

Organizations with Azure AD joined devices must do this before their devices can authenticate to on-premises resources with FIDO2 security keys. Organizations with hybrid Azure AD joined devices must also complete the steps in the article, Enable FIDO2 authentication to on-premises resources before Windows 10 FIDO2 security key authentication works. Enable with Group Policy (Hybrid Azure AD joined devices only).Organizations may choose to use one or more of the following methods to enable the use of security keys for Windows sign-in based on their organization's requirements: Hybrid Azure AD joined devices must run Windows 10 version 2004 or newer.

For the best experience, use Windows 10 version 1903 or higher.Īzure AD joined devices must run Windows 10 version 1909 or higher.


At the end of this article, you will be able to sign in to both your Azure AD and hybrid Azure AD joined Windows 10 devices with your Azure AD account using a FIDO2 security key. This document focuses on enabling FIDO2 security key based passwordless authentication with Windows 10 devices.
