How to Deploy FIDO2 Security Keys for High-Risk Users
Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.
FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.
Step 1: Choose who gets keys first
Prioritize: Global and privileged administrators, executives and their assistants, finance and payroll staff, IT help desk, and anyone with access to sensitive systems.
Step 2: Choose keys
Pick FIDO2-certified keys that support your devices (USB-A, USB-C, NFC for mobile). Many organizations issue two keys per user — one primary, one backup stored securely. Check the key's AAGUID against Microsoft's list of compatible vendors if you plan to restrict models.
Step 3: Enable FIDO2 in Entra ID
In Authentication methods → Passkey (FIDO2):
- Enable for the target group.
- Optionally enforce attestation and restrict to specific AAGUIDs (approved key models).
- Consider allowing device-bound passkeys in Microsoft Authenticator as an alternative for some users.
Step 4: Registration
Use Temporary Access Pass to let users register keys securely without a password. Users register at the My Security Info page.
Step 5: Enforce
Create a Conditional Access policy requiring authentication strength: Phishing-resistant MFA for the target group and admin roles.
Step 6: Recovery process
Define what happens when a key is lost: identity verification by help desk (not by easily known information), Temporary Access Pass issuance, and registration of a replacement key.
Step 7: Expand
Track adoption and extend to more users. Passkeys on phones make broader rollout cheaper.
- 0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies Incident Teardowns
- Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: The Case for Hardware Security Keys CIO Briefings