Hello @testuser7,
Thank you for posting your query on Microsoft Q&A.
It is correct that iOS devices strip off the attestation from the response-assertion provided by passkey providers, such as the Microsoft Authenticator app, as part of their privacy-preserving measures. Currently, for passkeys in Microsoft Authenticator, we do not support attestation.
Regarding the BS and BE flags, these flags indicate whether the passkey registration ceremony is being performed in a secure environment. If the BS and BE flags are set to zero, it means that the passkey registration ceremony is not being performed in a secure environment. However, this does not necessarily mean that the attestation blob will be stripped from the response-assertion.
In summary, iOS devices do not support attestation for passkey registration ceremonies, and the removal of attestation from the response-assertion is not directly related to the BS and BE flags.
Please refer to the following documentation for more information:
Hope this includes all the information that you were looking for.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.
Thanks,
Raja Pothuraju.