Passwordless authentication in Azure AD with Token2 FIDO2 keys

Passwordless authentication in Azure AD with Token2 FIDO2 Security keys

FIDO2 enables organizations and users to use a USB key sign in to identity providers like Azure AD.

In the context of Azure AD, FIDO2 Security keys are not a replacement of the standard authentication mechanisms, they are added as an alternative, marketed by Microsoft as one of the Passwordless login methods

The guide below will walk you thru the steps required to enable passwordless access using Token2 FIDO2 Security keys.

Requirements

  • An Azure AD tenant which licensed to use  Azure MFA functions
  • A global tenant admin account in Azure AD
  • A regular account to use for the test
  • A FIDO2 compatible security key, for example, Token2 T2F2 FIDO2 USB key
  • Windows 10 - 1903 or higher. Only MS Edge can be used as the browser during enrollment and sign-in


Enable FIDO2 authentication method

Newly created tenant subscriptions will have this enabled for all users, but, in some cases, you may need to enable FIDO2 (for all or selected user groups) by following the steps below:

  • Go to the Azure Portal (https://portal.azure.com) and log in using your Global Admin account.
  • Navigate to the "Azure Active Directory", then choose "User settings"
  • Go to  "User feature previews"  and choose "Manage user feature preview settings"

    Passwordless authentication in Azure AD with Token2 FIDO2 keys

  • Enable the feature called "Users can preview features for registering and managing security info – enhanced". You can turn it on for All users - this will only add the possibility for end-users to self-enroll FIDO2 keys

    Passwordless authentication in Azure AD with Token2 FIDO2 keys

To verify FIDO2 Security keys feature, go to "Authentication Methods" and make sure you have FIDO2 Security keys listed 

Passwordless authentication in Azure AD with Token2 FIDO2 keys

After the authentication method has been activated, users are able to enroll their FIDO2 Keys

User registration and management of FIDO2 security keys

Note that only end users can perform the enrollment. Administrator provisioning and de-provisioning of security keys is not available in the public preview.

  • Browse to https://myprofile.microsoft.com
  • Sign in if not already
  • Click Security Info
    • If the user already has at least one Azure Multi-Factor Authentication method registered, they can immediately register a FIDO2 security key.
    • If they don’t have at least one Azure Multi-Factor Authentication method registered, they must add one.
  • Add a FIDO2 Security key by clicking Add method and choosing Security key


    Passwordless authentication in Azure AD with Token2 FIDO2 keys

  • Choose USB device 

    Passwordless authentication in Azure AD with Token2 FIDO2 keys

  • Have your key ready and choose Next
  • A box will appear and ask you to create/enter a PIN for your security key, then touch the shield or lock icon on the key (the LED indicator is usually blinking at this moment).
  • You will be returned to the combined registration experience and asked to provide a meaningful name for your token so you can identify which one if you have multiple. Click Next.
  • Click Done to complete the process


Changing the PIN and resetting the Security Key

Azure AD requires the security keys to be protected with a PIN code. This can be done during the enrollment, but you can also change the PIN code later if needed. In case you forgot the PIN code, you can reset the security key and re-enroll again (as a new FIDO2 Security device). Changing the PIN and resetting Token2 T2F2 security keys can be done using the Windows Control panel (Control Panel -> Windows Security -> Account Protection -> Windows Hello / Manage sign-in options -> Security Key -> Manage ) 

Passwordless authentication in Azure AD with Token2 FIDO2 keys 


It is recommended to have more than one security key enrolled. This is why we decided to introduce the FIDO bundle, which comes with a pair of T2F2 keys: one (primary, with a red sticker) to keep with you and one (secondary, with a green sticker) to keep in your desk drawer.
Payment methods

   PayPal Logo
Large Volume Orders
For large orders, Token2 offers volume discounts.If you are interested in larger volume orders, please contact us and we will get back with a quote immediately


We are using cookies. By using our site you agree with ToS  ok