gsk Posted August 11 Posted August 11 Hi All, I thought it would be interesting to see what people are assessing the impact to them will be. I know we've got a few people who rely on SMS/Voice for various reasons (of varying validity!). The vast majority of our users use authenticator push notifications. I've not given it enough (any) thought yet to see how these users might be impacted and what training and actions we'll need to put in place, if anything. Thanks,
jmak Posted August 11 Posted August 11 I'm aiming to push our users towards passkeys as quickly as we can. We've had multiple successful phishing attacks despite authenticator based MFA. Issues for us (not a school): 1) A mostly universal solution for an alternative second factor when they lose/change/forget/drown their phone 2) An option for people who want to login to desktop computers that they haven't used before, e.g. presenting at a venue that has a PC as part of the hosts AV setup. There's a third internal issue for us: the team that runs the tenancy is not the team that runs active directory. I haven't yet persuaded them to talk to each other and run the command that will allow it as authentication for logins to domain PCs.
gsk Posted August 11 Author Posted August 11 Good luck getting the different departments to talk. What’s you preferred form factor for storing passkeys?
pete Posted August 11 Posted August 11 Happily, we banned SMS and voice auth more than a year ago and moved the handful of SMS users to a physical token or an authenticator app. The interesting part comes when the (token-using) person needs N+1 authenticators for different work-related websites that can't use an existing source of truth. You can get physical tokens that can hold N+1 authenticators (https://www.token2.com/products/token2-molto-1-i-multi-profile-totp-hardware-token) but setup isn't straightforward for an end-user.
jmak Posted August 11 Posted August 11 23 minutes ago, gsk said: Good luck getting the different departments to talk. What’s you preferred form factor for storing passkeys? Most people use laptops and for the last four years I've specified fingerprint readers and most of the new ones have Windows Hello capable cameras, so for convenience I think most people will have a passkey on their main device. I have one on my phone in the MS Authenticator app which I find works well. The user experience with a hardware token on the machine you're logged in on is much better than even simple passwords. I'm sure it'll be broken at some point but I think they're a genuine upgrade for users and admins.
gsk Posted August 11 Author Posted August 11 3 hours ago, jmak said: Most people use laptops and for the last four years I've specified fingerprint readers and most of the new ones have Windows Hello capable cameras, so for convenience I think most people will have a passkey on their main device. I have one on my phone in the MS Authenticator app which I find works well. The user experience with a hardware token on the machine you're logged in on is much better than even simple passwords. I'm sure it'll be broken at some point but I think they're a genuine upgrade for users and admins. I’d like to understand this better. So you issue them with a laptop, they enrol into windows hello on that device and then what’s the process to get them using passkeys on there?
itskdog Posted August 17 Posted August 17 On 11/08/2026 at 23:06, gsk said: I’d like to understand this better. So you issue them with a laptop, they enrol into windows hello on that device and then what’s the process to get them using passkeys on there? When you go to enrol or use a passkey on a website, it just asks for your WHfB credentials (e.g. PIN, Face, Fingerprint). Entra will enrol the passkey automatically, so you won't need to manually enrol for any services with SSO.
gsk Posted August 17 Author Posted August 17 On 12/08/2026 at 11:55, jmak said: This is my draft user guide Passkey_Setup_Guide.pdf 118.09 kB · 29 downloads This is brilliant - thanks for sharing.
gsk Posted August 17 Author Posted August 17 13 minutes ago, itskdog said: When you go to enrol or use a passkey on a website, it just asks for your WHfB credentials (e.g. PIN, Face, Fingerprint). Entra will enrol the passkey automatically, so you won't need to manually enrol for any services with SSO. How is this looking/working across multiple devices. One of my biggest frustrations with WHfB is that it doesn’t sync those authentication methods back to entra so that you can enrol a face onto one laptop and then log in on another laptop without re-enrolling.
itskdog Posted August 17 Posted August 17 29 minutes ago, gsk said: How is this looking/working across multiple devices. One of my biggest frustrations with WHfB is that it doesn’t sync those authentication methods back to entra so that you can enrol a face onto one laptop and then log in on another laptop without re-enrolling. WHfB is bound to the device, they can use their password still on other devices. So far only my machine has WHfB enabled, to test. Haven't done a wider rollout as so many devices are shared.
cjw1903 Posted August 17 Posted August 17 @itskdog Once you setup the WHfB passkey, do you see it as one of your authentication methods on the Security info section on your account? We have rolled out WHfB but with the SMS depreciation happening soon, we are not sure if staff can only have WHfB it looks like they will also need another form i.e a passkey in the authenticator app. So we have to target getting those with SMS and those with only SMS + WHfB
gsk Posted August 17 Author Posted August 17 2 hours ago, itskdog said: WHfB is bound to the device, they can use their password still on other devices. So far only my machine has WHfB enabled, to test. Haven't done a wider rollout as so many devices are shared. How does they passkey situation work if you log in on another device?
gsk Posted August 17 Author Posted August 17 2 hours ago, itskdog said: WHfB is bound to the device, they can use their password still on other devices. So far only my machine has WHfB enabled, to test. Haven't done a wider rollout as so many devices are shared. Also, what method are you using to target WHfB? I’d like to target it to users rather than devices if possible.
itskdog Posted August 17 Posted August 17 2 hours ago, gsk said: Also, what method are you using to target WHfB? I’d like to target it to users rather than devices if possible. Disabled in the enrollment configuration and also on a default policy that applies to all devices (with the WHfB device group excluded), then a second policy that enables it, targeting the same group, and a third custom policy to disable Post-logon provisioning (as that CSP is not in the Settings Catalog). I'm sure if you used a user group instead, and the User version of the policies rather than the Device version, it might work.
gsk Posted August 17 Author Posted August 17 Oooh disabling the post-login provisioning would be good. With the result being that users can enrol to WHfB but aren’t prompted to? Any chance of sharing that custom policy please?
itskdog Posted August 18 Posted August 18 11 hours ago, gsk said: Oooh disabling the post-login provisioning would be good. With the result being that users can enrol to WHfB but aren’t prompted to? Any chance of sharing that custom policy please? https://learn.microsoft.com/en-us/windows/client-management/mdm/passportforwork-csp#devicetenantidpoliciesdisablepostlogonprovisioning
gsk Posted August 18 Author Posted August 18 Ah, looks like it's only applicable to Insider builds. Thanks for the link
mdrabble Posted August 19 Posted August 19 How are you managing to get students/parents to move over to the Authenticator app? I would say the vast majority of students/parents use SMS when accessing emails etc off site (despite info being sent out for MS Authenticator)
pete Posted August 19 Posted August 19 ^ Most students who have the Bromcom MIS app on their phones also have the Outlook Mobile app on their phones (due to *interesting* design choices in the initial authentication setup for the student MIS app). Outlook mobile can function as a (not particularly great) second factor. If it's working, great. If it breaks and it's the only second factor it's annoying to resolve compared to standard MFA reset.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now