Passwordless authentication from unmanaged devices?

%3CLINGO-SUB%20id%3D%22lingo-sub-401448%22%20slang%3D%22en-US%22%3EPasswordless%20authentication%20from%20unmanaged%20devices%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-401448%22%20slang%3D%22en-US%22%3E%3CP%3EI%20see%20that%20we%20could%20enable%20Windows%20Hello%20for%20Business%20for%20company-owned%2C%20Hybrid%20AD%20Joined%20Windows%2010%20devices%20with%20would%20allow%20users%20to%20log%20into%20their%20PC%20with%20PIN%2C%20face%20or%20fingerprint%20and%20then%20get%20SSO%20into%20Office%20365%20apps%20as%20well%20as%20local%20AD%20resources%20(network%20shared%20drives%2C%20printers%20etc..).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20what%20about%20contractors%20(with%26nbsp%3B%20hybrid%26nbsp%3B%20AD%20user%20accounts%20in%20our%20domain%20and%20Office%20365%20tenant)%20using%20their%20own%20laptops%20both%20on%20the%20corporate%20office%20network%20and%20remotely%3F%26nbsp%3B%20These%20laptops%20will%20be%20managed%20by%20their%20employer%2C%20so%20we%20cannot%20manage%20them%20with%20Intune%20or%20any%20other%20MDM%20since%20their%20employer%20is%20already%20managing%20them.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20will%20provide%20them%20with%20third%20party%20MFA%20such%20as%20Duo%20Security%20for%20the%20Hybrid%20AD%20tenant%20using%20ADFS.%26nbsp%3B%20So%2C%20we%20want%20these%20users%20to%20be%20able%20to%20access%20the%20resources%20using%20MFA%20and%20some%20kind%20of%20passwordless%20authentication%20rather%20than%20type%20in%20their%20AD%20password.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESince%20they%20can't%20use%20Windows%20Hello%20For%20Business%20with%20our%20resources%2C%20what%20passwordless%20authentication%20options%20are%20available%20for%20them%20to%20access%20Office%20365%20apps%20from%20our%20Office%20365%20tenant%20(Exchange%20Online%20OWA%2C%20using%20the%20Outlook%20365%20desktop%20app%20or%20Outlook%202016%20desktop%20app%2C%20Teams%2C%20Skype%20For%20Business%20Online%2C%20SharePoint%20Online%2C%20One%20Drive%20For%20Business%20etc%2C)%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20about%20passwordless%20authentication%20to%20on%20prem%20AD%20resources%20such%20as%20shared%20network%20drives%20and%20network%20printers%3F%3C%2FP%3E%3CP%3EAlso%2C%20mobile%20apps%20for%20iOS%20and%20Android%20such%20as%20Exchange%20Active%20Sync%20email%20and%20Office%20mobile%20apps%20(Outlook%20for%20iOS%20and%20Android%2C%20Skype%20For%20Business%2C%20OneDrive%20For%20Business%2C%20SharePoint%2C%20Teams%20etc%2C)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWill%20certificate%20based%20authentication%20work%20with%20all%20these%20options%3F%26nbsp%3B%20What%20about%20using%20FIDO%20keys%3F%3C%2FP%3E%3CP%3EWhich%20passwordless%20options%20will%20work%20best%20when%20the%20devices%20can't%20be%20managed%20via%20MDM%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-401448%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20Apps%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESkype%20for%20Business%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Contributor

I see that we could enable Windows Hello for Business for company-owned, Hybrid AD Joined Windows 10 devices with would allow users to log into their PC with PIN, face or fingerprint and then get SSO into Office 365 apps as well as local AD resources (network shared drives, printers etc..).

 

However, what about contractors (with  hybrid  AD user accounts in our domain and Office 365 tenant) using their own laptops both on the corporate office network and remotely?  These laptops will be managed by their employer, so we cannot manage them with Intune or any other MDM since their employer is already managing them.

 

We will provide them with third party MFA such as Duo Security for the Hybrid AD tenant using ADFS.  So, we want these users to be able to access the resources using MFA and some kind of passwordless authentication rather than type in their AD password.

 

 

Since they can't use Windows Hello For Business with our resources, what passwordless authentication options are available for them to access Office 365 apps from our Office 365 tenant (Exchange Online OWA, using the Outlook 365 desktop app or Outlook 2016 desktop app, Teams, Skype For Business Online, SharePoint Online, One Drive For Business etc,)?  

What about passwordless authentication to on prem AD resources such as shared network drives and network printers?

Also, mobile apps for iOS and Android such as Exchange Active Sync email and Office mobile apps (Outlook for iOS and Android, Skype For Business, OneDrive For Business, SharePoint, Teams etc,)?

 

Will certificate based authentication work with all these options?  What about using FIDO keys?

Which passwordless options will work best when the devices can't be managed via MDM?

 

0 Replies