passwordless authentication in (azure) active directory

55
Passwordless Authentication in (Azure) Active Directory Mgr. Michael Grafnetter @MGrafnetter dsinternals.com 26. 3. 2020

Upload: others

Post on 13-Nov-2021

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Passwordless Authentication in (Azure) Active Directory

Passwordless Authenticationin (Azure) Active Directory

Mgr. Michael Grafnetter

@MGrafnetterdsinternals.com

26. 3. 2020

Page 2: Passwordless Authentication in (Azure) Active Directory

Agenda

• Passwordless Authentication Overview

• Microsoft Authenticator

• FIDO2

• Windows Hello for Business

• Choosing The Right Technology

3

Page 3: Passwordless Authentication in (Azure) Active Directory

PasswordsAreDead

4

Page 4: Passwordless Authentication in (Azure) Active Directory

Passwords Are Difficult to Remember

5

Page 5: Passwordless Authentication in (Azure) Active Directory

Passwords Are Exposed in Data Breaches

6

Page 6: Passwordless Authentication in (Azure) Active Directory

Passwords Are Reused

7

Page 7: Passwordless Authentication in (Azure) Active Directory

Passwords Are Subject to Phishing Attacks

8

Page 8: Passwordless Authentication in (Azure) Active Directory

Microsoft’s Strategy is Passwordless

9

Page 9: Passwordless Authentication in (Azure) Active Directory

Passwordless Authentication Options

10

Page 10: Passwordless Authentication in (Azure) Active Directory

What About Smart Cards?

11

Page 11: Passwordless Authentication in (Azure) Active Directory

Microsoft AuthenticatorApp

12

Page 12: Passwordless Authentication in (Azure) Active Directory

Android

Page 13: Passwordless Authentication in (Azure) Active Directory

iOS + watchOS

Page 14: Passwordless Authentication in (Azure) Active Directory

Passwordless Phone Sign-In

Page 15: Passwordless Authentication in (Azure) Active Directory

Demo PasswordlessPhone Sign-In

16

Page 16: Passwordless Authentication in (Azure) Active Directory

Enabling Phone Sign-in

Page 17: Passwordless Authentication in (Azure) Active Directory

Self-Service Registration

https://aka.ms/mysecurityinfo

Page 18: Passwordless Authentication in (Azure) Active Directory

Pairing the App

Page 19: Passwordless Authentication in (Azure) Active Directory

Supported Scenarios

• Azure Active Directory Accounts

• Microsoft Accounts

• No Windows Sign-in

• Self-Service Enrollment Only

Page 20: Passwordless Authentication in (Azure) Active Directory

FIDO2

FastIDentityOnline

21

Page 21: Passwordless Authentication in (Azure) Active Directory

FIDO2 Overview

Page 22: Passwordless Authentication in (Azure) Active Directory

FIDO Alliance Board Level Members

23

Page 23: Passwordless Authentication in (Azure) Active Directory

FIDO Alliance Government Level Members

24

Page 24: Passwordless Authentication in (Azure) Active Directory

FIDO U2F vs. FIDO2

Page 25: Passwordless Authentication in (Azure) Active Directory

FIDO2 Device Management in Windows

Page 26: Passwordless Authentication in (Azure) Active Directory

Device Authentication: PIN + Touch

Page 27: Passwordless Authentication in (Azure) Active Directory

Device Authentication: Biometrics

Page 28: Passwordless Authentication in (Azure) Active Directory

FIDO2 Device Interface: USB, Bluetooth, NFC

Page 29: Passwordless Authentication in (Azure) Active Directory

FIDO2 Usernameless Login

Page 30: Passwordless Authentication in (Azure) Active Directory

Demo FIDO2

Sign-In

31

Page 31: Passwordless Authentication in (Azure) Active Directory

Windows Logon – Azure AD Joined

Page 32: Passwordless Authentication in (Azure) Active Directory

TBA: Authentication in Hybrid Environments

Page 33: Passwordless Authentication in (Azure) Active Directory

FIDO2 Browser Support

Page 34: Passwordless Authentication in (Azure) Active Directory

FIDO2 Mobile Browser Support

Page 35: Passwordless Authentication in (Azure) Active Directory

Enabling FIDO2 Support In Azure AD

36

Page 36: Passwordless Authentication in (Azure) Active Directory

FIDO2 Authenticator Management

Page 37: Passwordless Authentication in (Azure) Active Directory

Auditing FIDO2 Keys In (Azure) AD

Page 38: Passwordless Authentication in (Azure) Active Directory

Free Feitian Sample Devices

39

https://ftsafe.com/pathtopasswordless

Page 39: Passwordless Authentication in (Azure) Active Directory

Windows Hello forBusiness

40

Page 40: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 41: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 42: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 43: Passwordless Authentication in (Azure) Active Directory

WHfB Provisioning UI

Page 44: Passwordless Authentication in (Azure) Active Directory

Windows 10 Logon Screen With PIN

Page 45: Passwordless Authentication in (Azure) Active Directory

Windows Hello UI

Page 46: Passwordless Authentication in (Azure) Active Directory

Demo Windows Hello

Sign-In

47

Page 47: Passwordless Authentication in (Azure) Active Directory

Multifactor Device Unlock

48

Page 48: Passwordless Authentication in (Azure) Active Directory

Dynamic Lock

49

Page 49: Passwordless Authentication in (Azure) Active Directory

Deployment Options

• Hybrid Azure AD Joined Key Trust

• Hybrid Azure AD Joined Certificate Trust

• On Premises Key Trust

• On Premises Certificate Trust

• Azure AD Join Single Sign-on

Page 50: Passwordless Authentication in (Azure) Active Directory

WHfB Prerequisites (Varies)

• Windows 10 1703+

• Windows Server 2016• Active Directory Domain Services (AD DS)

• Active Directory Federation Services (AD FS)

• Active Directory Certificate Services (AD CS)

• Azure Active Directory

• Azure Multi-Factor Authentication (MFA)

• Microsoft Intune

Page 51: Passwordless Authentication in (Azure) Active Directory

Provisioning Methods

52

Page 52: Passwordless Authentication in (Azure) Active Directory

Active Directory NGC Key Auditing

53

Page 53: Passwordless Authentication in (Azure) Active Directory

WrappingThingsUp

54

Page 54: Passwordless Authentication in (Azure) Active Directory

Choosing The Right TechnologyHello for Business FIDO2 Authenticator App

Security Platform Hardware Software

Removable Authenticator Keyring Phone

PIN ✔ ✔ ✔

Biometrics Optional Optional Optional

Azure AD Sign-In ✔ ✔ ✔

Modern Auth App Sign-In ✔ ✔ ✔

Custom Web App Sign-In ✔ ✔ Through Azure AD

Windows Sign-In ✔ Through Azure AD

Phone App Sign-In Partial Support ✔

Air Gap Scenarios ADDS+ADFS 3rd Party ADFS Providers

Passwordless Provisioning With a Smart Card ✔ With FIDO2 or a 2nd Phone

Open Standards Kerberos PKINIT, OAUTH W3C WebAuthn, CTAP2 TOTP

55

Page 55: Passwordless Authentication in (Azure) Active Directory

Passwordless Authenticationin (Azure) Active Directory

Mgr. Michael Grafnetter

@MGrafnetterdsinternals.com

26. 3. 2020