It's repeatedly stated that pure on-premise ADDS environments are not supported. Will you offer insight into the reason for this decision and whether there are any plans to support these environments in the future? As far as I know, smart cards are the only other option in this regard and they require quite a bit more setup (CA management) and cost (infrastructure and multi-purpose keys to support both PIV and FIDO2).
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@gtbuchanan
Thanks for your feedback! We will investigate and update as appropriate.
PG response: AD DS is not seen as a fully authoritative Domain controller, so a lot of the capabilities will not work or be supported.
You are welcome to make a feature request for the PG here: https://feedback.azure.com/forums/34192--general-feedback
Here's the feedback submission for future reference