<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Passkey Authentication Fails to Display QR Code in Azure Virtual Desktop

Okta Classic Engine
Okta Identity Engine
Authentication

Overview

Unsupported Bluetooth redirection in Azure Virtual Desktop (AVD) causes a missing QR code during Okta passkey authentication, requiring the use of a physical security key or alternative authenticator. When attempting to log in to AVD using a passkey, the QR code required for mobile scanning fails to display. Instead, a prompt appears requesting a USB security key.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Azure Virtual Desktop (AVD)
  • FIDO2 / WebAuthn / Passkeys

Cause

The QR code option for passkey authentication utilizes the FIDO2/WebAuthn hybrid (cross-device) transport flow. This process relies on a Bluetooth Low Energy (BLE) proximity check between the mobile device and the browser rendering the QR code. Microsoft documentation confirms that AVD sessions do not redirect or pass through Bluetooth. When the browser or operating system detects that no functioning Bluetooth radio is available, it automatically omits the QR code option and defaults to prompting for a physical security key.

Solution

How is the passkey authentication issue resolved in Azure Virtual Desktop?

Since Azure Virtual Desktop does not support Bluetooth redirection, the cross-device QR code flow fails. An alternative method must provide authentication.

Bypass the Bluetooth limitation in Azure Virtual Desktop by utilizing one of the following alternative authentication methods.

  • Insert a physical FIDO2 security key into the local machine and verify it when prompted by the operating system.
  • Configure and use an alternative authenticator for the authentication flow.
Loading
Okta Passkey Authentication Fails to Display QR Code in Azure Virtual Desktop | Okta Support