Entra passkey registration sends hints ["security-key"] on Linux, blocking synced passkeys (1Password)

David Salinas 0 Reputation points
2026-10-09T11:39:09.97+00:00

We have a passkey profile that allows synced passkeys (no attestation, no AAGUID restrictions). Users can register 1Password passkeys from macOS, but not from Linux (Chrome and Edge): Security info > Add sign-in method > Passkey always opens the hardware-key dialog instead of 1Password.

The fido/create page sends hints: ["security-key"] to Linux user agents and ["client-device"] to macOS. If only that hint is removed client-side, 1Password registers the passkey and Entra accepts it as "Passkey (Synced)".

Is this intended? Is there a supported way to register synced passkeys from Linux?

The FIDO2 compatibility matrix lists Linux Chrome/Edge as supported and synced passkeys as GA, with no Linux exception.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Rauh, Alexander 240 Reputation points
    2026-10-10T13:48:35.65+00:00

    Hello David,

    the matrix you are quoting covers FIDO2 in general for synced Passkeys you can find the Matrix here this list only Includes Windows, MacOS, IOS and Android so Linux is not a documented platform for synced Passkeys.

    The documented route is that the users register the passkey on their phone in the 1Password app (minimum Version for IOS 17+ and Android 14+) following the Microsoft guide here and 1Password syncs it to their vault.

    Does the sign-in on Linux work with that passkey?

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.