An open standard, used together with WebAuthn, that underpins passkeys and hardware security keys. Sign-in relies on a private key kept on the device in place of a password, so it resists phishing.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-900SC-900AB-900SC-300MD-102ALZ
Each book explains FIDO2 in context, with comparison tables and the common traps.
Terms in this definition
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID.
Related terms
- AAGUID
Passkey profiles and authentication strengths can permit or refuse particular authenticators by this value. It is a 128-bit ID handed over by the passkey (FIDO2) maker when a key is registered, telling Microsoft Entra which make and model it is.
- Authentication methods policy
Tenant-level Microsoft Entra policy that switches on each sign-in method, such as FIDO2, Authenticator, certificate-based authentication, TAP or SMS, for chosen users or groups.
- NFC
Short-distance radio connection offered by some FIDO2 keys as an alternative to plugging in over USB.
- Passkey profile
A named group of passkey (FIDO2) settings applied to chosen groups, covering attestation, whether device-bound or synced passkeys are permitted, and AAGUID restrictions. Opting in is permanent and transfers your current settings into the Default passkey profile.
- Phishing-resistant MFA
Authentication that is tied to the real website and the user's device, so a fake site cannot capture and replay it. Examples include passkeys (FIDO2), Windows Hello for Business and certificate-based authentication used as multifactor; Conditional Access can demand these through a built-in authentication strength.