Cannot See FIDO2 authentication method in the User profile

Y.S 0 Reputation points
2023-05-23T06:40:06.6+00:00

Hi,

Im trying to use FIDO2 authentication method. the FIDO is enabled but when trying to set the authentication for FIDO in the User i cannot see the option:

User's image

User's image

Any idea?

Microsoft Configuration Manager
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,393 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,156 Reputation points Microsoft Employee
    2023-05-24T01:16:32.63+00:00

    Hi @Y.S .

    Thanks for your post! The "Add authentication method" section is not where you add the FIDO2 option for the users and you can only remove the FIDO2 key in the Authentication Methods section. Note that when you have enabled FIDO2 authentication in the Azure Portal, you need to ensure that Allow self-service set up is set to Yes.

    The end user (who needs to have already registered for MFA) needs to go to aka.ms/mysecurityinfo, sign in, go to Security info, and insert their FIDO2 key to enable the authentication under "+Add sign-in method." Once the user has done this, the FIDO2 key will show up under their authentication methods.

    User's image

    Note that if you need to enable the use of security keys with Intune, you need to go to Devices > Enroll Devices > Windows enrollment > Windows Hello for Business and set Use security keys for sign-in to Enabled.

    User's image

    You can also set up a configuration profile in Microsoft Endpoint Management at endpoint.microsoft.com. There you would go to Devices > All devices > Configuration profiles > Create profile.

    In the profile, select the platform (i.e. Windows 10 or later), select the Profile type (i.e. Templates > Identity Protection) > Add a name (Enable FIDO2 login), and under "Use security keys for sign-in" select "Enable."

    User's image

    Then you would assign the configuration to the applicable group where you want the policy to apply.

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-security-key-windows

    There are some good walk-through videos on YouTube for this process.

    https://www.youtube.com/watch?v=GfKeiKA8aEo
    https://www.youtube.com/watch?v=baVTd38hMEE

    Let me know if this helps and if you run into any issues. I'm happy to discuss this further if the method still does not show up after the end user has added it and you have confirmed their MFA registration status.

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar information.

    0 comments No comments