
Passwordless support for "Windows 365, Azure Virtual Desktop and Virtual Desktop Infrastructure" is now available at the preview stage for Windows 11 participants in the Windows Insider testing program, the announcement noted. Passwordless improvements are coming to Microsoft's desktop-as-a-service offerings, Windows Hello for Business and Microsoft Authenticator app, among others. Microsoft signaled its embrace of the FIDO passwordless standards and described product advancements in its Thursday announcement. Thus, this feature is managed by MS that have not been explicitly disabled by an administrator.Operating system platform makers Apple, Google and Microsoft on Thursday all embraced the FIDO passwordless approach in a joint announcement. If the status of the feature is set to “Microsoft-managed”, Microsoft will activate it at an appropriate time after the preview period. AAD validate the private / public key and returns the token.

The nonce will be signed with the private key and send to the AAD.The user unlock the private key via a authentication via pin or biometric.The app calls Azure AD and receives a proof-of-presence challenge and nonce.

The user gets the notification and opens the authenticator app.Via a push notification service using the APNS (iOS) or FCM (android) a notification will be send to the device of the user.Azure AD detects that the user has strong credentials and starts the Strong Credential flow.

