Forum Discussion
woelki
Aug 03, 2021Iron Contributor
Set FIDO2 minimum pin length in a hybrid environment
Hi there, we have just established a successful pilot for FIDO2 security key usage with WHfB in a hybrid environment. The key which has been registered in Azure is able to authenticate the user on...
woelki
Oct 20, 2021Iron Contributor
I can tell you something about what I have found ou in the meantime. I had a chat with some 3rd party manufacturers and it looks like the minimum PIN lenght or complexity depends on the FIDO sticks themselves. Unfortunately you cannot manage this with Microsoft builtin management tools.
In most cases the standard FIDO sticks from all manufacturers are not able to do this, but the more expensive sticks with FIPS industry standard will let you change your PIN requirements.
In most cases the standard FIDO sticks from all manufacturers are not able to do this, but the more expensive sticks with FIPS industry standard will let you change your PIN requirements.
KalimanneJ
Oct 30, 2021Iron Contributor
Can you be more specific?
Please name some examples of FIDO sticks that let you change PIN requirements and what is the process to actually change the PIN requirements?
So, are you saying even these "more expensive sticks" don't have any kind of complex PIN requirement (blocking PINs like 1234 etc.) enabled out of the box by default?
Please name some examples of FIDO sticks that let you change PIN requirements and what is the process to actually change the PIN requirements?
So, are you saying even these "more expensive sticks" don't have any kind of complex PIN requirement (blocking PINs like 1234 etc.) enabled out of the box by default?