OneSpan's innovative FIDO2 passwordless technology allows users to securely sign in to Azure AD (Microsoft Entra ID) using a USB key, completely removing the need for traditional passwords. Once set up, users can effortlessly access their accounts and log onto their Windows devices (whether joined to EntraAD or Hybrid AD) with DIGIPASS FX7 authenticators. This method ensures robust two-factor authentication by requiring both the physical security key and a PIN or biometric verification (such as a fingerprint) configured on the FIDO2 security keys.
This guide provides step-by-step instructions on how to enable DIGIPASS FX7 authenticators in EntraID and set them as the default security measure for Microsoft 365 logins. Follow these steps to adopt a modern, passwordless authentication method and enhance your organization's security.
The Entra ID Admin center is available at https://entra.microsoft.com.
Step 1: Enable the Passkey (FIDO2) authentication method
- Select Protection > Authentication Methods. 
- Click Passkey (FIDO2) settings. 
- Enable All Users. 
- Switch to the Configure tab. 
- Use the following configuration: - Allow self-service setup: YES 
- Enforce attestation: YES 
- Enforce key restrictions: YES 
- Restrict specific keys: Allow 
- Clear the Microsoft Authenticator box. 
- Click Add AAGUID of the DIGIPASS FX7 authenticator. - The AAGUID for the DIGIPASS FX7 is 30b5035e-d297-4ff7-b00b-addc96ba6a98.  
 
Step 2: Configure the authentication strengths
- Select Protection > Authentication Methods. 
- Select Manage > Authentication Strengths. 
- Click New Authentication Strength to add a new authentication method and use the following configuration: - Name: Passkeys (FX7) Only 
- Check: Passkeys (FIDO2) 
 
- Under Advanced Options: - Click Add AAGUID and type 30b5035e-d297-4ff7-b00b-addc96ba6a98. 
- Click Save. 
 
- Select Temporary Access Pass (Multi-Use). - Click Next. 
- Click Save. 
 
Step 3: Disable the security defaults
- Sign in to the Microsoft Entra admin center as at least a security administrator. 
- Select Identity > Overview > Properties. 
- Click Manage security defaults. - Set Security defaults to Disabled. 
- Click Save. 
 .png?sv=2022-11-02&spr=https&st=2025-10-26T20%3A18%3A20Z&se=2025-10-26T20%3A30%3A20Z&sr=c&sp=r&sig=xDV93Oj2JZKK0kE1c8fXT8yew7as1eJ4ejpf0Vg5Epc%3D) 
Step 4: Create a group for PasskeyOnly users
- Select Users > Groups > All Groups. 
- Click New Group and use the following configuration: - Group Name: PasskeyOnly 
- Group Type: Security 
 
- Add users to the group that should use Passkeys Only for MFA. .png?sv=2022-11-02&spr=https&st=2025-10-26T20%3A18%3A20Z&se=2025-10-26T20%3A30%3A20Z&sr=c&sp=r&sig=xDV93Oj2JZKK0kE1c8fXT8yew7as1eJ4ejpf0Vg5Epc%3D) 
Step 5: Configure conditional access
- Select Protection > Conditional Access. 
- Switch to Policies. 
- Click New Policy to create a new policy and use the following configuration: - Name: Require multifactor authentication for group passkeys only 
- Users: Select the PasskeyOnly group previously created. 
 
- Switch to Access Controls and configure: - Select Grant Access 
- Select Require Authentication Strength. 
- Select Passkeys (FX7) Only in the drop-down list. 
- Click Select. 
- Set Enable Policy to On. 
- Click Save. 
  
Step 6: Assign a temporary access pass to a user
- Select Users > All Users. 
- Select a user account. 
- Switch to Authentication Methods. 
- Click Add Authentication Method to configure a new method and use the following configuration settings: - Choose Method: Temporary Access Pass 
- Set a duration value. 
- Set One-Time use according to your organizational policies. 
 
- Click Add. 