How to allow my users to be password less when authenticating ?

EnterpriseArchitect 5,406 Reputation points
2024-10-31T05:37:53.26+00:00

Based on this: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless#choose-a-passwordless-method

I am trying to enable all of my users with the Passwordless feature with the existing mobile/cell phones (iPhone and Android), but not with FIDO2 keys since there is no hardware will be provisioned.

I have created the AD Security group 'Hybrid Group—Secure Laptop Users' for all AD user accounts who own laptops with Fingerprint, Bluetooth, and Camera enabled. This group is already hybrid-synched to Entra ID.

Do I just manually enable the Passkey (FIDO2) settings from: https://entra.microsoft.com/#view/Microsoft_AAD_IAM/AuthenticationMethodsMenuBlade/~/AdminAuthMethods/fromNav/ ?

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
12,265 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
432 questions
Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,914 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,093 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 149.1K Reputation points MVP
    2024-10-31T10:39:31.0666667+00:00

    Are they using Windows for Business and met all the requirements?

    https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/#authentication-to-microsoft-entra-id

    Otherwise, enabling passkeys/Fido enables passwordless MFA for hardware keys and their authenticator phones.

    You can also enable Phone Sign in for passwordless with the Authenticator app

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.