Apple passkey attestation: align identity and MDM
Apple lets an organization use a certificate presented during provisioning to verify that a passkey was created on a managed device. This evidence can strengthen an identity architecture when MDM, the certificate authority, and the web service share a precise policy.
1. What the attestation actually proves
The Passkey Attestation declarative configuration allows WebAuthn enterprise attestation for passkeys associated with defined domains. Apple states that the attestation takes the form of a certificate used during provisioning. The relying service can therefore obtain evidence linked to the managed context in which the passkey was created.
This evidence replaces neither user authentication nor conditional access rules or continuous compliance evaluation. It should not be confused with Managed Device Attestation, which covers cryptographically verified device identity and properties.
2. Apple requirements and limits to validate
Apple's matrix updated on September 17, 2026 continues to list availability from iOS 17, iPadOS 17, and macOS 14, with device or user channels depending on the platform. Apple documents Device Enrollment and Automated Device Enrollment, but not User Enrollment. The configuration page says supervision is not required.
The declaration requires an attestation identity from an ACME, SCEP, or PKCS#12 certificate asset and a list of relying parties. Only explicitly listed domains can request attestation when creating a passkey. On macOS, an optional setting controls whether the identity's private key is extractable; that choice must align with the organization's key-protection policy.
3. What does this change for a Belgian or French organization?
For a small business, this is useful mainly when an identity provider or business application can consume the attestation; enabling a declaration in isolation delivers no value. For a mid-market company, large enterprise, or public administration, it can help distinguish passkeys provisioned in a managed context from other credentials, particularly for sensitive applications.
Within the European Union, technical evidence should remain proportionate to its purpose. Security and compliance teams need to document allowed domains, transmitted data, certificate lifetime, and the handling of devices reassigned or removed from MDM. The control should support an explicit access policy, not indiscriminate collection.
4. Underside analysis: design the trust chain before the profile
Our assessment is that the challenge lies less in the MDM declaration than in aligning four components: directory and identity provider, MDM service, certificate infrastructure, and WebAuthn relying party. If one component cannot issue, distribute, request, or validate the evidence, the project remains incomplete.
In Jamf or another Apple MDM, first confirm the exact implementation of the configuration and identity assets. Apple notes that not every management service exposes every setting. The scope should then be aligned with Apple Business, Automated Device Enrollment, and the selected identity model, without assuming that attestation automatically grants access.
5. Recommended deployment plan
- Identify applications and domains that genuinely request and validate WebAuthn enterprise attestation.
- Select the certificate identity and its delivery method—ACME, SCEP, or PKCS#12—with the PKI team.
- Limit relying parties to strictly necessary domains and document each owner.
- Verify iOS, iPadOS, and macOS channels and confirm that the chosen MDM supports the declaration.
- Test creation, use, renewal, deletion, and recovery after erase or reassignment.
- Define behavior for missing or invalid attestation without arbitrarily blocking users.
- Log the access decision and prepare a support process for IT teams in Belgium and France.
Goal: use attestation as a verifiable signal in the identity policy, with controlled domains, certificates, and fallback rules.
Scope an Apple passkey and MDM projectOfficial sources: Apple Platform Deployment — Passkey Attestation declarative configuration and Apple Developer — SecurityPasskeyAttestation.