

Select “Device enrollment” -> “Windows enrollment” -> Windows Hello for BusinessĦ. Press “Members” to add the Azure AD devices which you want to use. In this Lab I will manually assign the devices and therefore select the membership type “Assigned”. Select group type “Security” and give the group a recognizable name. Go to “Azure Active Directory” and select “Groups”ģ. First create a group containing your test device in the Azure AD this group will be used to assign the deviceconfiguration. The Azure Tenant has now been setup, now it’s time for the Device Configuration.ġ. (On this moment Key Restriction Policy cannot be used in Public Preview). In this lab I will configure “all” but in a production environment you will probably only allow a group of testuser(s). Now the FIDO2 Security Key can be enabled by pressing on the text “FIDO2 Security Key”, the FIDO2 Security settings screen will pop-up. Press “Save” to save your choice and press “Authentication methods – Authentication method policy (Preview) to continue.ĥ. Configure which user groups can use the preview features. Press the link “Click her to enable users for the enhanced registration preview”Ĥ. The Authentication Methods screen will open.


Select the “Azure Active Directory” and go to “Authentication methods”ģ. Sign in to the Azure Portal with the Global adminĢ. Let’s begin with setting up the Azure Tenant:ġ.
