John Doe
lllllll
20%
of support calls for enterprises are
about forgotten passwords
540K
forgotten
passwords
For Microsoft account, on a yearly basis
$5M+
spent on forgotten
passwords
John Doe
lllllll
John Doe
lllllll
2FAPasswords
2FA verification
code: 020987
MESSAGES
+
Passwords + 2FA is more secure, but also
more complicated and difficult to use.
While passwords are bad in some ways….
Human generated symmetric secrets
Easy to provision
Portable
Compatible
Expensive
Inconvenient
Insecure
Human generated symmetric secrets
…Passwords are great in other ways
High Security
Low Security
ConvenientInconvenient
Passwords
2FA verification
code: 020987
MESSAGES
John Doe
lllllll
Passwords +
standard 2FA
?
Path to Passwordless
1. Develop password-
replacement offerings
2. Reduce user-visible
password surface area
3. Transition into
password-less deployment
4. Eliminate passwords
from identity directory
1. Develop
2. Reduce
3. Transition
4. Eliminate
Apps
Web app
Device sign in
App that works
crossplatform
Device + Biometric
Biometric on device
+
Windows 10 or other OS
Microsoft Edge or other browser
Any device
Azure Active
Directory
Microsoft
account
Windows Hello Microsoft Authenticator FIDO2 Security Keys
Ready for Enterprise
69M
active Windows
Hello users
6000+
enterprises have
deployed Windows
Hello for Business
350%
46%
Only for sign in to Windows
What about other platforms?
Doesn’t work for shared PCs
Not portable
Windows Hello Limitations
manini.roy@hotmail.com
??
Phone sign-in using Microsoft Authenticator
Password-less authentication
Public / Private key exchange
Works cross-platform and on all browsers
Microsoft Authenticator
rcalafato@live.com
Passwordless sign in only works with Microsoft
Account and Azure AD
Not all phones have a secure enclave
What if you lose your phone?
Limitations of Authenticator
FIDO2 Protocol
Path to Passwordless
1. Develop password-
replacement offerings
2. Reduce user-visible
password surface area
3. Transition into
password-less deployment
4. Eliminate passwords
from identity directory
Windows Hello
Authenticator App
FIDO
1. Develop
2. Reduce
3. Transition
4. Eliminate
Path to Passwordless
1. Develop password-
replacement offerings
2. Reduce user-visible
password surface area
3. Transition into
password-less deployment
4. Eliminate passwords
from identity directory
Windows Hello for Business
Authenticator App
FIDO
Windows 10S is passwordless
Next
Create account
maniniroy@hotmail.com
Sign in with Microsoft
Offline account Terms of usePrivacy & cookies
Forgot password
Enter your password
Enter the password for karanbir-singh@hotmail.com
● ● ● ● ● ● ● ● ●
Use another method
Manini Roy
Sign in options
PIN
Manini Roy
Manini Roy
Sign in options
PIN
Manini Roy
No passwords!
What’s Coming?
1. Develop password-
replacement offerings
2. Reduce user-visible
password surface area
3. Transition into
password-less deployment
4. Eliminate passwords
from identity directory
Windows Hello for Business
Authenticator App
FIDO2 Security keys
Windows 10S is passwordless
Windows is passwordless
MSA and AAD doesn’t need a
password
Users can create passwordless MSAs
Users can turn off passwords for their existing MSAs
IT admins can turn off passwords
Legacy apps
Initial bootstrapping
Gnarly recovery scenarios
Biggest Gaps
manini.roy@hotmail.com
@manini_roy

Microsoft's Path to Passwordless - FIDO Authentication for Windows & Azure Active Directory