Native Passkey Support in Embedded Browsers for Microsoft Admin Center

Native Passkey Support in Embedded Browsers for Microsoft Admin Center

2 votes

avatar

Add native Passkey (WebAuthn) redirection support within the embedded browser session window (specifically for Edge/Chrome engines). This will allow MSPs and enterprise administrators to leverage the Private Mode (Tenant Isolation) feature while simultaneously adhering to Microsoft’s mandatory phishing-resistant MFA requirements (such as Entra Admin Center passkey logins).

Currently, Remote Desktop Manager (RDM) handles multi-tenant isolation beautifully via Private Mode in embedded browser entries. However, as Microsoft aggressively pushes phishing-resistant authentication—making passkeys mandatory for Entra admin center access—administrators hit a wall.
When trying to authenticate using a passkey inside an embedded browser tab, the WebAuthn API call fails or is unable to use the added passkey from the DVLS safe.
To work around this, we are forced to open sessions in an External Browser. While this fixes authentication, it completely breaks the tenant isolation benefits of Private Mode and clutters the local machine with multiple browser profiles. As an MSP, we need to open lots of Microsoft Admin Centres at the same time.. It is therefore necessary to have a central overview, with each entry opening in the embedded browser.

We need the embedded browser component in RDM to natively support integrated passkeys in the DVLS safe.

  1. Seamless MFA: When a website inside an embedded tab requests a passkey, RDM should trigger the integrated passkey.
  2. Best of Both Worlds: Keep the excellent session isolation provided by Private Mode and allow administrators to log in using modern passkeys securely.

Why This Matters

  • Mandatory Microsoft Requirements: Microsoft is steadily rolling out mandatory phishing-resistant MFA for all admin portals. This isn't a "nice-to-have" anymore; it is becoming a hard blocker for daily administration.
  • Crucial for MSPs: Managing dozens of Entra tenants requires strict isolation to prevent accidental cross-tenant data leaks or session bleeding.
  • Productivity: Switching back and forth between embedded and external browsers breaks the unified "single pane of glass" workflow that makes RDM so powerful.

All Comments (4)

avatar

Hi @podralski,

Thank you for reaching out, this has been in our plans for a while, I'll look into bumping priority.

Cheers,

Luc Fauvel

avatar

Hi, we wanted to emphasize our support for this feature request.

As far as I know, Microsoft will enforce phishing resistant authentication for all its 365 admin portals.
Our sysadmins work 100% in RDM, and we don’t use the browser extension.
Therefore, we need RDM to be able to handle Passkeys in the WebSessions with the embedded Edge.
The documentation suggests that this is something not possible today, or I couldn’t find it.

Thank you very much for listening!

Reference: 00124893: RDM PassKey support

--
Citrix Technology Advocate (CTA) at https://www.meinekleinefarm.net

avatar

Hi @Marco Hofmann,

Just to be certain, currently passkeys work with the embedded browser only if the passkey is not stored in RDM.

If your passkey is on a YubiKey for example, this should currently work.

What we’re working on is getting Devolutions provided passkeys to work with RDMs embedded browser.

If you currently have issues with externally stored passkeys and the embedded browser, please let us know.

Cheers,

Luc Fauvel

avatar

Hi Luc,

> If your passkey is on a YubiKey for example, this should currently work.
We have our personal passkeys on YubiKey, but that is not opur use-case.

> What we’re working on is getting Devolutions provided passkeys to work with RDMs embedded browser.
This is what we are looking for.

> If you currently have issues with externally stored passkeys and the embedded browser, please let us know.
This i not something we are looking for.

We are an IT-MSP. For some customers, we have a Global Admin available to use, currently secured with TOTP, besides the GDAP access, to administrate the customers tenant.
We want to replace TOTP for this shared Global Admin, with a Passkey stored in DVLS, to be used in an embedded WebSession in RDM.

--
Citrix Technology Advocate (CTA) at https://www.meinekleinefarm.net