Are Separate Passkey Policies Necessary for Admins and Regular Users?

0
2
Asked By MellowPine42 On

We currently use Microsoft's default passkey configuration, allowing both passkey types without attestation. I'm considering whether to create different authentication strengths for various user groups.

For highly privileged administrators, I'm looking at attested, device-bound YubiKey credentials, Microsoft Authenticator on iOS or Android, or a one-time Temporary Access Pass. For Global Administrators, staff, and guests, I'm considering Windows Hello hardware or software credentials, Microsoft Authenticator, Temporary Access Pass, or possibly password plus Authenticator push notifications.

Users may have both an iPhone/iCloud Keychain passkey and a Windows or Microsoft Authenticator passkey, so I'm also trying to understand whether synced and device-bound passkeys can coexist under separate policies.

My understanding is that I would target passkey/FIDO2 authentication policies to the appropriate groups, then use Conditional Access policies with authentication strengths tailored to each user type. Is that the right model? For a company with fewer than 15 users, is this level of separation worthwhile, or would a simpler configuration provide adequate security?

2 Answers

Answered By CedarFox7 On

For a small organization, this is probably more complicated than necessary. A sensible baseline is to allow synced passkeys for regular staff and guests, while requiring a device-bound or otherwise strongly controlled credential for highly privileged accounts such as Emergency Access or Global Administrator accounts.

You still need Conditional Access to enforce the requirements, but you may not need a large collection of separate authentication strengths. Let system-preferred authentication and a small number of clearly targeted policies do most of the work. The important distinction is protecting privileged accounts with credentials that cannot be freely synced or copied between devices.

MellowPine42 -

So the practical split would be synced passkeys for regular users, guests, and perhaps Global Administrators, with device-bound credentials reserved for the most sensitive emergency or highly privileged accounts?

Answered By BrightWalrus19 On

This sounds like overengineering for a team of fewer than 15 people. Keep the design easy to understand and maintain: use phishing-resistant authentication wherever practical, define a stronger requirement for privileged accounts, and avoid creating a separate policy for every credential type unless there is a specific risk or compliance requirement.

Make sure emergency access accounts have an appropriate recovery plan and are tested periodically. A smaller policy set that everyone can explain and administer is usually safer than a highly granular setup that becomes difficult to audit.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.