Step-by-Step Information : The way to allow QR code authentication for Microsoft Entra ID (Preview) ?


Microsoft Entra ID helps an extended checklist of Authentication strategies.

  • Home windows Hey for Enterprise
  • Microsoft Authenticator app
  • Authenticator Lite
  • Passkey (FIDO2)
  • Certificates-based authentication
  • {Hardware} OATH tokens (preview)
  • Software program OATH tokens
  • Exterior authentication strategies (preview)
  • Momentary Entry Move (TAP)
  • Brief Message Service (SMS) sign-in and verification
  • Voice name verification
  • Password

This allows organizations to pick probably the most safe and productive authentication strategies for his or her enterprise. Whereas probably the most safe technique could not at all times be the most efficient, and vice versa, having a wide range of supported authentication strategies helps to strike a steadiness between these two elements.

Microsoft Entra ID now helps QR authentication, a way particularly designed for frontline staff who use shared units. This supplies a handy and safe login expertise for these staff.

1)        An account with Authentication Coverage Administrator permission or greater can allow QR code as an authentication technique.

2)        As soon as the strategy is enabled, a QR code and non permanent PIN could be generated for the consumer.

3)        The QR code must be made obtainable to the consumer. It may be downloaded, printed, or added to a badge.

4)        The QR code is exclusive however can’t be used with out the PIN.

5)        The non permanent PIN have to be reset when the consumer authenticates for the primary time.

6)        As soon as the QR code and PIN are arrange, the consumer can use them for subsequent logins.

1)        QR authentication is designed for frontline staff and shouldn’t be extensively used. Phishing-resistant authentication is really helpful wherever attainable.

2)        Don’t allow this authentication technique for all customers; solely allow it for required customers.

3)        QR authentication is at the moment solely supported on cell units operating iOS/iPadOS or Android.

4)        QR authentication doesn’t permit self-service PIN reset for customers.

On this weblog put up I’m going to display methods to configure QR authentication for the Microsoft Entra ID customers.

Let’s begin with enabling authentication technique.

  1. Log in to the Entra admin portal at https://entra.microsoft.com/as an Authentication Coverage Administrator or greater.
  2. Navigate to Safety | Authentication Strategies.

  1. Beneath Insurance policies, click on on QR code (Preview).

  1. Within the QR code (Preview) settings web page, click on on Allow to activate the authentication technique. Then, choose the related consumer group because the goal.

  1. Click on on the Configure tab. Right here, you may modify the PIN size and the lifetime of the QR code. The default is twelve months, however it may be prolonged as much as 395 days. As soon as modifications are made, click on on Save to use them.

This allows the QR code as an authentication technique for the tenant. Subsequent, let’s have a look at methods to generate a QR code for a consumer.

To generate QR code for consumer,

  1. Navigate to Customers | All customers.
  2. Choose the consumer from the goal group configured within the earlier part.
  3. Click on on Authentication strategies.

 

  1. Click on on + Add authentication technique.

  1. From the dropdown, choose QR code (Preview).

 

 

  1. Within the settings web page, outline the expiration date and activation time. Click on on Generate PIN to create a brief PIN. Observe down the PIN and click on on Add.

 

  1. It will generate the QR code. Obtain it to be used with authentication.

 

Now that we now have generated a QR code for a consumer, let’s proceed with some testing.

For testing, I used an iOS machine to log in to the workplace portal. On the login web page, I typed the username after which clicked on Signal-in choices.

 

 

Within the Signal-in choices web page, I chosen Check in to a company.

 

On the following web page, I selected Check in with QR code.

 

I clicked on Permit to grant entry to the digicam.

 

After that, I scanned the QR code downloaded within the earlier step.

 

As soon as the QR code was efficiently detected, I entered the non permanent PIN that was generated and clicked on Check in.

 

On the following web page, I used to be prompted to outline a brand new PIN since this was the primary login. After defining the PIN, I clicked on Check in.

 

As anticipated, I used to be in a position to log in efficiently.

 

 

This marks the top of the weblog put up, and I imagine you now have a greater understanding of methods to allow and use QR code for authentication.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles