Back to the blog

Apple passkey attestation: align identity and MDM

Article created October 4, 2026 · Source reviewed October 4, 2026 · Official matrix updated September 17, 2026: Apple Platform Deployment · Topic: passkeys, identity, and Apple security

Apple lets an organization use a certificate presented during provisioning to verify that a passkey was created on a managed device. This evidence can strengthen an identity architecture when MDM, the certificate authority, and the web service share a precise policy.

1. What the attestation actually proves

The Passkey Attestation declarative configuration allows WebAuthn enterprise attestation for passkeys associated with defined domains. Apple states that the attestation takes the form of a certificate used during provisioning. The relying service can therefore obtain evidence linked to the managed context in which the passkey was created.

This evidence replaces neither user authentication nor conditional access rules or continuous compliance evaluation. It should not be confused with Managed Device Attestation, which covers cryptographically verified device identity and properties.

2. Apple requirements and limits to validate

Apple's matrix updated on September 17, 2026 continues to list availability from iOS 17, iPadOS 17, and macOS 14, with device or user channels depending on the platform. Apple documents Device Enrollment and Automated Device Enrollment, but not User Enrollment. The configuration page says supervision is not required.

The declaration requires an attestation identity from an ACME, SCEP, or PKCS#12 certificate asset and a list of relying parties. Only explicitly listed domains can request attestation when creating a passkey. On macOS, an optional setting controls whether the identity's private key is extractable; that choice must align with the organization's key-protection policy.

3. What does this change for a Belgian or French organization?

For a small business, this is useful mainly when an identity provider or business application can consume the attestation; enabling a declaration in isolation delivers no value. For a mid-market company, large enterprise, or public administration, it can help distinguish passkeys provisioned in a managed context from other credentials, particularly for sensitive applications.

Within the European Union, technical evidence should remain proportionate to its purpose. Security and compliance teams need to document allowed domains, transmitted data, certificate lifetime, and the handling of devices reassigned or removed from MDM. The control should support an explicit access policy, not indiscriminate collection.

4. Underside analysis: design the trust chain before the profile

Our assessment is that the challenge lies less in the MDM declaration than in aligning four components: directory and identity provider, MDM service, certificate infrastructure, and WebAuthn relying party. If one component cannot issue, distribute, request, or validate the evidence, the project remains incomplete.

In Jamf or another Apple MDM, first confirm the exact implementation of the configuration and identity assets. Apple notes that not every management service exposes every setting. The scope should then be aligned with Apple Business, Automated Device Enrollment, and the selected identity model, without assuming that attestation automatically grants access.

5. Recommended deployment plan

Goal: use attestation as a verifiable signal in the identity policy, with controlled domains, certificates, and fallback rules.

Scope an Apple passkey and MDM project

Official sources: Apple Platform Deployment — Passkey Attestation declarative configuration and Apple Developer — SecurityPasskeyAttestation.