Support for FIDO2 authentication with Microsoft Entra ID - Microsoft Entra ID (2024)

  • Article

Microsoft Entra ID allows passkeys to be used for passwordless authentication. This article covers which native applications, web browsers, and operating systems support passwordless authentication using passkeys with Microsoft Entra ID.

Note

Microsoft Entra ID currently supports device-bound passkeys stored on FIDO2 security keys and in Microsoft Authenticator. Microsoft is committed to securing customers and users with passkeys. We are investing in both synced and device-bound passkeys for work accounts.

Native application support

The following sections cover support for Microsoft and third-party applications. Passkey (FIDO2) authentication with a third-party Identity Provider (IDP) isn't supported in third-party applications using authentication broker, or Microsoft applications on macOS, iOS, or Android at this time.

Native application support with authentication broker (preview)

Microsoft applications provide native support for FIDO2 authentication in preview for all users who have an authentication broker installed for their operating system. FIDO2 authentication is also supported in preview for third-party applications using the authentication broker.

The following tables lists which authentication brokers are supported for different operating systems.

OSAuthentication brokerSupports FIDO2
iOSMicrosoft Authenticator
macOSMicrosoft Intune Company Portal 1
Android2Authenticator or Company Portal

1On macOS, the Microsoft Enterprise Single Sign On (SSO) plug-in is required to enable Company Portal as an authentication broker. Devices that run macOS must meet SSO plug-in requirements, including enrollment in mobile device management. For FIDO2 authentication, make sure that you run the latest version of native applications.

2Native application support for FIDO2 on Android is in development.

If a user installed an authentication broker, they can choose to sign in with a security key when they access an application such as Outlook. They're redirected to sign in with FIDO2, and redirected back to Outlook as a signed in user after successful authentication.

Microsoft application support without authentication broker (preview)

The following table lists Microsoft application support for passkey (FIDO2) without an authentication broker.

ApplicationmacOSiOSAndroid
Remote Desktop

Third-party application support without authentication broker

If the user has yet to install an authentication broker, they can still sign in with a passkey when they access MSAL-enabled applications. For more information about requirements for MSAL-enabled applications, see Support passwordless authentication with FIDO2 keys in apps you develop.

Web browser support

This table shows browser support for authenticating Microsoft Entra ID and Microsoft accounts by using FIDO2. Consumers create Microsoft accounts for services such as Xbox, Skype, or Outlook.com.

OSChromeEdgeFirefoxSafari
WindowsN/A
macOS
ChromeOSN/AN/AN/A
LinuxN/A
iOS
AndroidN/A

Note

Passkeys in Authenticator don't work with browsers like Google Chrome or Microsoft Edge on Android devices. Support to create and sign in using Authenticator passkeys from browsers depends upon API updates to be made available by the Android platform.

Web browser support for each platform

The following tables show which transports are supported for each platform. Supported device types include USB, near-field communication (NFC), and bluetooth low energy (BLE).

Windows

BrowserUSBNFCBLE
Edge
Chrome
Firefox

Minimum browser version

The following are the minimum browser version requirements on Windows.

BrowserMinimum version
Chrome76
EdgeWindows 10 version 19031
Firefox66

1All versions of the new Chromium-based Microsoft Edge support FIDO2. Support on Microsoft Edge legacy was added in 1903.

macOS

BrowserUSBNFC1BLE1
EdgeN/AN/A
ChromeN/AN/A
Firefox2N/AN/A
Safari2,3N/AN/A

1NFC and BLE security keys aren't supported on macOS by Apple.

2New security key registration doesn't work on these macOS browsers because they don't prompt to set up biometrics or PIN.

3See Sign in when more than three passkeys are registered.

ChromeOS

Browser1USBNFCBLE
Chrome

1Security key registration isn't supported on ChromeOS or Chrome browser.

Linux

BrowserUSBNFCBLE
Edge
Chrome
Firefox

iOS

Browser1,3LightningNFCBLE2
EdgeN/A
ChromeN/A
FirefoxN/A
SafariN/A

1New security key registration doesn't work on iOS browsers because they don't prompt to set up biometrics or PIN.

2BLE security keys aren't supported on iOS by Apple.

3See Sign in when more than three passkeys are registered.

Android

Browser1USBNFCBLE2
Edge
Chrome
Firefox

1Security key registration with Microsoft Entra ID isn't yet supported on Android.

2BLE security keys aren't supported on Android by Google.

Known issues

Sign in when more than three passkeys are registered

If you registered more than three passkeys, sign in with a passkey might not work. If you have more than three passkeys, as a workaround, click Sign-in options and sign in without entering a username.

Support for FIDO2 authentication with Microsoft Entra ID - Microsoft Entra ID (1)

PowerShell support

Microsoft Graph PowerShell supports FIDO2. Some PowerShell modules that use Internet Explorer instead of Edge aren't capable of performing FIDO2 authentication. For example, PowerShell modules for SharePoint Online or Teams, or any PowerShell scripts that require admin credentials, don't prompt for FIDO2.

As a workaround, most vendors can put certificates on the FIDO2 security keys. Certificate-based authentication (CBA) works in all browsers. If you can enable CBA for those admin accounts, you can require CBA instead of FIDO2 in the interim.

Next steps

Enable passwordless security key sign-in

Support for FIDO2 authentication with Microsoft Entra ID - Microsoft Entra ID (2024)

FAQs

Does Microsoft authenticator support FIDO2? ›

Microsoft Entra ID currently supports device-bound passkeys stored on FIDO2 security keys and in Microsoft Authenticator.

What is Microsoft Entra ID in the authenticator app? ›

Microsoft Entra ID lets Authentication Policy Administrators choose which authentication methods can be used to sign in. They can enable Microsoft Authenticator in the Authentication methods policy to manage both the traditional push MFA method and the passwordless authentication method.

How do I allow FIDO2 authenticator access? ›

Click User Security Policies > User Account Settings. Select Yes in the Enable FIDO2 Authentication drop-down box. Select Yes in the Enable security key enrollment drop-down box. Enter a name in the FIDO2 Security Key Display Name field.

How do I enable FIDO2 security key method? ›

Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator. Browse to Protection > Authentication methods > Authentication method policy. Under the method FIDO2 security key, set the toggle to Enable.

What devices support FIDO2? ›

With this news, any compatible device running Android 7.0+ were now FIDO2 Certified out of the box or after an automated Google Play Services update. This gives users the ability to leverage their FIDO security keys for secure passwordless access to websites and native applications that support the FIDO2 protocols."

What is FIDO2 authentication? ›

FIDO2 is an open, license-free standard for multifactor passwordless authentication in mobile and desktop environments.

Do I need an Entra ID? ›

IT admins use Microsoft Entra ID to control access to apps and app resources, based on business requirements. For example, as an IT admin, you can use Microsoft Entra ID to require multifactor authentication when accessing important organizational resources.

What is Microsoft Entra ID used for? ›

Microsoft Entra ID is a cloud-based identity and access management solution. It's a directory and identity management service that operates in the cloud and offers authentication and authorization services to various Microsoft services, such as Microsoft 365, Dynamics 365, and Microsoft Azure.

How to test Microsoft Entra ID? ›

Test Your Configurations in Microsoft Entra ID

Log in to Microsoft Entra ID at https://portal.azure.com/. Navigate to Azure Active Directory (Microsoft Entra ID) > Enterprise Applications. Select your app and navigate to Single Sign-on > Test SAML settings. Select the user that you want to log in as.

What is a FIDO2 authentication key? ›

FIDO2 advantages

Replaces weak passwords with strong hardware-based authentication using public key crypto to protect against phishing, session hijacking, man-in-the-middle, and malware attacks. No secrets are shared between services.

What is an example of a FIDO2? ›

What are some examples of FIDO2 authentication methods? Biometric-capable devices and platform authenticators: These are built-in authenticators that require a biometric, PIN, or passcode. Examples include Apple's Touch ID and Face ID, Windows Hello, or Android fingerprint and face recognition.

Does Windows 10 support FIDO2? ›

Microsoft also supports FIDO2 passwordless login for Windows 10 with Azure AD. FIDO2 passwordless login allows roaming users to authenticate on any chosen Window 10 machine without having to set up Windows Hello.

Does Microsoft Authenticator use FIDO2? ›

The integration of Microsoft Authenticator with FIDO2 keys not only simplifies access to Microsoft applications but also strengthens the overall security infrastructure, introducing a phishing-resistant stack to iOS mobile platforms.

How do I set up FIDO2 on Windows? ›

To get started, go to "Settings" → "Accounts" → "Sign-in options" → "Security Key" and click "Manage". Next, insert your key and follow the on-screen prompts to touch it in a timely manner. If you haven't already, you'll need to set up a PIN before registering a fingerprint.

What are the authentication methods for FIDO2? ›

FIDO2 security keys are an unphishable standards-based passwordless authentication method that can come in any form factor. They're commonly USB devices, but they can also use Bluetooth or near-field communication (NFC).

Does Microsoft Authenticator work with YubiKey? ›

Microsoft and YubiKey work seamlessly together.

Which services use FIDO2? ›

So you can already use FIDO U2F with very many services, among them are: Nextcloud, GitHub, Odoo, Gitlab, Facebook, Google and many more. Passwordless logins using FIDO2 are comparatively rare, e.g. at Microsoft or Nextcloud. We list an overview of compatible services on dongleauth.com.

What type of authentication is Microsoft Authenticator? ›

Authenticator can be used three ways: As a way to verify sign in if you forget your password. As a way to sign every time, by using a one-time password code to increase account security. This is called two-step verification or multi-factor authentication.

Top Articles
How Do I Avoid Probate Court In New Jersey?
Check The Full URL - Information Security Office - Computing Services - Carnegie Mellon University
Was ist ein Crawler? | Finde es jetzt raus! | OMT-Lexikon
Evil Dead Rise Showtimes Near Massena Movieplex
The Best Classes in WoW War Within - Best Class in 11.0.2 | Dving Guides
Puretalkusa.com/Amac
Bill Devane Obituary
Large storage units
Assets | HIVO Support
Fairy Liquid Near Me
Gon Deer Forum
5 high school volleyball stars of the week: Sept. 17 edition
Bitlife Tyrone's
Roster Resource Orioles
Byui Calendar Fall 2023
Vrachtwagens in Nederland kopen - gebruikt en nieuw - TrucksNL
Acts 16 Nkjv
Tyler Sis University City
Robeson County Mugshots 2022
Iu Spring Break 2024
Baja Boats For Sale On Craigslist
LCS Saturday: Both Phillies and Astros one game from World Series
Academy Sports Meridian Ms
Dewalt vs Milwaukee: Comparing Top Power Tool Brands - EXTOL
Piedmont Healthstream Sign In
Marokko houdt honderden mensen tegen die illegaal grens met Spaanse stad Ceuta wilden oversteken
Weather October 15
The Clapping Song Lyrics by Belle Stars
WPoS's Content - Page 34
Kristy Ann Spillane
Insidious 5 Showtimes Near Cinemark Southland Center And Xd
R/Sandiego
25Cc To Tbsp
Craigs List Tallahassee
Persona 4 Golden Taotie Fusion Calculator
Most popular Indian web series of 2022 (so far) as per IMDb: Rocket Boys, Panchayat, Mai in top 10
Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
Pill 44615 Orange
Craigslist West Seneca
Myql Loan Login
Evil Dead Rise (2023) | Film, Trailer, Kritik
Ramsey County Recordease
Costco Gas Foster City
How to Install JDownloader 2 on Your Synology NAS
Bridgeport Police Blotter Today
Turok: Dinosaur Hunter
French Linen krijtverf van Annie Sloan
Runescape Death Guard
The Plug Las Vegas Dispensary
Craigslist Cars For Sale By Owner Memphis Tn
Rocket Bot Royale Unblocked Games 66
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 6121

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.