May 18 2022 01:11 PM
Using FIDO2 devices physically attached to the Hyper-V host in a virtual machine is greatly needed, for instance for PAWs, where the user on his not-locked-down desktop/production-apps VM needs to do FIDO2 logins.
And now that Microsoft has commited to accellerate passwordless platforms , one would expect it to be a priority.
MS employees have said a year ago, that it was on the roadmap.
But when can we expect to see it coming?
May 30 2022 04:35 PM
Apr 11 2023 09:54 AM
Interested in FIDO2 passthrough also, because of PAWs use.
btw: Current Microsoft recommendation regarding PAWs/SAWs is to have both admin+user OSes as virtual machines
Apr 11 2023 10:20 AM
Apr 11 2023 11:57 AM - edited Apr 11 2023 12:01 PM
@KalimanneJ here under “Secure devices” section https://www.microsoft.com/insidetrack/blog/improving-security-by-protecting-elevated-privilege-accou...
Apr 15 2023 05:51 PM - edited Apr 15 2023 06:01 PM
I don’t see anywhere there that they are recommending against the SAW being a physical machine.
That link has a story that talks about them internally deploying proprietary customized, very locked down laptops with both the SAW and their everyday machine running as VMs on it.
It does not seem applicable to everyone else.
The base host laptop has to be locked down at least as much as a SAW would be or it will become a source of compromise and would make the SAW VM running on it also subject to compromise.
With that setup, you are running 3 operating systems that need management and patching, plus the laptop has to be powerful enough to run the local OS plus 2 additional copies of Windows as VMs and have licensing to do that.
Does not look practical!
Nov 21 2023 05:44 PM