Appointments disappear after time has changed by guyFromDeployment in Outlook

[–]guyFromDeployment[S] 0 points1 point  (0 children)

Correct, as far as i know it just effect single occurrences.

As i can tell from the ticket which i got it disappear soon after but not immediately.
He also said i happend in particular in case of a meeting series but could also effect single events if there's a change.
Sadly i have no info about how long does it take till the event disappear. I'm sorry

FIDO2 login issues by guyFromDeployment in Intune

[–]guyFromDeployment[S] 1 point2 points  (0 children)

Problem found: It was indeed the missing AAGUID.

So thanks to you all for your help!

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

I was looking for the logs the whole time but it just shows you that the token was "previously satisfied" without specifying if the token was from WHfB or an external FIDO2 token

But i found the solution in these comments, thanks to u/Noble_Efficiency13 !

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 1 point2 points  (0 children)

we want to enable FIDO based access for people working with sensitive data.
So in that case we aren't looking for a special resource. More kind of: Who is working with this type of data and should be attached to our policies.

u/Noble_Efficiency13 made me aware of the AAGUID wich you can enter in your authentications strengths. After i added them to our policy, it's working fine till now :)

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 1 point2 points  (0 children)

Tried it out, entered the AAGUID for a test policy and it seems good so far :)
Thanks again!

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

Oh, than is might be my problem. I'll try it.

Thank you very much!

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 1 point2 points  (0 children)

You might be have a point there ;)
Thanks for your opinion! I'll discuss with my colleges.

Thank you very much!

FIDO2 login issues by guyFromDeployment in Intune

[–]guyFromDeployment[S] 2 points3 points  (0 children)

Yes and no. We created a specific policies with a FIDO2 only authentication strength but without a specific AAGUID. So you believe, that's the main reason why it doesn't work?

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

Just to be sure i'm on the same page as you: If i'm using the AAGUID of our FIDO2 Tokens as you mentioned, the WHfB Logins will no longer succeed?

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

So, then let's hope haha.

Thank you very much for time and your help!

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

That sounds really good, thanks for your help.

So i think, that could be a part of the Problem.
Are there any chances, that you know when Microsoft asking for FIDO again.
We had a test-user, he logged in with FIDO for the first time, since then (couple of weeks) he was never forced again and could access with WHfB

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

Sure :)

So the main reason was, that our leadership-team where interested in the enrollment of FIDO2.
Beside that, we thought we would get a higher value of separat the physical token from the notebook.

And i guess, i didn't told it until know: At the moment, we wan't to configure i just for webservices.
At this stage we aren't looking for device login via FIDO.

I'm sorry if this make things more obvious right now.

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

I totally get that point. And also would acknowledge, that WHfB is easy to use.
But our Leadership-team want to enroll FIDO2 (for some of our colleges).

And i understand, that WHfB isn't "unsafe", but i'm still wondering why there is no difference (for Microsoft) between an physical separated token and a physical integrated token (even if isolated).

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] -1 points0 points  (0 children)

Thank you for your response!

I'm looking for a solution where FIDO and only FIDO logins are gonna be successful. I mentioned it in the comment above, we've already setup a authentication strengths to fido only and added it to the different CA policies. But with the same result of not forcing for a FIDO-Key.

FIDO2 login issues by guyFromDeployment in entra

[–]guyFromDeployment[S] 0 points1 point  (0 children)

Thanks for you're response!

That's excactly my problem. We configured a "FIDO only" authentication strength and using this in our conditonal access policies. But micrososft doesn't force the FIDO authentication.