Microsoft MFA support?
Alan Buxey
alan.buxey at myunidays.com
Thu Jan 9 15:03:50 UTC 2025
hi,
> It occurred to me that if MS supported a model where only MFA was applied
> and password authentication was just skipped, that's more or less how Duo
> works now anyway (it's an OP you proxy to via OIDC). I don't know if MS
> supports that model or not.
>
I believe that EntraID can be configured to allow logins only using
non-password mechanisms (eg FIDO2 key/passkey or windows
authenticator/windows hello etc) - but it's not something that I've
deployed or had any hands-on experience with and the docs all talk about
passing kerberos tokens back to the on-prem directory and having windows
clients of a specific flavour - so I don't know how that would play in the
'just proxy SAML2 and deal with an authentication and any web client'
playground.
I noted this after I received communication about being able to configure
my microsoft account to have no password
alan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250109/4129ed78/attachment.htm>
More information about the users
mailing list