


If set to no, your users won't be able to register a FIDO key through the MySecurityInfo portal, even if enabled by Authentication Methods policy. Allow self-service set up should remain set to Yes.There are some optional settings on the Configure tab to help manage how security keys can be used for sign-in. As a workaround, replace the users and groups you are trying to add with a single group, in the same operation, and then click Save again.

If you see an error when you try to save, the cause might be due to the number of users or groups being added.

Under the method FIDO2 Security Key, click All users, or click Add groups to select specific groups. Enable FIDO2 security key methodīrowse to Azure Active Directory > Security > Authentication methods > Authentication method policy. Follow the steps in the article Enable combined security information registration, to enable combined registration. Registration features for passwordless authentication methods rely on the combined registration feature. Enable passwordless authentication method Enable the combined registration experience Hybrid Azure AD joined devices must run Windows 10 version 2004 or higher. Prepare devicesįor Azure AD joined devices, the best experience is on Windows 10 version 1903 or higher. These include Microsoft Edge, Chrome, Firefox, and Safari. To use security keys for logging in to web apps and services, you must have a browser that supports the WebAuthN protocol.
