Forum Discussion

jameswonderguy's avatar
jameswonderguy
Copper Contributor
Mar 03, 2024

Passwordless setup for environment with only desktops

Hi,

 

We have a requirement to build a restricted network infrastructure with only desktops for users. The users will not be provided or allowed to use any other device like laptop, mobile, etc. Plus, they will not have email access and the desktops will be shared between the users.

 

Our objective is implement passwordless authentication for user authentication. The desktops could either be Microsoft Entra ID joined or hybrid joined.

 

FIDO2 security key

As per the link below, the 1st requirement for FIDO2 security key based passwordless authentication is Multi-Factor Authentication. MFA cannot be met because the users are only provisioned with desktops.

https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-passwordless-se...

 

Windows Hello for Business

It appears from the below link that Windows Hello for Business is not an option either because the users would use shared desktops.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless

 

Can Temporary Access Pass (TAP) be used in a restricted scenario like this OR am I missing some thing?

 

 

Thanks!

James

Resources