Okta Passkey Authentication Fails to Display QR Code in Azure Virtual Desktop
Last Updated:
Overview
Unsupported Bluetooth redirection in Azure Virtual Desktop (AVD) causes a missing QR code during Okta passkey authentication, requiring the use of a physical security key or alternative authenticator. When attempting to log in to AVD using a passkey, the QR code required for mobile scanning fails to display. Instead, a prompt appears requesting a USB security key.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Azure Virtual Desktop (AVD)
- FIDO2 / WebAuthn / Passkeys
Cause
The QR code option for passkey authentication utilizes the FIDO2/WebAuthn hybrid (cross-device) transport flow. This process relies on a Bluetooth Low Energy (BLE) proximity check between the mobile device and the browser rendering the QR code. Microsoft documentation confirms that AVD sessions do not redirect or pass through Bluetooth. When the browser or operating system detects that no functioning Bluetooth radio is available, it automatically omits the QR code option and defaults to prompting for a physical security key.
Solution
How is the passkey authentication issue resolved in Azure Virtual Desktop?
Since Azure Virtual Desktop does not support Bluetooth redirection, the cross-device QR code flow fails. An alternative method must provide authentication.
Bypass the Bluetooth limitation in Azure Virtual Desktop by utilizing one of the following alternative authentication methods.
- Insert a physical FIDO2 security key into the local machine and verify it when prompted by the operating system.
- Configure and use an alternative authenticator for the authentication flow.
