FIDO2 token or other hardware tokens for combined MFA/SSPR Registration?

%3CLINGO-SUB%20id%3D%22lingo-sub-2676604%22%20slang%3D%22en-US%22%3EFIDO2%20token%20or%20other%20hardware%20tokens%20for%20combined%20MFA%2FSSPR%20Registration%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2676604%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20link%20says%20FIDO2%20security%20keys%20are%20an%20available%20choice%20for%20combined%20registration%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fconcept-registration-mfa-sspr-combined%23methods-available-in-combined-registration%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ECombined%20registration%20for%20SSPR%20and%20Azure%20AD%20Multi-Factor%20Authentication%20-%20Azure%20Active%20Directory%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22fido2.PNG%22%20style%3D%22width%3A%20985px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F305171i9F28DE9755A6B59A%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22fido2.PNG%22%20alt%3D%22fido2.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20I%20can't%20find%20any%20way%20to%20set%20either%20FIDO%20security%20key%20or%20mobile%20app%20code-only%20for%20SSPR.%26nbsp%3B%20Mobile%20app%20code%20SSPR%20option%20is%20requiring%20setting%20up%20a%20second%20SSPR%20option%20such%20as%20SMS.%20I%20don't%20see%20any%20option%20to%20add%20FIDO2%20security%20keys%20or%20hardware%20tokens%20for%20SSPR%20at%20all.%3C%2FP%3E%3CP%3EWe%20want%20to%20set%20users%20up%20so%20their%20options%20for%20MFA%20are%20just%20app%20codes%20(if%20the%20user%20uses%20a%20smart%20phone)%20or%20FIDO2%20tokens%20(if%20they%20don't%20use%20a%20phone).%26nbsp%3B%20We%20don't%20want%20SMS%2C%20email%20or%20security%20questions%20enabled%20at%20all%20even%20as%20a%20secondary%20option.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

This link says FIDO2 security keys are an available choice for combined registration:

 

Combined registration for SSPR and Azure AD Multi-Factor Authentication - Azure Active Directory | M...

 

 

fido2.PNG

 

However, I can't find any way to set either FIDO2 security key or mobile app code-only for SSPR.  Mobile app code SSPR option is requiring setting up a second SSPR option such as SMS. I don't see any option to add FIDO2 security keys or hardware tokens for SSPR at all.

We want to set users up so their options for MFA and SSPR are just authenticator app OTP codes (if the user uses a smart phone) or FIDO2 tokens (if they don't use a phone).  We don't want SMS, email or security questions enabled at all even as a secondary option.

0 Replies