Passkey as 2FA?
My workplace recently implemented passkey support in our SSO system. Unfortunately they only trust physical devices like a YubiKey for full passwordless login, so I can’t use 1Password for that. However they allow synced passkeys stored in 1Password to be used as a second factor instead of OTPs.
What I did: I deleted the old OTP and instead created a passkey by scanning the QR code provided by our SSO on my iPhone. This brought up 1Password, were I attached it to the correct item which has our websites, my username and password stored. To test, I navigated to outlook.office.com in Safari on the iPhone, which brought up our SSO login prompt. Now I was offered to use the passkey to login, with didn’t work, since it’s only authorised as 2FA, not for a full login.
Now the different UIs started kinda tripping over each other. I could not figure out how to select the correct user/PW combo from iOS/1Password’s menu to fill in instead of the passkey. I couldn’t even manually select the entry fields to enter or copy and paste user/PW. In the end I resigned, deleted the passkey and set up good old OTP again.
So my question boils down to this: Is there a way to set up 1Password so that it autofills user and PW on the first prompt, then uses the stored passkey on the following 2FA prompt?
Best regards, Armin
