bitwarden related ? Is it some timeout or prompt that is not working ?

    1. James

      Are you trying to add your “Passkey” on a device with Windows Hello enabled? Or have you previously marked the domain as “Always use Hardware Passkey” when Bitwarden originally prompted?

      Try adding it on your phone or A N Other device. My heads saying it’s a device specific issue.

  2. Ron

    Thank you for the clear procedure which works with one modification. bitwarden ext must be active & it is not active in a “private edge session”. Thus, a private session will trigger Microsoft attempting to save the passkey locally.

    Or Edge installed extensions > BitWarden > Allow in Private

    1. James

      This is a given. Bitwarden has to be running, of course.

  3. Ish Rashad

    Thanks for the wonderfully clear walk-through. I’d like to say it’s been successful, but I have hit a snag. And I think it is a misunderstanding on my part.
    To gloss over unnecessary detail: I use Firefox, but it gave me hell setting up the Passkey in the Entra admin centre, so I’ll step around it for now.
    I was successful with setting it up in Chrome, following your guide. It shows Passkey(synced) as an authentication method, everything looks fine.
    However – when I try a fresh login to test, the login window recognises that I have a passkey set up – but asks me for a PIN a la Windows Hello.
    I noticed that in an earlier post, you asked someone the question”Are you trying to add your “Passkey” on a device with Windows Hello enabled? ”
    Is that a no-no? Because I do have Windows Hello enabled, and usually sign into this device with a PIN.
    Like others, I use passkeys on other sites and it works fine. It’s only MS that seems really pernickety.
    Any thoughts about what I may be bumping my head against?
    Cheers.

    1. James

      Hi there,

      When creating a passkey, Windows Hello might intercept the prompt. If you save a passkey directly into Windows Hello instead of Bitwarden, it will not sync across your devices. Furthermore, passkeys saved natively in Windows Hello on Windows 10/11 do not support vault decryption (PRF capability).

      This/that was the reason I mentioned using another device, and it remains true today. I’m unsure if you can negate the Hello prompt to prevent interception. You probably can, but I’m unsure how right now.

  4. Philipp

    Hello,
    I have provisioned and synchronized my Microsoft Entra ID users to Bitwarden so that they can sign in to Bitwarden using Entra SSO.

    I am now testing synced passkeys. The Entra ID passkey is stored in the user’s Bitwarden vault and can be used successfully for Microsoft sign-ins once Bitwarden is already unlocked.

    However, this creates a circular dependency when the user signs in on a new device:

    The user needs to authenticate to Entra ID in order to access Bitwarden via SSO.
    The Entra ID passkey required for that authentication is stored in Bitwarden.
    Bitwarden is not yet signed in or unlocked on the new device.
    Microsoft is increasingly moving towards passkeys as the default authentication experience and is also providing mechanisms to enforce phishing-resistant authentication through Microsoft Entra ID and Conditional Access. This makes the bootstrap problem even more important: if passkeys become mandatory or password-based fallback authentication is no longer available, users may be unable to access Bitwarden in order to retrieve the very passkey required to authenticate to Entra ID.

    What is the recommended bootstrap or recovery method for this scenario?

    Should users retain an additional authentication method outside Bitwarden, such as a Temporary Access Pass, Microsoft Authenticator, Windows Hello for Business, or a physical FIDO2 security key?

    If passkeys are enforced for the user through Microsoft Entra ID, can a Temporary Access Pass or another independent phishing-resistant method still be used to access Bitwarden for the initial setup or recovery of a new device?

    Ideally, I would like to use the Bitwarden-stored synced passkey for normal day-to-day authentication while still having a secure and well-defined process for:

    first-time setup,
    signing in on a new device,
    a locked or unavailable Bitwarden vault,
    device replacement,
    lost or reset devices,
    and account recovery.
    Is there a recommended architecture or deployment pattern for using Bitwarden as the synced passkey provider for Microsoft Entra ID without creating a circular authentication dependency?

    1. James

      That’s some conundrum you outline Philipp! Being honest, the best suggestion from me, would be to reach out to Bitwarden support or their community, someone more closely aligned to Bitwarden, especially in Enterprise will give you a much better answer.

      However, if I understand correctly, surely the recommended approach is to register multiple independent authentication methods? The Bitwarden stored passkey can be used for normal authentication, but it shouldn’t be the user’s ONLY Entra credential. In my head, users should retain another method outside Bitwarden, for example Windows Hello for Business, Authenticator or something like a physical FIDO key. I guess TAP could be an additional fallback even further.

Leave a Reply

Your email address will not be published. Required fields are marked *