Share via

How to allow my users to be password less when authenticating ?

EnterpriseArchitect 6,366 Reputation points
2024-10-31T05:37:53.26+00:00

Based on this: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless#choose-a-passwordless-method

I am trying to enable all of my users with the Passwordless feature with the existing mobile/cell phones (iPhone and Android), but not with FIDO2 keys since there is no hardware will be provisioned.

I have created the AD Security group 'Hybrid Group—Secure Laptop Users' for all AD user accounts who own laptops with Fingerprint, Bluetooth, and Camera enabled. This group is already hybrid-synched to Entra ID.

Do I just manually enable the Passkey (FIDO2) settings from: https://entra.microsoft.com/#view/Microsoft_AAD_IAM/AuthenticationMethodsMenuBlade/~/AdminAuthMethods/fromNav/ ?

Microsoft Security | Intune | Security
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Graph
Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Andy David - MVP 160.2K Reputation points MVP Volunteer Moderator
    2024-10-31T10:39:31.0666667+00:00

    Are they using Windows for Business and met all the requirements?

    https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/#authentication-to-microsoft-entra-id

    Otherwise, enabling passkeys/Fido enables passwordless MFA for hardware keys and their authenticator phones.

    You can also enable Phone Sign in for passwordless with the Authenticator app

    User's image

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.