How should we configure passkeys and authentication strengths for a 15-person Microsoft environment?

0
0
Asked By MellowPine47 On

We currently use Microsoft's default passkey configuration, supporting both synced and device-bound passkeys without attestation. I'm trying to work out whether we should create different authentication strengths and passkey policies for different user groups.

For highly privileged administrators, I'm considering attested YubiKey flows, Microsoft Authenticator on iOS and Android, or a one-time Temporary Access Pass. For other administrators, staff, and guests, I'm considering Windows Hello, Microsoft Authenticator, Temporary Access Pass, or password plus Authenticator push notifications.

Users may have both an iCloud Keychain passkey and a Windows or Microsoft Authenticator passkey, so I'm also wondering whether synced and attested/device-bound passkeys can coexist under separate policies.

My understanding is that I would target passkey or FIDO2 policies to the appropriate groups, then use Conditional Access policies with authentication strengths tailored to each user type. Is that the correct model? For a company with fewer than 15 users, is this level of separation worthwhile, or would a simpler setup provide enough security without creating unnecessary administrative work?

2 Answers

Answered By CedarFox82 On

The general approach is sound, but the design is probably more complex than necessary for a 15-person organization. Synced passkeys are generally suitable for ordinary staff and guest accounts, while highly privileged accounts should use phishing-resistant, device-bound credentials such as properly managed security keys. You still need Conditional Access for enforcement, but authentication strengths and system-preferred authentication can usually handle the selection without creating a large number of overlapping policies.

MellowPine47 -

So the practical split would be synced passkeys for staff, guests, and less-privileged administrators, with device-bound or attested keys reserved for the most privileged accounts?

Answered By QuietMaple19 On

This sounds like overengineering for such a small environment. Start with a simple baseline: require phishing-resistant authentication for privileged administrators, use passkeys or Authenticator for everyone else, keep strong recovery methods available, and apply the policies to clearly defined groups. Add attestation or separate authentication strengths only if you have a specific compliance or risk requirement that justifies the extra maintenance.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.