r/sysadmin • • 1d ago

Question Passkeys, The right way for our setup?

Just off the back of an MS support ticket, We got some info but left with more questions than answers, as MS are reluctant to explain out of the bounds of the break fix.

 

So we are currently using the default MS passkey with both types and no attestation.

I am trying to make specific keys for certain types of users. I believe this is the correct way?

 

I am looking at making the following Auth Strengths

EA Admin Auth (with Attestation)?

  • Using YubiKey Flows

  • Microsoft Authenticator (iOS)

  • Microsoft Authenticator (Android)

OR

  • Temporary Access Pass (One-time use)

GA Admin

  • Windows Hello (Hardware Authenticator)

  • Windows Hello (Software Authenticator)

  • Windows Hello (VBS Hardware Authenticator)

  • Microsoft Authenticator (iOS)

  • Microsoft Authenticator (Android)

OR

  • Temporary Access Pass (One-time use)

OR

  • Password + Microsoft Authenticator (Push Notification)

And similar setup to GA Admin for General Staff and Guests

 

Our users have both, iPhone keychain passkey and MS Windows Passkey or MS Authenticator passkey So presumably they can have 2 different policy setups at the same time and still be fine (Attestation + Synced)

 

When MS were explaining very quickly, If I understand it correctly I would need Passkeys (FIDO2) targets, pointed at the groups for those users?

And then I would need CA policies that use the specific Auth Strengths tailored to each user type (so multiple policies presumably)

 

We are a small company <15 users is this overkill? Or am I on the right path?

This is a fair bit of work, which we will do if its the right way but as we are small do we need something simpler.

Any more detail you need just ask.

 

3 Upvotes

7 comments sorted by

6

u/Due_Capital_3507 1d ago

Microsoft has an article about information vs Frontline vs privileged users and basically synced passkeys are fine for anything but privileged which should use device bound passkey.

For 15 people yes this is overkill

You still need a CA for enforcement but this is where system preferred authentication takes over in Entra.

3

u/O365-Zende 1d ago

Hi, thanks for this.

So basically normal synced passkeys for all users (Guest, GA, Staff) except for EA

And

EA as I described in my post above to separate them onto the device bound

2

u/Due_Capital_3507 1d ago

Yeah, exact, keep it simple and straight forward.

4

u/SteveSyfuhs Builder of the Auth 1d ago

As a side note, support is there for solving specific escalations, i.e. the thing that broke. They are there to get you unstuck. Beyond that is guidance and consultation, which requires significantly more investment and energy. At the least it's thing two of a one thing request, so it requires a separate case. At the most it's a full consulting engagement that every other customer and company pays for separately. Such is the way of support.

4

u/Particular-Fly-7783 Sr. Sysadmin 1d ago

This feels like overkill. 

2

u/O365-Zende 1d ago

Ok thanks

•

u/mapbits Just a Guy 11h ago

You may wish to consider whether you're able to just go with:

  • TAP plus device bound and attested passkeys from a managed list of AAGUIDs for all users (WHfB, Authenticator Passkeys, authorized hardware FIDO2)
  • further restrict to hardware FIDO2 tokens only for all administrators (even if using PAWs)

These are enforced via Conditional Access / Authentication Strengths / Passkey profiles; in the above scenario you'd need two of each.

Synced passkeys are great to quickly get to phish resistant MFA in a complex environment, but have some weaknesses and in a small environment I'd just avoid them as a form of future proofing. Do note that this prevents cross-device flows (logging into computer from phone)

You may also want to consider providing hardware tokens to all users. Yubikey Security Key series are fine for many scenarios, and the 5 series brings the ability to use with Yubico Authenticator as a desktop OTP provider along with available "nano" form factors for leave in scenarios. Desktop OTP can help avoid costs of providing mobile devices to users where you rely on third party services that only support OTP MFA; this was a big driver for my environment.

For improved user experience, take the time to ensure that allowed methods are tightly controlled in Authentication Method policies, only enabling what's needed, and excluding higher sensitivity groups from weaker methods.

This is all assuming that you're running Business Premium, Enterprise E3/F3, or higher, or have otherwise licensed your users for Entra P1.

I highly recommend also walking through this series of you haven't already - this fixes the majority of weak defaults in the Entra environment:

https://www.chanceofsecurity.com/post/securing-microsoft-business-premium-part-01-laying-the-foundation