Microsoft Entra ID can now hand the sign-in step of a federated domain to the system browser on Android, iOS, and managed macOS. This browser authentication for external identity providers lets users sign in to Outlook, Teams, OneDrive, and other brokered Microsoft apps with passkeys or
FIDO2 security keys issued by a third-party identity provider (IdP). The feature is off by default, works only for domains federated through
WS-Fed or
SAML 2.0, and requires a broker app on the device. You enable it per platform with Microsoft Graph or Microsoft Graph PowerShell. This article explains how it works, what you need, and where the documentation is unclear.
Source