1. Home
  2. Knowledge Base
  3. Office 365
  4. How to register a FIDO2 key as an Azure AD sign-in method

How to register a FIDO2 key as an Azure AD sign-in method

Implementing MFA is a key step to securing your business. However not all MFA is created equal. MFA is still susceptible to certain attacks, such as push bombing, social engineering, or various SMS-related vulnerabilities.

The Gold Standard for phishing resistant MFA [] is to use a FIDO2-capable hardware key, where the key must be physically present in order to confirm access.

Setting up your new FIDO2 hardware key with your Microsoft 365 account

Common vendors for FIDO2-compliant security keys include Yubico, TrustKey, and FEITAN.

If your organization has issued you a FIDO2 key, follow the steps below to get set up for secure access to your Microsoft 365 account:

  1. In your web browser, go to and login.
  2. Make sure you’re on the Security Info page. Click Add sign-in method.
  3. Choose security key and click Add.
  4. If you already have MFA set up, you’ll be prompted to confirm it. If not, you’ll be required to set one up; reach out to GreenLoop and request that we issue you a Temporary Access Pass that will meet this requirement.
  5. You will be prompted to Choose the type of security key you have. In most cases, you’ll have a USB key.
  6. Get your key ready, and hit Next.
  7. In Windows, you will be prompted to create a passkey:

  8. Click Ok to confirm that the request from your browser to Windows is authorized:
  9. Confirm again:
  10. Insert your key into an open USB port when prompted. Note that this does not always work with docking stations and USB hubs; it may need to be directly connected to the PC in order to work.
  11. If this is a brand new key, you’ll be prompted to create a security PIN. This is a hardware PIN specific to the hardware key:

    Otherwise, enter your existing PIN:
  12. Touch your key when prompted to continue setup:
  13. Give your key a name.
  14. You’re done! You can use the hardware key to securely access your Microsoft 365 account. Keep this key in a safe place!

Using your FIDO2 hardware key to authenticate to Microsoft 365

Now that your FIDO2 hardware key is set up, follow these steps to use it to authenticate:

  1. Enter your username when prompted,
  2. You should be prompted to Sign in with a security key:
  3. Provide the security key (that you set up on step #11 above):
  4. Touch your security key when prompted:
  5. You’re done!

Related Articles