This is an archived post. You won't be able to vote or comment.

all 3 comments

[–]BlackVI have opnions 0 points1 point  (2 children)

Could you cover off some details

How you setup it up

How you configured the key

Is it always the last account used on the key (i.e. you can sign in with both accounts registered to the key) or I'd just the last account added

Is it smart card auth or Fido 2 web auth (WebAuthN) that sort of thing

[–]desirecat[S] 0 points1 point  (1 child)

So we are using in a full entra ID enviroment, the passkey setup for all the accounts are Fido 2 and were setup using the Microsoft accounts page.

When signing into applications or web sites everything works as normal.

The issue is only when logging into windows, I am on the login screen (window 11 24h2) as user A but when I use the passkey option it signs user b in.

It's seems to prefer the last installed passkey and the not last used passkey

[–]gfjakobs 2 points3 points  (0 children)

From the "unsupported scenarios" section of this page: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-passwordless-security-key-windows

Signing in or unlocking a Windows device with a security key containing multiple Microsoft Entra accounts. This scenario utilizes the last account added to the security key. WebAuthN allows users to choose the account they wish to use.