> For the complete documentation index, see [llms.txt](https://enterprise.hideez.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://enterprise.hideez.com/faq/hideez-key/how-to-enable-fido2-passwordless-authentication-with-microsoft-azure-ad-for-use-with-windows-10.md).

# How to enable FIDO2 passwordless authentication with Microsoft Azure AD for use with Windows 10-11

### 1. Add the user to the AD

1. Sign in to the [Azure portal](https://portal.azure.com/).
2. Go to **Azure Active Directory → Users**.

<figure><img src="/files/sB2yPGEmxTBNWFlLCiEj" alt="" width="563"><figcaption></figcaption></figure>

3. Click **New User**, fill in the required fields.

<figure><img src="/files/BjwitDBhRpB4epjb3JQ3" alt="" width="507"><figcaption></figcaption></figure>

4. Click **Create**.

* The new user will appear in the list and will be ready for login.

### 2. Enable Authentication Methods and FIDO2 Keys

1. Sign in to the [Azure portal](https://portal.azure.com/) with a **Global Admin** or **Security Admin** account.
2. Go to **Azure Active Directory → Security → Authentication methods**.
3. Select **Passkey (FIDO2)**.

<figure><img src="/files/TVWJFzJYsEfcP8jsH3XH" alt="" width="563"><figcaption></figcaption></figure>

4. Set **Enable** to **Yes** → Click **Save**.

* A success notification will appear.

5. (Recommended) Also, enable passwordless sign-in via the **Microsoft Authenticator app**.

*Reference:* [*Microsoft official instructions*](https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-security-key-windows#enable-security-keys-for-windows-sign-in)

### 3. Join a PC to Microsoft Entra ID (Azure AD)

1. On the workstation, go to **Settings → Accounts → Access work or school → Connect**.
2. Click **Join this device to Microsoft Entra ID (Azure Active Directory)**.

<figure><img src="/files/AHsC0WjSi9RdAThE7ufT" alt="" width="375"><figcaption></figcaption></figure>

3. Enter the user’s Azure AD login and temporary password → set a new password.
4. Click **Join** to confirm.
5. Verify the new account appears in **Settings**.

   * You can now log in with the Azure AD password.
   * System may prompt you to set up MFA (e.g., via phone) and a Windows PIN.

   <img src="/files/Db5v8ZK0X7iqaxjtNqYk" alt="" width="563">
6. Click the "Join" button:

<img src="/files/JJTMbkhYhG6q2w4SLkYp" alt="" width="563">

7. Verify that the new account appears in **Settings**.

* Users can now log in with their Azure AD account.
* The system may require **multi-factor authentication (MFA)** and a **Windows PIN**.

<img src="/files/oLFTGfaFtCdEXaAP2eoI" alt="" width="563">

### 4. Enable FIDO2 Logon Support on Windows

1. Apply the provisioning package **FIDO enable package.ppkg (7KB)** to configure Windows for FIDO2 login.
   * Double-click the file, **or**
   * Go to **Settings → Accounts → Access work or school → Add a provisioning package**.

{% file src="/files/KVr0tw38B0H7Icyhkofx" %}

{% hint style="info" %}
This package configures Windows to allow FIDO2 security keys (such as Hideez Key) for passwordless login. Run it by double-clicking or applying via the “Access work or school” > “Add a provisioning package” option in Windows settings.
{% endhint %}

### 5. Register a Security Key in Microsoft Account

1. Sign in at [My Profile](https://myprofile.microsoft.com/).
2. Go to **Security Info** → add a phone number (required for MFA).

<figure><img src="/files/jQ7t5mvADatmVMgAzhlC" alt=""><figcaption></figcaption></figure>

3. Pair the **Hideez Key** with Windows.

{% embed url="<https://www.youtube.com/watch?v=3qw2appqR50>" %}

4. In **Security Info**, click **Add Method → Security Key**.

<figure><img src="/files/OyT9UkKjWefw9SeJt8gX" alt="" width="375"><figcaption></figcaption></figure>

5. Follow the prompts:

* Insert or tap the security key.
* Enter the **PIN code** of your security key when requested.
* **Press the button** on the key (or tap NFC) to confirm.

<div><figure><img src="/files/n2vhUDgSEH4RD4TTDtxI" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/bmXVYBQthI7hmjf7nso5" alt=""><figcaption></figcaption></figure> <figure><img src="/files/wUKBS9pWMcgyMQRDug9a" alt=""><figcaption></figcaption></figure></div>

* Assign a name to the key.

<img src="/files/bbKyobroh2cK4KZNgfnM" alt="" width="563">

6. Confirm the key is listed among available authentication methods.

<figure><img src="/files/GyLRLAmb66crgKFutNl3" alt="" width="563"><figcaption></figcaption></figure>

Now you can use [unlock PC by Security Key scenario](/use-cases/fido-security-key/unlock-pc-by-security-key.md).
