Forum Discussion
Chris-Yue
Jun 01, 2021Iron Contributor
Managing PIN complexity on FIDO Security Keys
I have FIDO2 security keys working as part of Windows Hello for Business login to Windows 10 devices. Whilst I can set PIN complexity as part of the user gesture PIN code, I don't seem to be able...
SorenSonnichsen225
Copper Contributor
Hi, we have the exactly same issue, we would like to use FIDO2 keys, but the PIN security is way to bad for our security department.
Does anyone at Microsoft have an answer?
Does anyone at Microsoft have an answer?
Jan Bakker
Feb 23, 2022Iron Contributor
FIDO2 standard does not use complexity by default.
So 1111 and 1234 are allowed.
So 1111 and 1234 are allowed.
- SorenSonnichsen225Feb 23, 2022Copper ContributorHi Jan
Yes, and that is exactly the issue.
Do you know whether it is possible to apply/force complexity rules to FIDO2 devices?- Jan BakkerFeb 27, 2022Iron ContributorUnfortunately not.
But check out this key: https://janbakker.tech/this-might-be-the-fido2-key-for-you-authentrend-atkey-pro/
You can do offline enrollment of the fingerprint, so a user is never prompted to configure a PIN. If you’re interested, please ping me on socials for a free sample.- KalimanneJMar 10, 2022Iron ContributorThen what happens if the user’s fingerprint fails to be read for any reason such as wet hands?
The FIDO2 keys generally fail over to the PIN after some number of biometric fails and they won’t know the PIN.