Managing profiles and sync in Microsoft Edge on Windows 10
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Issue Summary: Microsoft Edge SSO (Single Sign-On) functionality broken after upgrading from version 143 to 144+ in Azure Virtual Desktop environment using device-bound Microsoft Authenticator passkeys.
Environment:
Working Configuration:
Broken Configuration:
Troubleshooting Steps Taken:
Expected Behaviour: Edge should automatically sign in to the user's Entra ID profile using SSO/PRT (Primary Refresh Token) and allow seamless access to Conditional Access-protected resources, as it did in version 143 and earlier.
Actual Behaviour: Edge treats the profile as unsigned or in a degraded sign-in state, prompting manual authentication and breaking SSO to protected web resources.
Business Impact: Users are unable to seamlessly access enterprise web applications in our AVD environment, requiring manual authentication steps that were not previously necessary. We are currently holding Edge at version 143 to maintain functionality, which is not sustainable long-term.
Request: Please investigate whether Edge 144+ has introduced changes to profile sign-in state validation or Windows Authentication Manager integration that affect device-bound passkey authentication scenarios in Azure Virtual Desktop environments.
Managing profiles and sync in Microsoft Edge on Windows 10
The issue you are experiencing with Microsoft Edge SSO functionality after upgrading from version 143 to 144+ in an Azure Virtual Desktop environment appears to be related to changes introduced in version 144. Specifically, the known issue noted in the Edge 144 release states that users who have not fully completed their Microsoft Entra ID sign-in for their Edge profile may face difficulties accessing Conditional Access (CA) protected web resources, which aligns with your observation of being prompted for manual authentication instead of seamless SSO.
Given that you have confirmed the issue persists even in version 144.0.3719.104, where the known issue was reportedly fixed, it suggests that there may be additional factors at play, particularly the interaction between Azure Virtual Desktop, FSLogix profile containers, and device-bound passkey authentication. The new profile sign-in state validation introduced in version 144 may not be compatible with your current authentication setup.
To resolve this, it may be beneficial to monitor future updates from Microsoft regarding Edge, as they may address this regression. Additionally, consider reaching out to Microsoft support for further investigation into the specific interaction between Edge 144+ and your Azure Virtual Desktop environment with device-bound passkeys.
References: