Block Synced Passkeys in Okta
Last Updated:
Overview
Passkeys implement the Fast IDentity Online 2 (FIDO2) standard, allowing Web Authentication (WebAuthn) credentials to synchronize across multiple devices and operating systems. The Okta passkey management feature allows administrators to block synced passkeys for new enrollments to prevent unmanaged devices from accessing sensitive applications. The solution section details the feature and answers frequently asked questions regarding its implementation and impact on end-users.
Applies To
- Okta Classic Engine
- Okta Identity Engine (OIE)
- iOS 16+
- iWatch iOS 9+
- macOS Ventura+
- iPadOS 16+
Solution
The Okta Passkey Management feature blocks synced passkeys for new enrollments.
The Block synced Passkeys for FIDO2 (WebAuthn) Authenticators feature allows administrators to block passkeys for new enrollments at an organizational level. This self-service feature is available in Okta Classic Engine and Okta Identity Engine (OIE) from the Settings page in the Okta Admin Console. When administrators enable this feature, it prohibits a user from enrolling with a multi-device FIDO credential, such as passkeys, and preempts any potential risks of unmanaged and insecure devices accessing sensitive applications.
NOTE:
- This does not affect existing enrollments, which continue to work according to their previous configuration. Okta is working on enhancing this feature so it applies to application sign-on policies in the future.
- When blocking the use of passkeys in the organization, users running macOS Monterey cannot enroll in Touch ID using the Safari browser.
- When administrators block passkeys in the organization, iPhone users running iOS 16 on their devices cannot use the FIDO2 (WebAuthn) authenticator. Okta recommends enabling Okta FastPass or security keys that support Near Field Communication (NFC) or USB-C instead. Okta supports device enrollments running iOS 16 after administrators block passkeys for non-passkey uses.
Enable the feature to block synced passkeys by navigating to the early access feature settings in the Okta Admin Console and toggling the feature.
The Passkey Management feature Affects Both Okta Classic Engine and Okta Identity Engine
The Block synced Passkeys for FIDO2 (WebAuthn) Authenticators feature is available in Okta Classic Engine and OIE from the Settings page in the Okta Admin Console. It is also available in the Multi-Factor Authentication (MFA) and Adaptive Multi-Factor Authentication (AMFA) SKUs, similar to WebAuthn.
What capabilities does the passkey management feature provide?
Administrators block all WebAuthn authenticators that are multi-device, such as passkeys, and any authenticator that lacks attestation. Okta blocks Safari Touch ID on macOS Monterey and Chrome on iOS 16 for new enrollments.
Does the feature impact both new and existing enrollments?
The feature specifically blocks new enrollments of FIDO2 WebAuthn authenticators. It does not impact existing enrollments. Okta plans to block authentication and apply blocks to application sign-on policies in the future.
What happens to users who currently use WebAuthn?
The feature only impacts new enrollments. Existing WebAuthn enrollments remain unaffected. Users continue to use their current WebAuthn authenticators without any change. Okta does not block existing WebAuthn passkey enrollments. Okta plans to enhance this feature so that application sign-on policies control passkey blocking using the hardware-protected checkbox. Once administrators select this option, Okta filters out all multi-device credentials, like passkeys, from sign-on. The release date for this enhancement remains undetermined.
Is it possible to use the current authentication methods on Mac and iOS devices?
Organizations must make choices if they rely on WebAuthn with Touch ID or Face ID as their core MFA solution. The self-service early access feature does not resolve the dilemma of whether to allow keys or prevent these devices from using the platform authenticator. For desktop environments, requiring Chrome and not supporting Safari is an option. This workaround is not feasible for iOS devices.
How does the feature affect other browsers like Chrome?
For new enrollments, Okta blocks all browsers, including Chrome, on iOS 16. There is no impact on other operating systems.
How can administrators determine if a user has enrolled a passkey?
There is currently no method to determine if a user enrolled a passkey. The best approach is to block passkeys entirely. For OIE environments, Okta FastPass serves as a better alternative.
Should administrators use this feature to block passkeys?
Passkeys are a type of FIDO2 credential, making them phishing-resistant and superior to passwords. However, if the enterprise enforces policies requiring hardware-protected and device-bound credentials, administrators must block passkeys because they are multi-device credentials that export from one device to another.
What are the potential disadvantages of allowing users to enroll in passkeys?
Passkeys are multi-device and export from secure, managed devices to potentially insecure, unmanaged devices. If the organization enforces access policies based on hardware-protected and device-bound credentials, allowing passkeys risks exposing sensitive applications to unmanaged devices that fail to conform to the device security posture specified by the administrator. This exposure leads to security breaches.
