A lot of the discussion here points out that synced passkeys essentially just shift the trust to the user's OS or cloud password manager, like Apple Keychain or Google.
If an enterprise goes all-in on Entra passkeys, what is the threat model if a user's personal iCloud or Google account gets compromised? Does Entra just blindly trust the synced passkey when it's suddenly presented from a new device across the globe, or can Conditional Access actually detect that a synced key is being used outside of its original context and block it?