Tech Community Live: Windows edition
Jun 05 2024, 07:30 AM - 11:30 AM (PDT)
Microsoft Tech Community

What is the roadmap for FIDO2 passthrough from Hyper-V host to VM?

Brass Contributor

Using FIDO2 devices physically attached to the Hyper-V host in a virtual machine is greatly needed, for instance for PAWs, where the user on his not-locked-down desktop/production-apps VM needs to do FIDO2 logins.

 

And now that Microsoft has commited to accellerate passwordless platforms , one would expect it to be a priority.

 

MS employees have said a year ago, that it was on the roadmap.

But when can we expect to see it coming?

6 Replies
Has anyone heard anything on this?

The PAW is supposed to be a physical machine; not a VM.
Also, would using Yubikeys as smartcards instead of FIDO2 keys be an alternative for Hyper-V VMs until FIDO2 support is available?

Interested in FIDO2 passthrough also, because of PAWs use.

btw: Current Microsoft recommendation regarding PAWs/SAWs is to have both admin+user OSes as virtual machines

Where are you seeing this “current” recommendation that a PAW should be a VM?
I have only seen Microsoft recommending VMs for creating a lab environment for testing.
They have always recommended that the PAW be on a locked down physical device and you run a VM or have a separate device for your non-admin use. They recommended that the PAW be physical so that a compromised VM host doesn’t compromise the virtualized PAW. They have always said to not sign-in to a higher privileged device from a lower privileged device.

I don’t see anywhere there that they are recommending against the SAW being a physical machine.
That link has a story that talks about them internally deploying proprietary customized, very locked down laptops with both the SAW and their everyday machine running as VMs on it.
It does not seem applicable to everyone else.
The base host laptop has to be locked down at least as much as a SAW would be or it will become a source of compromise and would make the SAW VM running on it also subject to compromise.
With that setup, you are running 3 operating systems that need management and patching, plus the laptop has to be powerful enough to run the local OS plus 2 additional copies of Windows as VMs and have licensing to do that.

Does not look practical!

What about if I’m an engineer and I have the option to run AWS commands in Powershell, but I would prefer to use a Linux environment in WSL for that. I would have to let WSL access my hardware device correct?