Skip to main content

Authentication Method - FIDO2 security key - Allow self-service set up

Allows users to register a FIDO key through the MySecurityInfo portal, even if enabled by Authentication Methods policy.

NameisSelfServiceRegistrationAllowed
ControlAuthentication Method - FIDO2 security key
DescriptionDefine configuration settings and users or groups that are enabled to use FIDO2 security keys
SeverityHigh

How to fix

Microsoft Learn - Enable passkeys (FIDO2) for your organization: Allow self-service set up

Details of configuration item

Recommendation
Configurationpolicies/authenticationMethodsPolicy/authenticationMethodConfigurations('Fido2')
SettingisSelfServiceRegistrationAllowed
Recommended Value'true'
Default Valuetrue
Graph API Docsfido2AuthenticationMethodConfiguration resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer