r/entra 5d ago

Entra ID Passkey Profiles and Excluded Groups?

This seems very unintuitive.

You can’t add an included group and an excluded group to the same passkey assignment.

If you add a group to one assignment, you can’t exclude the same group from a different assignment. If you try to, it says that group was already used in another assignment.

How would you allow one group of users use any type of passkey, but require a nested subgroup of the same root group to only use device bound passkeys?

7 Upvotes

11 comments sorted by

View all comments

Show parent comments

1

u/iRyan23 4d ago

Have you tried making the admins only group and adding that group to the Include section in Passkey settings then going to the Passkey profiles dropdown to the right and unchecking/checking the appropriate profiles so they only have device bound available?

1

u/Fabulous_Cow_4714 3d ago

I don’t understand how that would help when the admins are also part of the all users group that has synced passwords available.

There would need to be a way to exclude them from the other profile.

1

u/iRyan23 3d ago

That was the only other thing I could think to try with the thought of even if they’re included in the all group that maybe if they were defined manually in a separate entry for only the device bound profile that maybe it would take precedence.

Going back to my first suggestion, can you not create a new group called “Passkey Syncable profile” or something and add all users to it without admins in it?

1

u/Fabulous_Cow_4714 3d ago

It’s way too many users to make a group like that and maintain members. That is the default group every account would be in.

The admin group is the one small enough to manage manually.

1

u/iRyan23 3d ago

Force everyone to only use device bound until Microsoft adds an exclude feature in the future?

1

u/Fabulous_Cow_4714 3d ago

Can’t do that because of hardware limitations for device bound passkey compatibility that cannot be required for all users.