Other issues or features related to Microsoft Edge on Windows 11
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Summary
On one of two Windows 11 Pro machines, creating or using a passkey via Microsoft Password Manager in Edge fails with "Can't reach Microsoft Password Manager". Chrome on the same machine succeeds. A second machine, configured as similarly as I can determine, works in Edge. I've narrowed the difference to Windows Hello provisioning state and would like to know whether that's the supported dependency.
Environment
PrincipalSource: Local)Symptom
| Machine A (fails) | Machine B (works) | |
|---|---|---|
| Edge + Microsoft Password Manager | "Can't reach Microsoft Password Manager" | Works |
| -------- | -------- | -------- |
| Edge + Microsoft Password Manager | "Can't reach Microsoft Password Manager" | Works |
| Chrome (→ Windows Hello) | Works | — |
| Biometric hardware | None (PIN only) | Fingerprint + camera |
Reproduced independently of any one site. The same failure occurs on passkeys.io in Edge on Machine A, and that site works in Chrome on the same machine — so it isn't specific to the website I was originally testing.
Event log evidence — Microsoft-Windows-WebAuthN/Operational:
Error 0x8000FFFF Catastrophic failure
WebAuthN error at: DsrGetJoinInfoNoAccessTokenUrl
(5 occurrences, each coinciding with a failed attempt)
Error 0x800704C7 The operation was canceled by the user
Ctap GetAssertion completed
(follows each failure; appears to be the dialog being dismissed)
IsUserVerifyingPlatformAuthenticatorAvailable reports true on the failing machine, so Windows believes a platform authenticator exists.
dsregcmd /status comparison
Machine A (fails) Machine B (works)
IsDeviceJoined NO NO
IsUserAzureAD NO NO
PolicyEnabled NO YES
PostLogonEnabled YES YES
DeviceEligible YES YES
PreReqResult WillNotProvision WillNotProvision
NgcSet NO (not captured)
Registry — the only Hello-related difference found:
HKLM\SOFTWARE\Policies\Microsoft\PassportForWork
Machine A : key absent
Machine B : Enabled (DWORD) = 1
Neither machine has PassportForWork under HKLM\SOFTWARE\Microsoft\Policies, HKCU\SOFTWARE\Policies\Microsoft, or PolicyManager\current\device.
Ruled out
DsrGetJoinInfo failure appears on both and is presumably normal for an unjoined machineQuestions
PassportForWork\Enabled = 1 a documented requirement for Microsoft Password Manager passkeys, or is PolicyEnabled: YES a side effect of something else?NgcSet: NO the actual blocker — i.e. does the password manager require a provisioned NGC container even when the credential is cloud-synced?PreReqResult is WillNotProvision on both machines, yet only one fails. What else differs that dsregcmd doesn't surface?Not yet attempted: setting PassportForWork\Enabled = 1 on Machine A, and clearing/re-enrolling the NGC store. Both are reversible but I'd rather understand the dependency than change security policy speculatively — particularly as the NGC-clearing fix recommended in this thread didn't resolve it for that reporter.
Point 4 is worth keeping in. "Can't reach" reads as a network problem and cost you most of a day on the wrong trail — that's actionable feedback regardless of what causes the underlying fault.
Sources: Microsoft Q&A ask page, answers.microsoft.com Windows forum, existing passkey threadSummary
On one of two Windows 11 Pro machines, creating or using a passkey via Microsoft Password Manager in Edge fails with "Can't reach Microsoft Password Manager". Chrome on the same machine succeeds. A second machine, configured as similarly as I can determine, works in Edge. I've narrowed the difference to Windows Hello provisioning state and would like to know whether that's the supported dependency.
Environment
PrincipalSource: Local)Symptom
| Machine A (fails) | Machine B (works) | |
|---|---|---|
| Edge + Microsoft Password Manager | "Can't reach Microsoft Password Manager" | Works |
| Chrome (→ Windows Hello) | Works | — |
| Biometric hardware | None (PIN only) | Fingerprint + camera |
Reproduced independently of any one site. The same failure occurs on passkeys.io in Edge on Machine A, and that site works in Chrome on the same machine — so it isn't specific to the website I was originally testing.
Event log evidence — Microsoft-Windows-WebAuthN/Operational:
Error 0x8000FFFF Catastrophic failure
WebAuthN error at: DsrGetJoinInfoNoAccessTokenUrl
(5 occurrences, each coinciding with a failed attempt)
Error 0x800704C7 The operation was canceled by the user
Ctap GetAssertion completed
(follows each failure; appears to be the dialog being dismissed)
IsUserVerifyingPlatformAuthenticatorAvailable reports true on the failing machine, so Windows believes a platform authenticator exists.
dsregcmd /status comparison
Machine A (fails) Machine B (works)
IsDeviceJoined NO NO
IsUserAzureAD NO NO
PolicyEnabled NO YES
PostLogonEnabled YES YES
DeviceEligible YES YES
PreReqResult WillNotProvision WillNotProvision
NgcSet NO (not captured)
Registry — the only Hello-related difference found:
HKLM\SOFTWARE\Policies\Microsoft\PassportForWork
Machine A : key absent
Machine B : Enabled (DWORD) = 1
Neither machine has PassportForWork under HKLM\SOFTWARE\Microsoft\Policies, HKCU\SOFTWARE\Policies\Microsoft, or PolicyManager\current\device.
Ruled out
DsrGetJoinInfo failure appears on both and is presumably normal for an unjoined machineQuestions
PassportForWork\Enabled = 1 a documented requirement for Microsoft Password Manager passkeys, or is PolicyEnabled: YES a side effect of something else?NgcSet: NO the actual blocker — i.e. does the password manager require a provisioned NGC container even when the credential is cloud-synced?PreReqResult is WillNotProvision on both machines, yet only one fails. What else differs that dsregcmd doesn't surface?Not yet attempted: setting PassportForWork\Enabled = 1 on Machine A, and clearing/re-enrolling the NGC store. Both are reversible but I'd rather understand the dependency than change security policy speculatively — particularly as the NGC-clearing fix recommended in this thread didn't resolve it for that reporter.
Point 4 is worth keeping in. "Can't reach" reads as a network problem and cost you most of a day on the wrong trail — that's actionable feedback regardless of what causes the underlying fault.
Sources: Microsoft Q&A ask page, answers.microsoft.com Windows forum, existing passkey thread
Other issues or features related to Microsoft Edge on Windows 11