Top Banner
Passwordless Authentication in (Azure) Active Directory Mgr. Michael Grafnetter @MGrafnetter dsinternals.com 26. 3. 2020
55

Passwordless Authentication in (Azure) Active Directory

Nov 13, 2021

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Passwordless Authentication in (Azure) Active Directory

Passwordless Authenticationin (Azure) Active Directory

Mgr. Michael Grafnetter

@MGrafnetterdsinternals.com

26. 3. 2020

Page 2: Passwordless Authentication in (Azure) Active Directory

Agenda

• Passwordless Authentication Overview

• Microsoft Authenticator

• FIDO2

• Windows Hello for Business

• Choosing The Right Technology

3

Page 3: Passwordless Authentication in (Azure) Active Directory

PasswordsAreDead

4

Page 4: Passwordless Authentication in (Azure) Active Directory

Passwords Are Difficult to Remember

5

Page 5: Passwordless Authentication in (Azure) Active Directory

Passwords Are Exposed in Data Breaches

6

Page 6: Passwordless Authentication in (Azure) Active Directory

Passwords Are Reused

7

Page 7: Passwordless Authentication in (Azure) Active Directory

Passwords Are Subject to Phishing Attacks

8

Page 8: Passwordless Authentication in (Azure) Active Directory

Microsoft’s Strategy is Passwordless

9

Page 9: Passwordless Authentication in (Azure) Active Directory

Passwordless Authentication Options

10

Page 10: Passwordless Authentication in (Azure) Active Directory

What About Smart Cards?

11

Page 11: Passwordless Authentication in (Azure) Active Directory

Microsoft AuthenticatorApp

12

Page 12: Passwordless Authentication in (Azure) Active Directory

Android

Page 13: Passwordless Authentication in (Azure) Active Directory

iOS + watchOS

Page 14: Passwordless Authentication in (Azure) Active Directory

Passwordless Phone Sign-In

Page 15: Passwordless Authentication in (Azure) Active Directory

Demo PasswordlessPhone Sign-In

16

Page 16: Passwordless Authentication in (Azure) Active Directory

Enabling Phone Sign-in

Page 17: Passwordless Authentication in (Azure) Active Directory

Self-Service Registration

https://aka.ms/mysecurityinfo

Page 18: Passwordless Authentication in (Azure) Active Directory

Pairing the App

Page 19: Passwordless Authentication in (Azure) Active Directory

Supported Scenarios

• Azure Active Directory Accounts

• Microsoft Accounts

• No Windows Sign-in

• Self-Service Enrollment Only

Page 20: Passwordless Authentication in (Azure) Active Directory

FIDO2

FastIDentityOnline

21

Page 21: Passwordless Authentication in (Azure) Active Directory

FIDO2 Overview

Page 22: Passwordless Authentication in (Azure) Active Directory

FIDO Alliance Board Level Members

23

Page 23: Passwordless Authentication in (Azure) Active Directory

FIDO Alliance Government Level Members

24

Page 24: Passwordless Authentication in (Azure) Active Directory

FIDO U2F vs. FIDO2

Page 25: Passwordless Authentication in (Azure) Active Directory

FIDO2 Device Management in Windows

Page 26: Passwordless Authentication in (Azure) Active Directory

Device Authentication: PIN + Touch

Page 27: Passwordless Authentication in (Azure) Active Directory

Device Authentication: Biometrics

Page 28: Passwordless Authentication in (Azure) Active Directory

FIDO2 Device Interface: USB, Bluetooth, NFC

Page 29: Passwordless Authentication in (Azure) Active Directory

FIDO2 Usernameless Login

Page 30: Passwordless Authentication in (Azure) Active Directory

Demo FIDO2

Sign-In

31

Page 31: Passwordless Authentication in (Azure) Active Directory

Windows Logon – Azure AD Joined

Page 32: Passwordless Authentication in (Azure) Active Directory

TBA: Authentication in Hybrid Environments

Page 33: Passwordless Authentication in (Azure) Active Directory

FIDO2 Browser Support

Page 34: Passwordless Authentication in (Azure) Active Directory

FIDO2 Mobile Browser Support

Page 35: Passwordless Authentication in (Azure) Active Directory

Enabling FIDO2 Support In Azure AD

36

Page 36: Passwordless Authentication in (Azure) Active Directory

FIDO2 Authenticator Management

Page 37: Passwordless Authentication in (Azure) Active Directory

Auditing FIDO2 Keys In (Azure) AD

Page 38: Passwordless Authentication in (Azure) Active Directory

Free Feitian Sample Devices

39

https://ftsafe.com/pathtopasswordless

Page 39: Passwordless Authentication in (Azure) Active Directory

Windows Hello forBusiness

40

Page 40: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 41: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 42: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 43: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 44: Passwordless Authentication in (Azure) Active Directory

Windows 10 Logon Screen With PIN

Page 45: Passwordless Authentication in (Azure) Active Directory

Windows Hello UI

Page 46: Passwordless Authentication in (Azure) Active Directory

Demo Windows Hello

Sign-In

47

Page 47: Passwordless Authentication in (Azure) Active Directory

Multifactor Device Unlock

48

Page 48: Passwordless Authentication in (Azure) Active Directory

Dynamic Lock

49

Page 49: Passwordless Authentication in (Azure) Active Directory

Deployment Options

• Hybrid Azure AD Joined Key Trust

• Hybrid Azure AD Joined Certificate Trust

• On Premises Key Trust

• On Premises Certificate Trust

• Azure AD Join Single Sign-on

Page 50: Passwordless Authentication in (Azure) Active Directory

WHfB Prerequisites (Varies)

• Windows 10 1703+

• Windows Server 2016• Active Directory Domain Services (AD DS)

• Active Directory Federation Services (AD FS)

• Active Directory Certificate Services (AD CS)

• Azure Active Directory

• Azure Multi-Factor Authentication (MFA)

• Microsoft Intune

Page 51: Passwordless Authentication in (Azure) Active Directory

Provisioning Methods

52

Page 52: Passwordless Authentication in (Azure) Active Directory

Active Directory NGC Key Auditing

53

Page 53: Passwordless Authentication in (Azure) Active Directory

WrappingThingsUp

54

Page 54: Passwordless Authentication in (Azure) Active Directory

Choosing The Right TechnologyHello for Business FIDO2 Authenticator App

Security Platform Hardware Software

Removable Authenticator Keyring Phone

PIN ✔ ✔ ✔

Biometrics Optional Optional Optional

Azure AD Sign-In ✔ ✔ ✔

Modern Auth App Sign-In ✔ ✔ ✔

Custom Web App Sign-In ✔ ✔ Through Azure AD

Windows Sign-In ✔ Through Azure AD

Phone App Sign-In Partial Support ✔

Air Gap Scenarios ADDS+ADFS 3rd Party ADFS Providers

Passwordless Provisioning With a Smart Card ✔ With FIDO2 or a 2nd Phone

Open Standards Kerberos PKINIT, OAUTH W3C WebAuthn, CTAP2 TOTP

55

Page 55: Passwordless Authentication in (Azure) Active Directory

Passwordless Authenticationin (Azure) Active Directory

Mgr. Michael Grafnetter

@MGrafnetterdsinternals.com

26. 3. 2020