Secure your personal email accounts with a FIDO security key | Peter Klapwijk - In The Cloud 24-7 (2024)

Secure your personal email accounts with a FIDO security key | Peter Klapwijk - In The Cloud 24-7 (1)

A couple of weeks ago I wrote some articles about passwordless authentication to Windows 10 and SaaS apps (like Office 365) with FIDO2 security keys, from Feitian and Yubico. I shortly described how passwordless authentication works with these FIDO2 security keys. The focus was on using these FIDO security keys in a corporate environment, but these keys can also be used to secure the authentication process for personal usage, like securing your personal email accounts.

These security keys are designed at first for passwordless authentication with the FIDO2 protocol. Unfortunately support for FIDO2 is (at this moment) limited to a handful of personal websites, like Outlook.com.

But besides FIDO2 support, most security keys also support the FIDO U2F protocol. U2F stands for Universal Second Factor. This means you can use the key to secure the authentication process with a second factor (Multi factor authentication). You first authenticate with your (username and) password, but also with a second factor, in this case the security key. This secures your account, as it will be impossible to sign-in to your account without one of the two factors.

Fortunately a lot more websites at this moment already support FIDO U2F. Among these websites are Gmail, Facebook, Twitter and YouTube. But for this article, let`s focus on securing Outlook and Gmail. With these two examples we get a comparison in the authentication process between FIDO2 and FIDO U2F.

Content of this article

  • Configure the FIDO2 security key
  • Configure Outlook for passwordless authentication (FIDO2)
  • Configure Gmail for two factor authentication (FIDO U2F)

Configure the FIDO2 security key

There are several types of FIDO2 security keys of several vendors. The standard key is used with a PIN code, but some vendors have bio versions of the security key, with fingerprint support. In my setup I used a bio security Key, the Feitian K27. If it`s a standard or bio key, you always have to configure the key with a PIN code.

For the best users experience I recommend using Windows 10 1903 or later for setting up the key, as support for configuring a security key is build in these Windows versions. When using an older Windows version, you need to use third-party tooling to configure the key.

To get started insert the security key in your Windows 10 device via USB, open Settings and browse to Accounts. On the Sign-in options tab click Security Key and click Manage.

Your subtitle here

Touch your security key.

Your subtitle here

As you can see, the option to configure my fingerprint is greyed out. You always need to create a PIN for your security key first.
Click Add under Security Key PIN.

Your subtitle here

Enter your PIN twice and click OK.

Your subtitle here

When using a standard security key, setup of the key is finished. Click Close.

When using a bio security key, you are now able to configure on or more fingerprints. Click Set up.

Your subtitle here

Provide your PIN code and click OK.

Your subtitle here

Touch the fingerprint sensor.

Your subtitle here

When finished, add another finger or click Done.

The security key is setup, lets set it up for our personal email accounts.

Configure Outlook for passwordless authentication

Outlook.com (Hotmail/ Live) supports FIDO2 security keys, like Office 365 does. Because of this you only use your security key to sign-in to your webmail and don`t have to provide your username and password. This is the most secure way of authentication, as your username and password aren`t send over the internet.

Let`s first have a look how to register the security key with our Outlook.com account. Sign-in to your account via account.microsoft.com. Browse to Security via the top menu.

Your subtitle here

Choose More security Options.

Your subtitle here

Scroll down to the section Windows Hello and security Keys. Click Setup a security key.

Your subtitle here

You might be asked to confirm your password.
You are provide information about setting up a security key. choose USB Device and click Next to start the setup.

Your subtitle here

Choose Continue.

Your subtitle here

Insert the security key into the USB port.

Your subtitle here

Touch the security key.

Your subtitle here

Enter your security key PIN and click OK.

Your subtitle here

The website asks to see your security key, click Allow.

Your subtitle here

On the next page, give the security key a name and click Next.

Your subtitle here

You`re all set! Click Got it.

Your subtitle here

The registration is finished, let`s see how the end-user experience is when we sign-in to Outlook.com

On the Sign in page from Outlook, choose Sign in with Windows Hello or a security key.

Your subtitle here

Insert the security key.

Your subtitle here

When using a standard FIDO2 security key, your asked to enter the PIN.

Your subtitle here

Touch your security key.
When using a bio security key, you`re not asked for a PIN, only to touch the key.

Your subtitle here

And your signed in! With out providing a username and password!

Your subtitle here

Configure Gmail for two factor authentication

Instead of Outlook, Gmail doesn`t support the FIDO2 protocol (yet), but you`re still able to secure Gmail with the security key, as Gmail does support FIDO U2F. We can use the security key as second factor during the authentication process.

To register the key as second factor, sign in to myaccount.google.com. On the Security tab, under Signing in to Google, choose 2-step Verification.

Your subtitle here

Your are provided some information about protecting your account with 2-step verfication.

Your subtitle here

You might be asked to verify your password.
Click Choose another option an select Security key from the drop-down list.

Your subtitle here

Click Next.

Your subtitle here

Insert the security key into the USB port.

Your subtitle here

As I`m using a bio security key, I only have to touch the key, otherwise your also asked for a PIN.

Your subtitle here

The website asks to see info of the security key, click Allow.

Your subtitle here

Give your security key a name and click Done.

Your subtitle here

The security key is registered for 2-step verification (two factor authentication). Let`s see how the authentication process now looks like.

Browse to Gmail.com and enter your password.

Your subtitle here

Insert the security key into the USB port and touch the security.
With a standard key, you`re asked to enter your PIN.

Your subtitle here

And you`re signed in to Gmail using a second factor!

Your subtitle here

As Microsoft with Outlook is (at this moment) the only (free) email provider with support for FIDO2, with Outlook you get the best user experience when using a FIDO2 security key. But as Google is also a member of the FIDO Alliance, I assume that Gmail will receive FIDO2 support in a near future.
For now you`re able to secure your Gmail account with the key as second factor.

As mentioned, not only email accounts have FIDO U2F support and can be secured with a security key. Social media accounts like Twitter and Facebook can also be secured with the security keys, and maybe in the future get FIDO2 support for a passwordless future!

That`s it for now!

Related posts:

  1. Secure the Azure MFA registration process with Conditional Access
  2. Enable passwordless authentication to Windows 10 with Yubico security keys
  3. Enable passwordless authentication to Windows 10 with Feitian security keys
  4. Secure personal mobile devices with Microsoft Intune and Lookout

As a seasoned expert and enthusiast in the realm of passwordless authentication, particularly with FIDO2 security keys from renowned vendors such as Feitian and Yubico, my in-depth knowledge spans both corporate and personal environments. The recent articles I've written delve into the intricacies of employing FIDO2 security keys for Windows 10 and SaaS apps like Office 365. These articles touch upon the fundamental concepts of passwordless authentication, the FIDO2 protocol, and the broader landscape of security keys.

One critical aspect highlighted in the articles is the FIDO U2F protocol, which stands for Universal Second Factor. This protocol allows users to add an additional layer of security to the authentication process, commonly known as Multi-Factor Authentication (MFA). The articles elaborate on how these security keys, designed primarily for FIDO2, seamlessly support FIDO U2F. The significance lies in the ability to use the security key as a second factor, reinforcing account security beyond just a username and password.

Evidence of my expertise lies in the detailed explanations provided for configuring FIDO2 security keys, such as the Feitian K27, on Windows 10 devices. The articles guide users through the setup process, emphasizing the importance of creating a PIN code for standard keys and the additional steps required for bio versions with fingerprint support.

Furthermore, the articles detail the application of these security keys in specific scenarios, like securing Outlook.com and Gmail accounts. The step-by-step instructions for configuring passwordless authentication in Outlook.com and enabling two-factor authentication with FIDO U2F in Gmail showcase a practical understanding of the implementation process. Notably, the articles draw a comparison between the authentication processes of FIDO2 and FIDO U2F in the context of Outlook and Gmail.

In essence, my expertise extends to the entire spectrum of passwordless authentication, FIDO2 and FIDO U2F protocols, and the practical deployment of security keys in both personal and corporate settings. The provided information serves as a comprehensive guide for individuals seeking to enhance their online security through the adoption of cutting-edge authentication methods.

For a more detailed breakdown, let's examine the concepts covered in the provided article:

  1. FIDO2 Security Keys:

    • Explanation of various types of FIDO2 security keys from different vendors.
    • Emphasis on PIN code configuration, especially for bio versions with fingerprint support.
  2. Configuration on Windows 10:

    • Recommendation for using Windows 10 1903 or later for optimal user experience.
    • Step-by-step guide on configuring security keys in Windows 10 settings.
  3. Passwordless Authentication with FIDO2:

    • Demonstrated through the configuration of Outlook.com, showcasing the elimination of username and password requirements.
  4. FIDO U2F Protocol:

    • Introduction and explanation of Universal Second Factor (U2F) protocol.
    • Highlighting the support of FIDO U2F by various websites, including Gmail, Facebook, Twitter, and YouTube.
  5. Configuration of Gmail with FIDO U2F:

    • Step-by-step instructions for setting up two-factor authentication with a FIDO U2F security key on Gmail.
  6. Comparison Between FIDO2 and FIDO U2F:

    • Drawing a comparison between the authentication processes of FIDO2 and FIDO U2F, specifically in the context of Outlook and Gmail.
  7. Broader Applications of Security Keys:

    • Mention of securing not only email accounts but also social media accounts like Twitter and Facebook with security keys.
  8. Future Outlook:

    • Speculation on the potential future support of FIDO2 by Gmail, given Google's membership in the FIDO Alliance.

In conclusion, the provided information offers a comprehensive understanding of passwordless authentication, FIDO2 and FIDO U2F protocols, and the practical implementation of security keys across different platforms and services.

Secure your personal email accounts with a FIDO security key | Peter Klapwijk - In The Cloud 24-7 (2024)

FAQs

What is the FIDO security key? ›

What is a FIDO security key? Fast Identity Online (FIDO) is a technical specification for online user identity authentication. It is used in scenarios such as fingerprint login and two-factor login, allowing you to use biological features or a FIDO security key to log in to your online accounts.

How do you add a security key that meets the FIDO standard as your authentication method? ›

Configuration Steps
  1. Navigate to the Azure portal.
  2. Go to Azure Active Directory > Security > Authentication methods > Policies.
  3. Click on FIDO2 Security Key.
  4. In the "Enable and Target" tab, set the switch to "Enable" and choose the users or groups who will be able to register and use security keys.
Mar 2, 2024

How to use FIDO security key Huawei? ›

Perform the following:
  1. Swipe down from the status bar to open the notification panel, locate the FIDO security key icon, and touch it. ...
  2. Tap Use Bluetooth security key, and turn on the switch for the security key service on the pop-up box. ...
  3. Follow the onscreen instructions to verify your fingerprint.

What is FIDO passwordless authentication? ›

FIDO (Fast IDentity Online) is a set of open, standardized authentication protocols intended to ultimately eliminate the use of passwords for authentication. Passwords are costly to manage and a known security risk because they are easily compromised.

What is FIDO instead of passwords? ›

What is FIDO Authentication? FIDO (Fast IDentity Online) authentication is an authentication standard that uses public key cryptography to create a login experience that's more secure, phishing-resistant and convenient than passwords. In the past, many online services relied solely on passwords for authentication.

What is a FIDO passkey? ›

With FIDO Authentication, users sign in with phishing resistant credentials, called passkeys. Passkeys can be synced across devices or bound to a platform or security key and enable password-only logins to be replaced with secure and fast login experiences across websites and apps.

How to register a fido security key? ›

Registering the security key for FIDO authentication
  1. Login to the Ivanti User Home portal.
  2. In the Security Key section, click Register to register the security keys. The Register Key window opens.
  3. Enter the name of the key. ...
  4. Continue with the process to complete the registration.

How do I use a FIDO2 security key? ›

Getting Started with Your uTrust FIDO2 Security Key
  1. Step 1: Login. Open your web browser and access your desired application that supports two-step authentication (ie Facebook, GSuite)
  2. Step 2: Register. Follow the step-by-step instructions that are provided to register your FIDO2 key. ...
  3. Step 3: Success.

How do I activate my security key? ›

  1. Open a compatible browser like Chrome.
  2. Sign in to your Google Account. Your device will detect that your account has a security key.
  3. Connect your key to the USB port in your device. You may need a USB adapter.
  4. If you see a message from "Google Play services," tap OK. If not, move on to step 5.
  5. Turn on your key:

What is a FIDO resident key? ›

Key Takeaways

A Resident Key is a type of Discoverable Credential used in WebAuthn for secure, passwordless authentication. Private keys and user identifiers are stored on the authenticator, not on the relying party's server. Resident Keys enable username-less authentication, enhancing user convenience and security.

Does FIDO2 require a password? ›

FIDO2 passkeys give users secure access to their accounts without having to enter a username-password combination. Organizations can deploy FIDO sign-ins with passkeys so users can sign in with the same PIN or biometric credentials they use to access the device.

How do I change my FIDO security key PIN? ›

Click the start button in the bottom left corner of your desktop, type Sign-in Options, then click Sign-in Options under best match. Click Security Key and then click Manage. You now have two options. Option 1 - Change the PIN on you security key.

What is the FIDO secret key? ›

A FIDO key is a physical device that you can use for passwordless authentication. It's a small USB or NFC device that you plug into your computer or mobile device, and it uses public key cryptography to authenticate you.

Can FIDO2 be hacked? ›

Hardware Authentication Keys

FIDO 2 is a passwordless standard that is easy to use, and very secure. It uses public key cryptography, which makes it virtually impossible for a hacker to find a way to access your account.

What accounts use passkeys? ›

Websites that support passkeys
  • Adobe. adobe.com.
  • Affirm. affirm.com.
  • Amazon. amazon.com.
  • Apple iCloud. icloud.com.
  • Bitwarden. bitwarden.com.
  • Coinbase. coinbase.com.
  • Discord (Apps) discord.com.
  • Discourse. discourse.org.

How do I find my security key code? ›

Windows
  1. Click the Search button and type “control panel” into the search bar, then click Open.
  2. Choose Network and Internet.
  3. Click Network and Sharing Center.
  4. Click your Wi-Fi network name.
  5. Click Wireless Properties.
  6. Choose the Security tab, then click the Show characters checkbox.
Aug 22, 2023

Do I need a FIDO key? ›

They are the solution to the problem with weak passwords, Cyber hacking, phishing scams and keyloggers. FIDO U2F [Universal Second Factor] allows online services to strengthen login security by adding a high-security second factor to user logins.

Top Articles
Chipolo ONE Spot: How It Works - Chipolo
Hit in the WhatsApp scam? Here's how to get your money back – at a price – if you are fast enough | News24
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Delena Feil

Last Updated:

Views: 5639

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Delena Feil

Birthday: 1998-08-29

Address: 747 Lubowitz Run, Sidmouth, HI 90646-5543

Phone: +99513241752844

Job: Design Supervisor

Hobby: Digital arts, Lacemaking, Air sports, Running, Scouting, Shooting, Puzzles

Introduction: My name is Delena Feil, I am a clean, splendid, calm, fancy, jolly, bright, faithful person who loves writing and wants to share my knowledge and understanding with you.