Identity security

Phishing-Resistant MFA

FIDO2 security keys and passkeys configured with attention to authentication methods, device behavior, registration failures, and Conditional Access requirements.

Overview

This project introduced phishing-resistant authentication options through FIDO2 security keys and passkeys in Microsoft Entra ID.

Environment

Microsoft Entra ID authentication methods, FIDO2 security keys, passkeys, authenticator AAGUID behavior, and Conditional Access requirements.

Objective

Provide stronger authentication methods while ensuring registration behavior and policy decisions matched the intended Conditional Access design.

Responsibilities

Configured authentication methods, reviewed AAGUID behavior, investigated registration failures, and aligned deployment decisions with Conditional Access requirements.

Implementation

  • Enabled and configured supported FIDO2 security-key and passkey methods.
  • Reviewed device AAGUID behavior relevant to method policy.
  • Resolved registration failures rather than treating enrollment as a one-step configuration change.

Validation

Validation centered on successful registration, expected authenticator behavior, and alignment between the chosen methods and Conditional Access requirements.

Outcome

Registration failures were resolved and deployment decisions incorporated verified authentication-method and AAGUID behavior.

Technologies

  • Microsoft Entra ID
  • FIDO2
  • Passkeys
  • Conditional Access

Disclosure note

Operational details have been sanitized. User identities, authenticator inventory, policy values, and tenant configuration are not published.