How to enable FIDO2 passwordless authentication with Microsoft Azure AD for use with Windows 10-11
1. Add the user to the AD
Sign in to the Azure portal.
Go to Azure Active Directory → Users.

Click New User, fill in the required fields.

Click Create.
The new user will appear in the list and will be ready for login.
2. Enable Authentication Methods and FIDO2 Keys
Sign in to the Azure portal with a Global Admin or Security Admin account.
Go to Azure Active Directory → Security → Authentication methods.
Select Passkey (FIDO2).

Set Enable to Yes → Click Save.
A success notification will appear.
(Recommended) Also, enable passwordless sign-in via the Microsoft Authenticator app.
Reference: Microsoft official instructions
3. Join a PC to Microsoft Entra ID (Azure AD)
On the workstation, go to Settings → Accounts → Access work or school → Connect.
Click Join this device to Microsoft Entra ID (Azure Active Directory).

Enter the user’s Azure AD login and temporary password → set a new password.
Click Join to confirm.
Verify the new account appears in Settings.
You can now log in with the Azure AD password.
System may prompt you to set up MFA (e.g., via phone) and a Windows PIN.
Click the "Join" button:

Verify that the new account appears in Settings.
Users can now log in with their Azure AD account.
The system may require multi-factor authentication (MFA) and a Windows PIN.

4. Enable FIDO2 Logon Support on Windows
Apply the provisioning package FIDO enable package.ppkg (7KB) to configure Windows for FIDO2 login.
Double-click the file, or
Go to Settings → Accounts → Access work or school → Add a provisioning package.
5. Register a Security Key in Microsoft Account
Sign in at My Profile.
Go to Security Info → add a phone number (required for MFA).

Pair the Hideez Key with Windows.
In Security Info, click Add Method → Security Key.

Follow the prompts:
Insert or tap the security key.
Enter the PIN code of your security key when requested.
Press the button on the key (or tap NFC) to confirm.



Assign a name to the key.

Confirm the key is listed among available authentication methods.

Now you can use unlock PC by Security Key scenario.
Last updated
Was this helpful?