Forum Discussion

  • Thijs Lecomte's avatar
    Thijs Lecomte
    Bronze Contributor
    Hi Bart

    Currently there isn't a way to setup FIDO2 as MFA only. It also replaces your password
    • ChristianBergstrom's avatar
      ChristianBergstrom
      Silver Contributor
      Yeah, as noted above I had some question marks about the topic and only posted a link to the preview and a link as how to configure step-by-step. The very fundamental is the passwordless Multi-Factor Authentication itself so to speak.

      Anyway, I believe this sums it up very well.

      ”Passwordless authentication is a form of multi-factor authentication (MFA) that replaces passwords with two or more verification factors secured and encrypted on a user’s device, such as a fingerprint, facial recognition, a device pin, or a cryptographic key.”
    • Anuj_Rana's avatar
      Anuj_Rana
      Copper Contributor
      We dont need to set it up as MFA. You will see it as MFA option if Key is registered and supports U2F.
    • bart_vermeersch's avatar
      bart_vermeersch
      Steel Contributor
      Sorry if my question wasn't clear enough, I know FIDO can be used for passwordless log on, but can it be used as an MFA token (instead of an authenticator app or SMS).
      • A-Zure's avatar
        A-Zure
        Copper Contributor
        Bart, if you purchase a key such as Yubikey 5 that supports OTP, then the user can retrieve an OTP code from the device using Yubi Authenticator desktop app. That would only be needed for apps/browsers that don't support WebauthN protocol such as IE. I don't understand why you would want to get the OTP code otherwise, using passwordless auth is much simpler and more secure. It satisfies the MFA requirement, so the user doesn't get prompted for MFA when using FIDO2.
  • Hello Bart, my apologies for not fully understand your question recently. Too much going on to be honest. To answer your question though... it is planned.

    ”Azure AD now supports FIDO2 security keys in public preview. We’re working on allowing them to be used as a second factor as well (today they are used only first in sequence, but they satisfy MFA).”
    • ScottFarquhar_EXPD's avatar
      ScottFarquhar_EXPD
      Copper Contributor

      ChristianBergstrom do you know the timeline of when FIDO2 keys will be able to be used as an MFA for Windows Hello for Business?  Currently you can only use Facial recognition, fingerprint, pin, bluetooth device (e.g. cell phone), etc.  The process for enabling these is via  GPO and making sure you put in the correct code that matches the device you are using for MFA, however I can't find what that code would be for a FIDO2 key?  Multi-factor Unlock - Windows security | Microsoft Docs

  • Anuj_Rana's avatar
    Anuj_Rana
    Copper Contributor
    I know this is an old thread but i would like to confirm that FIDO2 keys can also be used as MFA. While it offers passwordless login, you can also use it to perform MFA when used along with password.

Resources