Skip to content
English
  • There are no suggestions because the search field is empty.

FIDO2 Authentication [CHK-1170]

This check determines if users can set FIDO2 as an authentication method.

Rationale

FIDO2 is a standard that provides phishing-resistant security keys for authentication. Enabling this method allows users to better secure their accounts.

Fix

An automated fix is available through Attic.

Manual steps:

  1. Navigate to Entra ID portal at https://entra.microsoft.com
  2. Go to Authentication methods > Policies
  3. Click on "FIDO2 security key"
  4. Set "Enable" to "Yes"
  5. Under "Target", select "All users" or specific groups
  6. Under "Configure", set "Allow self-service set up" to "Yes"
  7. Click "Save"

Impact

Current configuration:

  • FIDO2 Status:
  • Self-registration:

Recommended configuration:

  • FIDO2 Status: enabled
  • Self-registration: true

More Information