Did the product group take a closer look into the CTAP2-spec i.e. so that we can use Enpass as an external authenticator on a smartphone while logging into a website on a different device.
The scenario is the following
user navigates to a website (i.e. github, any google-workspace or o365 app etc)
app triggers passwordless auth
user scans qr-code (or app triggers ctap handshake through nfc/ble) with enpass on smartphone and finishes login
In that scenario it wouldn't be necessary to install enpass on the device, that triggers the login.
Client to Authenticator Protocol (CTAP)
Big news in our drive to eliminate passwords: FIDO2 / WebAuthn reaches candidate recommendation status! | Microsoft 365 Blog