Become a Microsoft-compatible FIDO2 security key vendor
Most hacking related breaches use either stolen or weak passwords. Often, IT will enforce stronger password complexity or frequent password changes to reduce the risk of a security incident. However, this increases help desk costs and leads to poor user experiences as users are required to memorize or store new, complex passwords.
FIDO2 security keys offer an alternative. FIDO2 security keys can replace weak credentials with strong hardware-backed public/private-key credentials which cannot be reused, replayed, or shared across services. Security keys support shared device scenarios, allowing you to carry your credential with you and safely authenticate to an Azure Active Directory joined Windows 10 device that’s part of your organization.
Microsoft partners with FIDO2 security key vendors to ensure that security devices work on Windows, the Microsoft Edge browser, and online Microsoft accounts, to enable strong password-less authentication.
You can become a Microsoft-compatible FIDO2 security key vendor through the following process. Microsoft doesn't commit to do go-to-market activities with the partner and will evaluate partner priority based on customer demand.
- First, your authenticator needs to have a FIDO2 certification. We will not be able to work with providers who do not have a FIDO2 certification. To learn more about the certification, please visit this website: https://fidoalliance.org/certification/
- After you have a FIDO2 certification, please fill in your request to our form here: https://forms.office.com/r/NfmQpuS9hF. Our engineering team will only test compatibility of your FIDO2 devices. We won't test security of your solutions.
- Once we confirm a move forward to the testing phase, the process usually take about 3-6 months. The steps usually involve:
- Initial discussion between Microsoft and your team.
- Verify FIDO Alliance Certification or the path to certification if not complete
- Receive an overview of the device from the vendor
- Microsoft will share our test scripts with you. Our engineering team will be able to answer questions if you have any specific needs.
- You will complete and send all passed results to Microsoft Engineering team
- Initial discussion between Microsoft and your team.
- Upon successful passing of all tests by Microsoft Engineering team, Microsoft will confirm vendor's device is listed in the FIDO MDS.
- Microsoft will add your FIDO2 Security Key on Azure AD backend and to our list of approved FIDO2 vendors.
Current partners
The following table lists partners who are Microsoft-compatible FIDO2 security key vendors.
Next steps
Povratne informacije
Pošalјite i prikažite povratne informacije za