What is the difference between Platform mode and Software mode among the passwordless authentication methods provided by Microsoft?

민수 김 0 Reputation points
2024-10-22T09:04:23.49+00:00

I have a question about the passwordless authentication method provided by Microsoft.

According to the docs(https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless), the passwordless method is divided into three modes: Platform, Software, and Hardware.

Among them, What's the difference between the platform and software mode?

  1. Does the software mode only apply when using a separate authentication app (e.g., MS Authenticator app) as in the example? Or should apps (e.g., banking apps) or password management ecosystems (e.g., Google password managers) that include self-authentication processes be considered in software mode?
  2. It seems that biometric authentication of platform mode is also utilized in software mode, but why is it classified as software mode rather than platform mode?
  3. What are the definitions and specific differences of platform mode, software mode, and hardware mode? (If you have any data to refer to, let me know)
  4. For cross-platform passkey authentication using QR code and Bluetooth, which mode does it fall into: Platform, Software, or Hardware, and why?
  5. Do Platform mode/Software mode/Hardware mode all use a secure area such as TPM to store the private key and use the WebAuthn standard? In other words, do all three modes use the FIDO2 passkey?
  6. When doing passwordless authentication via the MS Authenticator app mentioned in the above docs (not "Enable passkeys in Microsoft Authenticator (preview)"), does it use a passkey? If it does, is the passkey stored in a secure area (e.g. TEE)?

Thank you for your help.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,483 questions
Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
7,082 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,926 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.