Microsoft MFA support?

Alan Buxey alan.buxey at myunidays.com
Thu Jan 9 15:03:50 UTC 2025


hi,


> It occurred to me that if MS supported a model where only MFA was applied
> and password authentication was just skipped, that's more or less how Duo
> works now anyway (it's an OP you proxy to via OIDC). I don't know if MS
> supports that model or not.
>

I believe that EntraID can be configured to allow logins only using
non-password mechanisms (eg FIDO2 key/passkey or windows
authenticator/windows hello etc) - but it's not something that I've
deployed or had any hands-on experience with and the docs all talk about
passing kerberos tokens back to the on-prem directory and having windows
clients of a specific flavour - so I don't know how that would play in the
'just proxy SAML2 and deal with an authentication and any web client'
playground.

I noted this after I received communication about being able to configure
my microsoft account to have no password

alan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250109/4129ed78/attachment.htm>


More information about the users mailing list