Okta Authentication Fails With WebAuthN On Microsoft Cloud PC
Last Updated:
Overview
Users experience authentication failures in Okta when using a WebAuthN factor inside a Microsoft Cloud PC virtual machine because a local device setting blocks passkey access. Enabling the passkey setting on the physical device resolves the issue. The authentication succeeds on the local machine, but when an authentication policy requires a WebAuthN factor on the virtual machine, the Okta Sign-In Widget presents an immediate failure and generates the following error message:
The operation either timed out or was not allowed.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Cloud PC
- WebAuthN / YubiKey / Passkeys
- Multi-factor Authentication (MFA)
Cause
A setting on the physical device disables passkey access for the Microsoft Cloud PC. Without this setting enabled, the virtual machine cannot access passkeys or physical access keys attached to the local machine, causing the authentication request inside the Windows App to time out.
Solution
How is the WebAuthN timeout resolved on a Microsoft Cloud PC?
Enable the passkey setting on the physical device, then retry authentication to allow the virtual machine to access the attached security keys.
- Navigate to Settings > Privacy and security > Passkeys on the local physical device.
- Enable the Let apps create and use passkeys option.
- Attempt the Okta authentication again from within the Microsoft Cloud PC.
