Skip to main content
Skip table of contents

Fido passkey provisioning with Microsoft Entra

This article is new for Identity Manager 5.1.0.

This article describes Fido passkey provisioning with Microsoft Entra.

Prerequisites

  • Identity Manager 5.1.0 or later versions.

  • Hermod 4.2 or later versions.

  • Smart ID Desktop App 2.4 or later versions.

Register a passkey in Entra from an IDM process

The diagram below shows Entra Fido provisioning with Hermod.

EntraFidoProvisioningHermod.jpeg

Demo process

The example process "Entra ID - Hermod Create Fido Passkey" (EntraFidoProvisioningWithHermod.bpmn) in the default.zip illustrates how passkey provisioning is working and how the new service tasks are interacting. It is using a Parallel Gateway.

Make sure the "Hermod: Fido Create Credential" task has the Async option checked.

image-2025-4-7_10-52-45.png

The plugout URL form is used to trigger communication with Smart ID Desktop App on the client.
The parallel service task requests the actual creation of the credential from Smart ID Desktop App and runs in the background while the form is shown to the user.
Both parallel executions come together and proceed when creation is ready and the user clicks next on the form.

This demo process is just a simple example. Make sure to add error handling to make it usable in a customer project.

Links to service tasks

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.