<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Passkey Enrollment Fails on iPhone With Multi-Device Credentials Error

Okta Classic Engine
Okta Identity Engine
Multi-Factor Authentication

Overview

When attempting to enroll a passkey on an iPhone, the enrollment fails because the device attempts to create a synced credential via iCloud Keychain, which the Okta configuration blocks. To resolve this, administrators must either allow synced passkeys in the Okta policy or require users to enroll device-bound credentials. The following error message appears on the device screen during the enrollment process:

 

Your organization does not allow multi-device credentials/passkeys

 

 

Set up a passkey

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • FIDO2 (WebAuthn) Passkeys
  • Apple iOS

Cause

When an end user selects the setup option on an iPhone, iOS automatically attempts to create a passkey saved to iCloud Keychain. Fast Identity Online 2 (FIDO2) standards flag Apple Keychain passkeys as multi-device credentials because they sync across Apple devices. If the Block synced passkeys option is enabled in the Okta configuration, Okta rejects any enrollment request that attempts to create a multi-device synced credential.

Solution

What resolves the multi-device credentials error?

 

Navigate to the FIDO2 authenticator settings in the Admin Console and clear the restriction on synced passkeys to allow multi-device credentials.

  1. Navigate to the Admin Console.
  2. Go to Security and select Authenticators.
  3. Locate the Passkey (FIDO2 WebAuthn) authenticator and select Actions, then Edit.
  4. Clear the Block synced passkeys checkbox to allow multi-device credentials, as shown in the following configuration screenshot.
    Block synced passkeys
  5. Save the configuration.

 

NOTE: If the organization strictly requires device-bound credentials, leave the restriction enabled and instruct users to enroll using a hardware security key rather than the built-in iPhone passkey.

Loading
Okta Support - Okta Passkey Enrollment Fails on iPhone With Multi-Device Credentials Error