License needed for MFA with hardware token?

%3CLINGO-SUB%20id%3D%22lingo-sub-1771459%22%20slang%3D%22en-US%22%3ELicense%20needed%20for%20MFA%20with%20hardware%20token%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1771459%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ea%20customer%20of%20us%20wants%20to%20improve%20his%20MFA%20distribution.%20Therefore%20he%20wants%20to%20utilize%20hardware%20tokens%2C%20but%20there%20is%20no%20decision%20for%20TOTP%20or%20FIDO2%2C%20yet.%20Currently%20the%20customer%20utilizes%20Office%20365%20E3%20licenses%20for%20the%20end%20users%20and%20as%20the%20cloud%20strategy%20is%20not%20yet%20defined%20finally%2C%20he%20does%20not%20want%20to%20buy%20further%20%22addon%22%20licenses.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20present%20they%20have%20deployed%20basic%20MFA%20without%20Conditional%20Access.%20Is%20it%20possible%20to%20use%20any%20kind%20of%20hardware%20tokens%20without%20Azure%20AD%20Premium%20P1%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%2C%3C%2FP%3E%3CP%3EChristian%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1771459%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1779732%22%20slang%3D%22en-US%22%3ERe%3A%20License%20needed%20for%20MFA%20with%20hardware%20token%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1779732%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F281233%22%20target%3D%22_blank%22%3E%40woelki%3C%2FA%3E%26nbsp%3BHello%2C%20how%20about%20the%20Authenticator%20app%20until%20the%20strategy%20is%20defined%3F%20I'm%20attaching%20a%20couple%20of%20links%20below%20for%20information%20about%20available%20versions%20of%20Azure%20Multi-Factor%20Authentication%20and%20their%20associated%20licenses.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAvailable%20versions%20of%20Azure%20Multi-Factor%20Authentication%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fconcept-mfa-licensing%23available-versions-of-azure-multi-factor-authentication%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fconcept-mfa-licensing%23available-versions-of-azure-multi-factor-authentication%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20authentication%20and%20verification%20methods%20are%20available%20in%20Azure%20Active%20Directory%3F%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fconcept-authentication-methods%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fconcept-authentication-methods%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEnable%20passwordless%20sign-in%20with%20the%20Microsoft%20Authenticator%20app%20(preview)%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fhowto-authentication-passwordless-phone%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fhowto-authentication-passwordless-phone%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1805211%22%20slang%3D%22en-US%22%3ERe%3A%20License%20needed%20for%20MFA%20with%20hardware%20token%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1805211%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F232900%22%20target%3D%22_blank%22%3E%40Emin%20Huseynov%3C%2FA%3E%2C%3CBR%20%2F%3Ethanks%20for%20the%20confirmation.%20I%20already%20know%20Token2%2C%20but%20I%20have%20not%20yet%20tested%20all%20tokens.%3CBR%20%2F%3EI%20already%20found%20the%20manual%20for%20the%20MFA%20registration%20with%20Azure%20AD%20Free.%3CBR%20%2F%3EIt%20looks%20pretty%20forward%20for%20the%20most%20of%20us%20and%20it%20is%20a%20great%20idea%20just%20to%20ship%20the%20not%20marked%20device%20to%20the%20customers.%20But%20the%20impact%20on%20customer%20side%20is%20a%20bit%20bigger.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hi there,

 

a customer of us wants to improve his MFA distribution. Therefore he wants to utilize hardware tokens, but there is no decision for TOTP or FIDO2, yet. Currently the customer utilizes Office 365 E3 licenses for the end users and as the cloud strategy is not yet defined finally, he does not want to buy further "addon" licenses.

 

At present they have deployed basic MFA without Conditional Access. Is it possible to use any kind of hardware tokens without Azure AD Premium P1?

 

Thanks in advance.

 

Best regards,

Christian

3 Replies

@woelki Hello, how about the Authenticator app until the strategy is defined? I'm attaching a couple of links below for information about available versions of Azure Multi-Factor Authentication and their associated licenses.

 

Available versions of Azure Multi-Factor Authentication

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-licensing#availab...

 

What authentication and verification methods are available in Azure Active Directory?
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-method... 

 

Enable passwordless sign-in with the Microsoft Authenticator app (preview)

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-password...

Hi @woelki ,

You can benefit from programmable tokens - they act as drop-in replacement of Authenticator apps:

https://www.token2.swiss/shop/page/hardware-tokens-for-azure-cloud-multi-factor-authentication 

 

 

Hi @Emin Huseynov,
thanks for the confirmation. I already know Token2, but I have not yet tested all tokens.
I already found the manual for the MFA registration with Azure AD Free.
It looks pretty forward for the most of us and it is a great idea just to ship the not marked device to the customers. But the impact on customer side is a bit bigger.