PASSKEYS - What they are, why we want them and how to use them!

Поделиться
HTML-код
  • Опубликовано: 29 май 2024
  • In this video I explore what passkeys are, what is attractive about them for organizations and users, and then how to enable their use along with the user experience.
    🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!
    🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.
    ▬▬▬▬▬▬ C H A P T E R S ⏰ ▬▬▬▬▬▬
    00:00 - Introduction
    00:30 - Authentication history
    02:04 - Why Authenticator wasn't phishing resistant
    07:40 - Need protection from social engineering
    07:51 - Passkeys
    08:30 - Built on PKI
    10:40 - Passwordless FIDO2
    12:07 - How this works
    13:04 - Relying Party
    13:33 - Client
    13:52 - Authenticator
    14:41 - Public and private keys
    16:21 - Authentication flow
    18:23 - Need for a user gesture and intent
    20:08 - Presence and proximity
    21:25 - The promise of the protocol
    22:42 - Additional detail
    23:48 - WebAuthn use
    24:53 - Relying Party ID
    25:54 - WebAuthn client checks
    28:22 - Javascript and API calls
    29:36 - Key benefits for protection
    33:32 - Presence and CTAP
    36:47 - Bluetooth use
    37:16 - Cross-device authentication
    37:52 - How many passkeys
    40:25 - Authenticator options
    41:29 - Types of passkey
    46:47 - Authenticator can roam
    47:51 - Where can passkeys be used
    49:11 - What is different from before
    51:07 - Using with Entra
    53:52 - Enabling passkeys in Entra
    55:09 - User passkey addition
    55:55 - Using a passkey
    57:58 - Using passkey on same device
    1:00:06 - Cross-device authentication
    1:02:52 - Microsoft accounts
    1:03:51 - Always synced
    1:05:42 - MSA passkey CDA demo
    1:07:52 - Summary
    1:10:05 - Close
    ▬▬▬▬▬▬ K E Y L I N K S 🔗 ▬▬▬▬▬▬
    ► Whiteboard:
    🔗 raw.githubusercontent.com/joh...
    ► Microsoft Documentation
    🔗 learn.microsoft.com/entra/ide...
    ▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
    📖 Recommended Learning Path for Azure
    🔗 learn.onboardtoazure.com
    🥇 Certification Content Repository
    🔗 github.com/johnthebrit/Certif...
    📅 Weekly Azure Update
    🔗 • Azure Infrastructure U...
    ☁ Azure Master Class
    🔗 • Microsoft Azure Master...
    ⚙ DevOps Master Class
    🔗 • DevOps Master Class
    💻 PowerShell Master Class
    🔗 • PowerShell Master Class
    🎓 Certification Cram Videos
    🔗 • Microsoft Certificatio...
    🧠 Mentoring Content
    🔗 • Virtual Mentoring
    ❔ Questions? Maybe I answered it in my FAQ
    🔗 savilltech.com/faq
    👕 Cure Childhood Cancer Charity T-Shirt Channel Store
    🔗 johns-t-shirts-store.creator-...
    👂 Enable the subtitles and from there you can translate to your native language via the auto-translate feature in settings! • RUclips Captions and A... for a demo of using this feature.
    SUBSCRIBE ✅ / @ntfaqguy
    #microsoft #passkeys #johnsavillstechnicaltraining

Комментарии • 56

  • @NTFAQGuy
    @NTFAQGuy  24 дня назад +10

    Passkeys are everywhere so in this video we dive into what they are, what's good about them and how to use them. Please make sure to read the description for the chapters and key information about this video and others.
    ⚠ P L E A S E N O T E ⚠
    🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there!
    🕰 I don't discuss future content nor take requests for future content so please don't ask 😇
    🤔 Due to the channel growth and number of people wanting help I no longer can answer or even read questions and they will just stay in the moderation queue never to be seen so please post questions to other sites like Reddit, Microsoft Community Hub etc.
    👂 Translate the captions to your native language via the auto-translate feature in settings! ruclips.net/video/v5b53-PgEmI/видео.html for a demo of using this feature.
    Thanks for watching!
    🤙

  • @dogmanky
    @dogmanky 22 дня назад +18

    If there are "Emmy Awards" for tech training, this lesson should be nominated! Awesome stuff John! Thank you!

    • @NTFAQGuy
      @NTFAQGuy  22 дня назад

      lol, well thank you and glad you enjoyed it!

    • @IlkinJamalli
      @IlkinJamalli 13 дней назад

      Absolutely agree! Thanks John!

  • @expat64
    @expat64 23 дня назад +12

    Best presentation on the topic I have seen yet... but why am I not surprised ;-)

    • @NTFAQGuy
      @NTFAQGuy  23 дня назад

      very kind, thank you!

  • @MrYosssup
    @MrYosssup 20 дней назад +2

    Best FIDO2 explanation ever…will most likely watch this again. Thanks a bunch John!

    • @NTFAQGuy
      @NTFAQGuy  20 дней назад

      Very kind, thank you!

  • @NZScottie
    @NZScottie 19 дней назад +1

    New levels of understanding passkeys achieved thanks to your video and style. As always your work and effort towards the community is appreciated.

    • @NTFAQGuy
      @NTFAQGuy  19 дней назад

      Many thanks! Have a good weekend!

  • @mscloudvar
    @mscloudvar 21 день назад +1

    I've watched this twice and will probably watch it again as I develop my Proof of Concept to demonstrate the business case to move "rapidly" to passkey authentication. Great explanation, and as a visual learner, the whiteboard accompaniment was awesom!

    • @NTFAQGuy
      @NTFAQGuy  21 день назад

      Excellent, glad it was useful.

  • @DaveC-xe5ns
    @DaveC-xe5ns 13 дней назад

    Found this very informative and enabled passkeys on my Outlook and Gmail accounts. Thanks for the video John.

  • @grimson73
    @grimson73 День назад

    Wow, another video that makes totally sense of the discussed subject including the nice deeper technical bits (i'm a fan of this because how it works is the part for me that gets me to sleep well ;) ). Also for giggles I like how you draw the 'kite' Azure icon in every video, every time wandering how you close it at the top ;). Just kudo's for your endless dedicate work of sharing understandable bits to the curious public! well done!

    • @NTFAQGuy
      @NTFAQGuy  День назад

      That's very kind, thank you! Glad the content is useful.

  • @MoChowdhury-cl5hy
    @MoChowdhury-cl5hy 23 дня назад +1

    Another great video John - that deep dive helping the understand what is going on with PassKeys and the way you explain it is great, thanks again!

    • @NTFAQGuy
      @NTFAQGuy  23 дня назад

      Glad you enjoyed it

  • @johnthompson3530
    @johnthompson3530 16 дней назад

    This was a great video and thorough. Thanks John. I should make use of my Yubikey now lol!!

  • @antoinedentan5174
    @antoinedentan5174 14 дней назад

    Very impressive and very clear as usual. Thanks from France !

  • @Cormango
    @Cormango 20 дней назад

    I've been hooked on your videos. You're able to pick the right topics, at the right time, where general resources are missing key information. Well done and thank you!

  • @victorkurkov
    @victorkurkov 16 дней назад

    Thank you for making this so simplified, sir.

  • @retokrucker8634
    @retokrucker8634 23 дня назад

    This feature comes at the right time for me. We're about to create the cloud admins for the IT responsables in our subsidiaries.
    The plan was to buy a FIDO2 stick for every cloud admin. We don't need that now, because we can use passkeys.
    Although, I still prefer a physical stick for the high privileged roles.

  • @volcomstone54
    @volcomstone54 21 день назад

    Deployed in our dev environment after watching this. Thanks again John.

  • @SurferSandman
    @SurferSandman 24 дня назад

    This really helped me understand the main difference between the FIDO2 and Authentication Apps. Also the device bound and sync passkeys was a unique distinction.

  • @steveng.42
    @steveng.42 24 дня назад

    As always sir, I applaud the fantastic detail and clear communication you bring to complicated topics on the regular. This is just another fine example in a catalog of fantastic content. Well done!

    • @NTFAQGuy
      @NTFAQGuy  24 дня назад +1

      Glad it was helpful!

  • @jamesbarry4820
    @jamesbarry4820 21 день назад

    Great video John. Seems like every time I'm thinking about deploying a new feature at work you come out with a video about it. Guess it's a sign that I have to deploy it now!

  • @chris251188
    @chris251188 21 день назад

    Really appreciate this (and all your content tbh!), thanks John.

    • @NTFAQGuy
      @NTFAQGuy  21 день назад +1

      Very welcome!

  • @rogerosb2u
    @rogerosb2u 24 дня назад

    Very informative and helpful, as always. Thank you, John!

  • @nathanhartley
    @nathanhartley 23 дня назад

    Excellent explanation. Thank you.

  • @SamTurner-fo8pk
    @SamTurner-fo8pk 21 день назад

    Incredible as always John!

  • @adambarnard562
    @adambarnard562 23 дня назад

    Excellent deep dive. Thanks John.

    • @NTFAQGuy
      @NTFAQGuy  23 дня назад

      Glad you enjoyed it

  • @DrakeStardragon
    @DrakeStardragon 23 дня назад

    Excellent video, as always!

    • @NTFAQGuy
      @NTFAQGuy  23 дня назад

      Glad you enjoyed it!

  • @mariosaternus
    @mariosaternus 24 дня назад

    It would be VERY nice, if Microsoft would allow the Device Bound Passkeys to be used as a "fallback" mechanism if case a user lost the Windows Hello PIN or the Biometric Device is not working or faulty.
    Microsoft Authenticator with Number Matching is working today, so it should be possible to be used.
    Thank you for your interesting videos, John!

    • @StijnHommes
      @StijnHommes 21 день назад

      And how are you then supposed to unlock the device-bound passkey if the biometrics are faulty?

  • @ADAMSIVES
    @ADAMSIVES 23 дня назад

    you're a born communicator!

  • @cadea13
    @cadea13 24 дня назад +1

    Top notch as always! Question on BLE proximity - If Bluetooth is disabled on my phone will CDA+CTAP still work? Meaning - both devices need to have BT capability but not necessarily have it on, or it needs to be enabled and on for both devices?

    • @NTFAQGuy
      @NTFAQGuy  24 дня назад +1

      Need bluetooth on both.

  • @satishnaidu2000003
    @satishnaidu2000003 23 дня назад +1

    What are the chances of the Superman t-shirt turning up the same week James Gunn releases the first image of the new Superman?

  • @christianibiri
    @christianibiri 17 дней назад

    Awesome!

  • @eliotmansfield
    @eliotmansfield 24 дня назад +1

    I guess as a techie trying to login to say azure portal inside a vm or vdi session - i’m stuffed because there’s no proximity between my phone and the device - which is the whole point, but sometimes you need to - say for installing certain services and you need to sign into the portal inside a machine

    • @NTFAQGuy
      @NTFAQGuy  24 дня назад

      Right remote is an intresting challenge today.

  • @RoysIdea
    @RoysIdea 24 дня назад +1

    18:16 so how does this help with a man in the middle? He can monitor the reply and use it the next time.

    • @NTFAQGuy
      @NTFAQGuy  24 дня назад +8

      Because the server sends that nonce which is unique each time. Can't replay old response.

  • @joaabe11
    @joaabe11 21 день назад

    👋👋👋

  • @kradman188
    @kradman188 6 дней назад

    great video, shame about some of the namings they chose though...