How do I configure Azure AD to allow authentication with CAC cards

JohnMihalik-8471 0 Reputation points
2023-06-29T15:10:32.2833333+00:00

I'm trying to configure authentication in our azure AD to allow logins with CAC cards. I've found the documentation for configuring CBA in Azure, but there is nothing specific for CAC cards. As I understand it I need the CA .cer file(s), but no clue where to find that or which cer is specific to the CAC cards.

Thanks!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2023-06-30T21:49:26.1433333+00:00

    @JohnMihalik-8471

    Thank you for your post!

    I understand that you're trying to configure CAC card authentication within your Azure AD tenant and within the Azure AD CBA documentation there wasn't anything specific to CAC cards, along with which .cer file needs to be used specific to CAC cards. To hopefully point you in the right direction or resolve your issue, I'll share my findings below.

    Findings:

    For CAC card / Smart card specific authentication, it looks like you'll need to follow these steps to set up the User Experience. For more info.

    1. Join the machine to either Azure AD or a hybrid environment (hybrid join).
    2. Configure Azure AD CBA in your tenant as described in Configure Azure AD CBA.
    3. Make sure the user is either on managed authentication or using Staged Rollout.
    4. Present the physical or virtual smart card to the test machine.

    Select the smart card icon, enter the PIN, and authenticate the user.

    When it comes to the .cer file, did your Certificate Authority (i.e. DigiCert or GlobalSign) provide you with certificates?


    Links:

    Windows smart card sign-in using Azure Active Directory certificate-based authentication

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.