# How to enable FIDO2 passwordless authentication with Microsoft Azure AD for use with Windows 10-11

### 1. Add the user to the AD

1. Sign in to the [Azure portal](https://portal.azure.com/).
2. Go to **Azure Active Directory → Users**.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2Fc4DUEd1JZhhYLrHvgdck%2Fimage.png?alt=media&#x26;token=558d40b4-45e4-47dd-8a86-60ca1d8b9a70" alt="" width="563"><figcaption></figcaption></figure>

3. Click **New User**, fill in the required fields.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2F6sYDhtcCfc6AnxKnXidP%2Fimage.png?alt=media&#x26;token=a8cc40ad-7e66-4f44-944c-1959f6103632" alt="" width="507"><figcaption></figcaption></figure>

4. Click **Create**.

* The new user will appear in the list and will be ready for login.

### 2. Enable Authentication Methods and FIDO2 Keys

1. Sign in to the [Azure portal](https://portal.azure.com/) with a **Global Admin** or **Security Admin** account.
2. Go to **Azure Active Directory → Security → Authentication methods**.
3. Select **Passkey (FIDO2)**.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2Fx5N2hj3BtBg2eRy9XeEs%2Fimage.png?alt=media&#x26;token=bedeceea-5e73-44b7-96ac-c421f39f7955" alt="" width="563"><figcaption></figcaption></figure>

4. Set **Enable** to **Yes** → Click **Save**.

* A success notification will appear.

5. (Recommended) Also, enable passwordless sign-in via the **Microsoft Authenticator app**.

*Reference:* [*Microsoft official instructions*](https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-security-key-windows#enable-security-keys-for-windows-sign-in)

### 3. Join a PC to Microsoft Entra ID (Azure AD)

1. On the workstation, go to **Settings → Accounts → Access work or school → Connect**.
2. Click **Join this device to Microsoft Entra ID (Azure Active Directory)**.

<figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/9PxxrqPaDxcStTyTnmk6/Screenshot_1.jpg" alt="" width="375"><figcaption></figcaption></figure>

3. Enter the user’s Azure AD login and temporary password → set a new password.
4. Click **Join** to confirm.
5. Verify the new account appears in **Settings**.

   * You can now log in with the Azure AD password.
   * System may prompt you to set up MFA (e.g., via phone) and a Windows PIN.

   ![](https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/NaORn0d6DdeHvNYrcblA/image.png)
6. Click the "Join" button:

![](https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/PSLGOPByeRzKGm3SEmcM/image.png)

7. Verify that the new account appears in **Settings**.

* Users can now log in with their Azure AD account.
* The system may require **multi-factor authentication (MFA)** and a **Windows PIN**.

![](https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/0plbmnOBq9yZN8WRNaxQ/image.png)

### 4. Enable FIDO2 Logon Support on Windows

1. Apply the provisioning package **FIDO enable package.ppkg (7KB)** to configure Windows for FIDO2 login.
   * Double-click the file, **or**
   * Go to **Settings → Accounts → Access work or school → Add a provisioning package**.

{% file src="<https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/TZqgt3GBT8T85gaOIHzZ/FIDO%20enable%20package.ppkg>" %}

{% hint style="info" %}
This package configures Windows to allow FIDO2 security keys (such as Hideez Key) for passwordless login. Run it by double-clicking or applying via the “Access work or school” > “Add a provisioning package” option in Windows settings.
{% endhint %}

### 5. Register a Security Key in Microsoft Account

1. Sign in at [My Profile](https://myprofile.microsoft.com/).
2. Go to **Security Info** → add a phone number (required for MFA).

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2F4vHi6lvyLXbRniIV2eFr%2Fimage.png?alt=media&#x26;token=86838e09-2c4e-4813-9b39-f63a531e92f2" alt=""><figcaption></figcaption></figure>

3. Pair the **Hideez Key** with Windows.

{% embed url="<https://www.youtube.com/watch?v=3qw2appqR50>" %}

4. In **Security Info**, click **Add Method → Security Key**.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FiLsKGPTyH4JmtfgGGNrQ%2Fimage.png?alt=media&#x26;token=0a98cb6f-868e-4e31-8a5d-43d9c47fdb3d" alt="" width="375"><figcaption></figcaption></figure>

5. Follow the prompts:

* Insert or tap the security key.
* Enter the **PIN code** of your security key when requested.
* **Press the button** on the key (or tap NFC) to confirm.

<div><figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FsualTTVmXA5l0HcXYoiG%2Fimage.png?alt=media&#x26;token=dfdc0e7b-bec0-4406-a52c-7a84ba77c60b" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FPtGbilbZa710Ob1xpg9e%2Fimage.png?alt=media&#x26;token=3669b3d5-df0f-4b10-9a49-8c11562b2ac6" alt=""><figcaption></figcaption></figure> <figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FpgSA3jF9JI3sJYvErksh%2Fimage.png?alt=media&#x26;token=45330a7f-de65-4c9b-82c5-37bbda02a085" alt=""><figcaption></figcaption></figure></div>

* Assign a name to the key.

![](https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/alcwiAsydQfObAc5Nzlm/image.png)

6. Confirm the key is listed among available authentication methods.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FfCFckpYNzWbTJBQY0fap%2Fimage.png?alt=media&#x26;token=18150e02-c8c9-4b6a-b703-954c367e8660" alt="" width="563"><figcaption></figcaption></figure>

Now you can use [unlock PC by Security Key scenario](https://enterprise.hideez.com/use-cases/fido-security-key/unlock-pc-by-security-key).


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://enterprise.hideez.com/faq/hideez-key/how-to-enable-fido2-passwordless-authentication-with-microsoft-azure-ad-for-use-with-windows-10.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
