Entra ID & IdentityHow-To & HardeningRetrospectives

How to Deploy FIDO2 Security Keys for High-Risk Users

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.

FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.

Step 1: Choose who gets keys first

Prioritize: Global and privileged administrators, executives and their assistants, finance and payroll staff, IT help desk, and anyone with access to sensitive systems.

Step 2: Choose keys

Pick FIDO2-certified keys that support your devices (USB-A, USB-C, NFC for mobile). Many organizations issue two keys per user — one primary, one backup stored securely. Check the key's AAGUID against Microsoft's list of compatible vendors if you plan to restrict models.

Step 3: Enable FIDO2 in Entra ID

In Authentication methods → Passkey (FIDO2):

  • Enable for the target group.
  • Optionally enforce attestation and restrict to specific AAGUIDs (approved key models).
  • Consider allowing device-bound passkeys in Microsoft Authenticator as an alternative for some users.

Step 4: Registration

Use Temporary Access Pass to let users register keys securely without a password. Users register at the My Security Info page.

Step 5: Enforce

Create a Conditional Access policy requiring authentication strength: Phishing-resistant MFA for the target group and admin roles.

Step 6: Recovery process

Define what happens when a key is lost: identity verification by help desk (not by easily known information), Temporary Access Pass issuance, and registration of a replacement key.

Step 7: Expand

Track adoption and extend to more users. Passkeys on phones make broader rollout cheaper.

deploy fido2 security keys0ktapus / Twilio2022

More on this story