Forum Discussion
What is the roadmap for FIDO2 passthrough from Hyper-V host to VM?
The PAW is supposed to be a physical machine; not a VM.
Also, would using Yubikeys as smartcards instead of FIDO2 keys be an alternative for Hyper-V VMs until FIDO2 support is available?
Interested in FIDO2 passthrough also, because of PAWs use.
btw: Current Microsoft recommendation regarding PAWs/SAWs is to have both admin+user OSes as virtual machines
- KalimanneJApr 11, 2023Iron ContributorWhere are you seeing this “current” recommendation that a PAW should be a VM?
I have only seen Microsoft recommending VMs for creating a lab environment for testing.
They have always recommended that the PAW be on a locked down physical device and you run a VM or have a separate device for your non-admin use. They recommended that the PAW be physical so that a compromised VM host doesn’t compromise the virtualized PAW. They have always said to not sign-in to a higher privileged device from a lower privileged device.- MypetrApr 11, 2023Copper Contributor
KalimanneJ here under “Secure devices” section https://www.microsoft.com/insidetrack/blog/improving-security-by-protecting-elevated-privilege-accounts-at-microsoft/
- KalimanneJApr 16, 2023Iron Contributor
I don’t see anywhere there that they are recommending against the SAW being a physical machine.
That link has a story that talks about them internally deploying proprietary customized, very locked down laptops with both the SAW and their everyday machine running as VMs on it.
It does not seem applicable to everyone else.
The base host laptop has to be locked down at least as much as a SAW would be or it will become a source of compromise and would make the SAW VM running on it also subject to compromise.
With that setup, you are running 3 operating systems that need management and patching, plus the laptop has to be powerful enough to run the local OS plus 2 additional copies of Windows as VMs and have licensing to do that.Does not look practical!