Okta Passkey Enrollment Fails on iPhone With Multi-Device Credentials Error
Last Updated:
Overview
When attempting to enroll a passkey on an iPhone, the enrollment fails because the device attempts to create a synced credential via iCloud Keychain, which the Okta configuration blocks. To resolve this, administrators must either allow synced passkeys in the Okta policy or require users to enroll device-bound credentials. The following error message appears on the device screen during the enrollment process:
Your organization does not allow multi-device credentials/passkeys
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- FIDO2 (WebAuthn) Passkeys
- Apple iOS
Cause
When an end user selects the setup option on an iPhone, iOS automatically attempts to create a passkey saved to iCloud Keychain. Fast Identity Online 2 (FIDO2) standards flag Apple Keychain passkeys as multi-device credentials because they sync across Apple devices. If the Block synced passkeys option is enabled in the Okta configuration, Okta rejects any enrollment request that attempts to create a multi-device synced credential.
Solution
What resolves the multi-device credentials error?
Navigate to the FIDO2 authenticator settings in the Admin Console and clear the restriction on synced passkeys to allow multi-device credentials.
- Navigate to the Admin Console.
- Go to Security and select Authenticators.
- Locate the Passkey (FIDO2 WebAuthn) authenticator and select Actions, then Edit.
- Clear the Block synced passkeys checkbox to allow multi-device credentials, as shown in the following configuration screenshot.
- Save the configuration.
NOTE: If the organization strictly requires device-bound credentials, leave the restriction enabled and instruct users to enroll using a hardware security key rather than the built-in iPhone passkey.
