Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FIDO2 support #5768

Open
KuotingChiu opened this issue Feb 13, 2025 · 3 comments
Open

FIDO2 support #5768

KuotingChiu opened this issue Feb 13, 2025 · 3 comments

Comments

@KuotingChiu
Copy link

Is FIDO2 supported ? My organization mandates to use Smartcard and the get-credential never works for us as the password is unknown. With FIDO2 be enabled for our Microsoft 365 tenant, we can now use the YuriKey for create secret key and authenticate. However, M365DSC seems not support the FIDO2 authentication, can you please confirm that? Also, if it is indeed not supported, is this something will be supported in the future?

Thank you in advance!

George Chiu
The Hartford

@FabienTschanz
Copy link
Collaborator

FabienTschanz commented Feb 13, 2025

@KuotingChiu FIDO2 is only supported in PowerShell 7 onwards, see Authentication Commands - Graph PowerShell. So you probably can use Microsoft365DSC for exporting your configuration in PowerShell 7, but it's not possible to apply or test configurations since these require Windows PowerShell 5.1.

Edit: After further checking, I don't think that will work either. We are dependent on the credentials (like password and username) since there is currently nothing implemented that uses FIDO2 authentication. Don't know if this is planned, but from what I think, it probably won't be coming in the near (or rather distant) future.

@KuotingChiu
Copy link
Author

Thanks @FabienTschanz for reviewing! How about the -AccessTokens parameter of Export-M365DSCConfiguration ? Will I be able to use it (i.e. use either Smartcard or FIDO2 to authenticate and get the access token to pass via this parameter)? There are not many good example within M365DSC documentation but there are some other posts elsewhere talking about it

@FabienTschanz
Copy link
Collaborator

@KuotingChiu The AccessTokens parameter is supported across a couple of resource, but I don't think over all of them. You'll have to try and see how it goes unfortunately. I don't quite know how you get such an access token though.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants