
If the sign-in via authenticator app is not displayed directly, you have to select this option manually via “Other ways to sign-in”. After unlocking, the displayed number can now be selected and confirmed.Īnd voilà, a short time later you are signed-in to your Windows 10 device. This increases security and should not be disabled. By default, it is necessary to unlock the Authenticator app. A corresponding notification is now displayed on the smartphone. Now it is possible to select it during sign-in and after entering the user name, a number is displayed that you must select on your smartphone. This includes not only the smartphone itself, but also the Windows 10 device.įor this to be possible, the Web Sign-in login option must be enabled on the device.
:max_bytes(150000):strip_icc()/MSauthenticatorAppSetup1-fab3f7575abb4646b86a938ecfbc775d.jpg)
A device can only be registered in one Azure AD at a time, so this feature is effectively limited to one account.Īfter the successful setup, this type of sign-in can be used on any supported device. This requirement is at the same time a problem for people with many accounts in multiple tenants. In the authenticator app, the account must be selected and the registration started via “Set up phone sign-in”.įor the verification, you have to sign-in again with the TAP and then register the phone with the Azure AD. It is therefore a good idea to perform this setup directly during onboarding.

Now the phone Sign-In feature must be enabled on the smartphone. The steps described above are only half the job. It is best to install the app on your smartphone in advance and then start the process. To be able to use the passwordless sign-in via Authenticator app, it must first be added as a second factor in My Security Portal. But there is a solution for this as well: Microsoft does not currently support FIDO2 sign-in on Android or iOS, so a password would be required for sign-in on the smartphone. Unfortunately, there is still a gap in order to get along completely without a password.

So far, we have only used FIDO2 security keys and Windows Hello for Business for sign-in. PowerShell administration without a password.Windows 10 device onboarding and Windows Hello for Business.
