Step-by-Step Guide to Using Passkeys in Microsoft 365

Поделиться
HTML-код
  • Опубликовано: 20 янв 2025

Комментарии • 100

  • @JamesWimmer
    @JamesWimmer 6 месяцев назад +26

    While I really like this in theory, unfortunately, because iOS only allows one app to offer PassKeys, this won't work for us. My firm has a BYOD policy, and plenty of our users use their own password solution (e.g. built-in, 1Password, etc) and forcing them to switch to using the MS Auth app is a no go. Hopefully Microsoft works towards allowing other non-MS Auth Passkeys in the near future.

    • @StevenMcKenzie-83
      @StevenMcKenzie-83 6 месяцев назад +1

      @@JamesWimmer you should test it. I believe it does you need need add the app id to passkey in admin center.

    • @JamesWimmer
      @JamesWimmer 6 месяцев назад +1

      @@StevenMcKenzie-83 I have and it errors out every time I try. Based on what I've read, Microsoft is targeting late 2024 to allow other apps. I could be completely wrong, but right now they only support device bound keys, whereas 1Password would be considered synced keys, which aren't yet supported.

    • @philhersh
      @philhersh 6 месяцев назад

      I've gotten 1Password to work but it’s very flaky. I wouldn’t give it to my users, yet 😊

    • @bearded365guy
      @bearded365guy  6 месяцев назад +3

      @@JamesWimmer Good point. Hopefully Microsoft will sort this.

  • @christophecolnaghi-pierre2697
    @christophecolnaghi-pierre2697 6 месяцев назад +1

    thanks for this video Jonathan, just tried it on my 365 family subscription, and it works like a charm, need to discuss now with my client's CSO 🙂

  • @ChaJ67
    @ChaJ67 2 месяца назад +2

    Something to point out is while in this video all security keys except for the two phone ones are blocked, this method does work with other security keys enabled. I suppose if you really want to, you can manually add your vendor's ID, but there is the question of how hard do you really want to make life on yourself? Just stepping up to everything is a security key for authentication is a big step forward in being more secure about how you do things. If you don't want to have to care about the vendor IDs attached to security keys to make things work, you don't have to.

  • @PankanyaMusic
    @PankanyaMusic Месяц назад

    Thanks mate, learnt so much in this video

  • @teddmented
    @teddmented 3 месяца назад +1

    Another terrific video thank you

  • @SonnyLearnsToRock
    @SonnyLearnsToRock 3 месяца назад

    Simplicity and security is the 🗝
    Thank you #bearded365guy !!! 🔥 🚀 💯

  • @paulgilbert3618
    @paulgilbert3618 6 месяцев назад +1

    Thanks for the video. I set this up as you described but each time I try and sign in it asks me to insert a security key into the USB port. Any ideas?

  • @benphillips3731
    @benphillips3731 2 месяца назад

    Great video. I'm curious though, does this stop MIM attacks fully? What does it do to stop a user going to a dodgy login page which is relaying the QR image for them to authenticate?

  • @mindenesvegyes8512
    @mindenesvegyes8512 6 месяцев назад +2

    Fantastic video Jonathan! I really love your work and dedication. Clear, helpful, focused. Please never stop :)

  • @StevenMcKenzie-83
    @StevenMcKenzie-83 6 месяцев назад +2

    Awesome video. Makes much more sense now how it works. My only question is how do you setup new users who have just started that CA policy will block them right? Or would it go straight to setup page?

    • @bearded365guy
      @bearded365guy  6 месяцев назад +3

      @@StevenMcKenzie-83 Ah, I should have included that in the video. You will need to use temporary access passwords as outlined here: learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass

    • @StevenMcKenzie-83
      @StevenMcKenzie-83 6 месяцев назад

      @@bearded365guy so with a new user you give them temporary password and when they sign in it goes straight into passkey registration screen like it would do for MFA

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@StevenMcKenzie-83 Yes, that’s right.

  • @michelepacucci1907
    @michelepacucci1907 3 месяца назад

    If I have a tenant with a CA Policy that enforces MFA for all Cloud apps. how can I configure to enable also Passkeys because you only can chooese between MFA and Passkeys (or passwordless MFA). should I just create a second CA policy with passkey?

  • @networkn
    @networkn 6 месяцев назад +4

    Thanks Jonathan, great video. You didn't cover one particular thing. What happens if you lose the device that has your Passkeys Stored? Phone gets dropped or stolen or left in a taxi after a wild night ?

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@networkn Ring the taxi company 😩 - you can delete a users passkey from the 365 admin centre. I’ll record a video….

    • @networkn
      @networkn 6 месяцев назад

      @@bearded365guy I get that, however if you have your admins only able to use phish resistant login methods it's a decent sized risk. I'd suggest a two pronged approach like passkeys required outside of main office ip but mfa allowed inside office. Pretty secure still. What do you think?

    • @bearded365guy
      @bearded365guy  6 месяцев назад +2

      @@networkn Yes, good idea. But we always have a break glass account for 365 too…. Long long password, no CA, no MFA.

    • @mightygeek
      @mightygeek 2 месяца назад

      @@bearded365guy I believe as of October Microsoft started enforcing MFA on privileged accounts (which of course the break glass ones are) so perhaps buy yubi keys for those...

  • @ArditaLilaj-h1t
    @ArditaLilaj-h1t 3 месяца назад

    @Jonathan Edwards you have to enable MFA to use FIDO, you cannot just setup FIDO and expect it to work. Your setup screen under Authentication Methods shows everything isn't enabled.

    • @bearded365guy
      @bearded365guy  3 месяца назад

      MFA was enabled on this test tenant using legacy MFA settings.

    • @ArditaLilaj-h1t
      @ArditaLilaj-h1t 3 месяца назад

      @@bearded365guy I have had a lot of uses using the non-legacy MFA and FIDO Passkey options to get my YubiKey's setup. But after fighting with Entra/Intune for a couple of days it started to work. lol

  • @karlok.9631
    @karlok.9631 6 месяцев назад +1

    Thank you.
    Keep it up.

  • @britishagent
    @britishagent 6 месяцев назад +1

    So, do you have to keep scanning a QR code to sign in or only do that once?
    I would presume your biometric would be primary identifier afterwards?

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@britishagent keep scanning…

  • @jaccodominicus9808
    @jaccodominicus9808 2 месяца назад +1

    Hello Jonathan, i tried to configure pass key and it is working for cloudapps and login in to the office portal. Is there already a possibility to use this for logging on to a intune joined desktop/laptop ? regards jacco Dominicus

    • @bearded365guy
      @bearded365guy  2 месяца назад

      Not for logon - use Windows Hello for Business.

    • @jaccodominicus9808
      @jaccodominicus9808 2 месяца назад

      @ okay hope that will come soon. We have customers who would like to have that and not having to get additional hardware. Thanks for the fast response.

  • @fxylk
    @fxylk 6 месяцев назад

    Amazing 🤩🤩🤩 now I need to secure my admin accounts 😅

  • @ScozzieMan
    @ScozzieMan 6 месяцев назад +1

    can i ask if this can still be set up on a hybrid set up?

  • @jon539539
    @jon539539 2 месяца назад +1

    This video brilliantly shows us how to generate and store a passkey for an M365 account with Microsoft Authenticator on iOS storing the passkey. I understand that this is dependent on Bluetooth to determine the proximity of the phone to the computer in question. We would like to setup passkeys on Windows desktop machines with no bluetooth and have the passkey stored locally on the desktop computer and secured with Windows Hello. Can anyone guide us on how to do that? I know its supported, as I have a passkey for my own MS 365 account, I just cant seem to go into my MS 365 account settings on other accounts to add one. So I dont even really know where it came from!

    • @bearded365guy
      @bearded365guy  2 месяца назад

      Hi, take a look at this - support.microsoft.com/en-us/windows/save-a-passkey-in-windows-e92cd3e0-11fa-4630-a5ea-3ccc0396b3d9

  • @jaybigboy34
    @jaybigboy34 3 месяца назад +1

    I am thinking the pc has to be bluetooth compatible for this to work, correct?

  • @networkn
    @networkn 6 месяцев назад

    I have a question if I may. I have set it up. Went swimmingly. I can login on the computer I configured the passkey to my Android MS Authenticator, but when I try and login elsewhere, and select passkey, it asks me to insert my USB Key! I've tried a few different browsers etc, no luck! I don't think I missed anything, there are two AAGuids in the config.

  • @techgroupservices
    @techgroupservices 6 месяцев назад +1

    Fantastic video Jonathan! Once the new passkey account has been added to the Microsoft Authenticator app is it safe to assume the users original account can be removed from the authenticator app?

    • @bearded365guy
      @bearded365guy  6 месяцев назад +1

      @@techgroupservices I’ve not tested that yet. I don’t want to say either way 😁

    • @StevenMcKenzie-83
      @StevenMcKenzie-83 6 месяцев назад +1

      Was going to ask the same question

  • @kevinbeutler910
    @kevinbeutler910 6 месяцев назад +1

    Thank Jonathan, always look forward to your new videos. I'm currently testing this is my environment and found that if I enable the Conditional Access policy to require the Phishing-Resistant MFA to log in, my Teams and Outlook are not able to sign in anymore. Have you heard about any development for getting mobile log ins into M365 apps working?

    • @bearded365guy
      @bearded365guy  6 месяцев назад +2

      @@kevinbeutler910 Are those Teams and Outlook desktop clients?

    • @kevinbeutler910
      @kevinbeutler910 6 месяцев назад +1

      ​@@bearded365guy It's actually Teams and Outlook on Android and iOS devices. The CA policy works fine on desktops. Still trying to troubleshoot but any insight you have would be awesome to hear. 😊

    • @zachorton864
      @zachorton864 6 месяцев назад

      @@kevinbeutler910 Hey Kevin - Im hitting the same snags with the Mobile applications on our Androids. It just doesnt give us the option to use the Passkey in the authentication app.

  • @eugenemeenan3703
    @eugenemeenan3703 3 месяца назад

    had no problems with fido 2.1 and windows hello - took a while explaining to most users that this was more secure as doesn't transmit passwords - not sure where to find settings for passkeys in android - well to be more specific samsung android just so I can test so at least the options available if users decide that over mfa - any pointers :-)

    • @DannyNilsson
      @DannyNilsson Месяц назад

      if you viewed the video, he explains you need to use the ms authenticator app.

  • @andrewenglish3810
    @andrewenglish3810 4 месяца назад

    Can you use a YubiKey still? Since MS is enforcing MFA on all admin accounts that have access to the Admin Centre I don't really want to put the admin MFA on my phone and would rather use an YubiKey, this way if I am away or leave the company they can still get in.

    • @TonyFussellLFG
      @TonyFussellLFG 3 месяца назад

      Yes. We added yubikey as Fido2 Method for our break glass account, to handle the Microsoft mandatory MFA

    • @ChaJ67
      @ChaJ67 2 месяца назад

      I did some testing and found that yes you can. Actually, I did it a bit differently than in this video when setting up Conditional Access in that I did not restrict down the key types. That turns out to be unnecessary to make this work, granted you could lock down the key types and then manually add the Yubikey identifier to the list.
      It can provide you redundant ways to get in. I would be more trusting of the Yubikey, but this method does get rid of the heavily exploited TOTP codes.

  • @maltbycentre3394
    @maltbycentre3394 6 месяцев назад

    That's great!
    Is it possible to validate the credentials via WHfB? By inputting the PIN or fingerprint? Thank you

  • @cjax235
    @cjax235 6 месяцев назад +1

    Brilliant (and timely) as ever

  • @hasher87
    @hasher87 5 месяцев назад

    What would you recommend if we want to set this up but for laptop login with their AD/AAD account?

    • @bearded365guy
      @bearded365guy  5 месяцев назад

      @@hasher87 you can use Windows Hello

  • @techjordan
    @techjordan 6 месяцев назад

    When enforcing key restrictions in Entra Id, if I have users already using fido2 keys would I have to restrict for those as well so that they continue to work?

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@techjordan Are they Yubikey’s? Read this - support.yubico.com/hc/en-us/articles/360016648959-YubiKey-Hardware-FIDO2-AAGUIDs. If you remember in the video, I added the iOS and Android AAGUIDs

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@techjordan Or you could use groups instead of all users.

  • @jjrscorpion
    @jjrscorpion 6 месяцев назад

    Hi Johnathan, I've recently discovered your channel and love the content. Will the passkey keep de session alive indefinitely? Thanks in advance

    • @bearded365guy
      @bearded365guy  6 месяцев назад +1

      @@jjrscorpion that would depend on the other policies you have in place 👍

  • @pkeonz5300
    @pkeonz5300 6 месяцев назад

    Hi Johnathan, thanks for the great video, but I have a question, how do bulk users enable the key feature? Thanks!!

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@pkeonz5300 Hi, not sure I quite understand the question….

    • @theoyiorkas
      @theoyiorkas 6 месяцев назад

      Through conditional access policy.

  • @ensarguler7684
    @ensarguler7684 6 месяцев назад

    Does enabling the Fido2 security key method stop the 'Security Defaults' company-wide feature from working?

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@ensarguler7684 No, it shouldn’t do.

  • @DannyNilsson
    @DannyNilsson Месяц назад

    i wasted so much time to figure this out. went with the default settings and had it fail but after these settings the enrollment started working.

  • @tiqhubwork
    @tiqhubwork 6 месяцев назад

    Hey Jonathan , can we add multiple passkeys into the MS Authenticator ?...

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@tiqhubwork Yes, I have 3 in mine.

  • @alexjacxsens5134
    @alexjacxsens5134 6 месяцев назад

    Hi Jonathan. Great tutorial! What if users switch phone? Can they switch the passkey also?

    • @bearded365guy
      @bearded365guy  6 месяцев назад +1

      @@alexjacxsens5134 they can backup their authenticator app.

    • @joeyusf
      @joeyusf 3 месяца назад

      @@bearded365guy what happen if their personal icloud account got hacked into is that means their passkey also fall into the hacker's hand?

  • @mdoner
    @mdoner 6 месяцев назад +1

    Great video - thank you for all your content. I'm an Android guy - tried setting this up, believe I have the Passkey registered OK. When I attempt to sign in; I get a 'passkey not found' popup on my phone. I have confirmed that I marked Authenticator as a provider. Anyone else experiencing this issue? - I understand this is still in preview and there may likely be some kinks. Thanks!

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@mdoner If you go into your security info in 365, can you see the passkey registered? Which method did you use to register your passkey?

  • @Jordan-k7l
    @Jordan-k7l 3 месяца назад +1

    iOS 18 update, iPhone settings to configure: Settings > General > Autofill & Passwords.

  • @robertpearson5069
    @robertpearson5069 6 месяцев назад +1

    Would be cool if this could be used to sign into windows itself.

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      It really would be cool!

    • @lee161a
      @lee161a 6 месяцев назад

      It doesn't work with Web Sign-in for Entra ID joined Windows 11 devices?

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@lee161a Yes, for web sign in. Not to log into Windows PC

    • @lee161a
      @lee161a 6 месяцев назад

      @@bearded365guy I mean the feature "Web sign-in for Windows" that gives you an embedded browser window at the Ctrl-Alt-Delete screen to logon with OIDC to Windows.

  • @MrSam_Derp_Man
    @MrSam_Derp_Man 6 месяцев назад +2

    important side note: Your mobile device needs to run iOS version 17, or Android version 14, or later.

  • @chrisdonovan677
    @chrisdonovan677 2 месяца назад

    On android it's working only with Android 14, about 70% of users is excluded. If you want to use it with Windows Hello, what ar eteh AAGUID to add ? Thanks. For Android there is no need to scan everytime the QR code, while for IOS it's always there..a little bit annoying..

  • @tejasshirgaonkar9608
    @tejasshirgaonkar9608 6 месяцев назад

    Absolutely amazed with your presentation, crisp and complete information!!!
    Apart from M365 Business Premium licenses, I suppose this feature should also be available for users with E3 licenses,
    What are your thoughts?

    • @StevenMcKenzie-83
      @StevenMcKenzie-83 6 месяцев назад

      @@tejasshirgaonkar9608 yes works for anyone with P1 licence

    • @bearded365guy
      @bearded365guy  6 месяцев назад +1

      @@tejasshirgaonkar9608 Yes, it will be!

  • @expensivetechnology9963
    @expensivetechnology9963 6 месяцев назад

    #JonathanEdwards I like your polished helpful content. However, I’m leery of sharing anything with Microsoft. When I do as you suggest @5:23? (e.g. enabling Microsoft Authenticator) Does this share my IOS passwords with Microsoft Authenticator?

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      @@expensivetechnology9963 No, nothing is shared.

  • @robjeeves
    @robjeeves 4 месяца назад

    bro, man in the mirror :-) Hilarious little joke in there. Good job !!!

  • @mohamehima1792
    @mohamehima1792 5 месяцев назад

    thanks for the video, i followed all the stesp as explained and when i tried to login i got an error "try again"

  • @g04tn4d0
    @g04tn4d0 2 месяца назад +1

    Jesus... what a convoluted way for an end user to have to present their passkey when logging in. Leave it to Microsoft!

  • @adventuresofa9jaguy322
    @adventuresofa9jaguy322 6 месяцев назад

    Currently trying this and i think the CA policy takes time to kick in... maybe ill give it like 2 hrs but i did try the manual one and it doesnt feel seamless.. yubikeys just might be better but more expensive.
    EDIT - it works now! 💪

  • @StijnHommes
    @StijnHommes 6 месяцев назад

    Please stop performing unmarked and misleading advertisements like this.
    1. All advertising needs to be clearly marked in all videos.
    2. Passkeys don't improve your security, so this advert is misleading from the very first line.
    Microsoft should be ashamed of themselves for lying like that. Why would you want to promote that trash?
    Hackers have already circumvented passkey "security".

    • @bearded365guy
      @bearded365guy  6 месяцев назад

      Perhaps you could elaborate….