Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
18 days ago

This guide provides instructions to configure Active Directory–joined devices and Active Directory hybrid–joined devices for RSA MFA Agent 2.5 or later for Microsoft Windows.

The Agent uses Active Directory Certificate Services (AD CS) to enable secure passwordless authentication.

Users must register a FIDO Passkey or RSA Authenticator and use it along with their AD password for the first authentication. Subsequent authentications require only a supported passwordless method. Supported passwordless methods include FIDO Passkeys, QR Code, Mobile Passkey, Authenticate OTP, SecurID OTP, Device Biometrics, and Emergency Access Code.

Passwordless authentication is supported when the Agent connects directly to the Cloud Access Service (CAS), or in hybrid deployments that use Authentication Manager (AM) 8.9 or later. Both passwordless and password + step-up authentication are supported on AD-joined and AD/Entra ID hybrid-joined devices. Hybrid-joined devices follow the same configuration steps as AD-joined devices.

See Configure Hybrid Joined Devices for the RSA MFA Agent for instructions on configuring hybrid joined devices to work with the MFA Agent.

 

Configure Active Directory Joined Devices for the RSA MFA Agent

To configure passwordless authentication for users on AD-joined devices, follow the below steps.

  1. Confirm that Prerequisites are met.
  2. Set Up CAS.
  3. Configure GPO Settings.
  4. Create Certificate Templates in the Certificate Authority.
  5. Test authentication or onboard/offboard authentication methods using the RSA MFA Agent Authentication Utility.
  6. See Passwordless Authentication Flows for details about the flow of the first and subsequent passwordless authentications.

Prerequisites

  1. Confirm that the system requirements are met. See the System Requirements section in Chapter 2: Preparing for Installation in the Installation and Administration Guide.

  2. Install or upgrade the Agent.
    For fresh installations, refer to Chapter 3: Installing MFA Agent in the Installation and Administration Guide
    If you are upgrading the MFA Agent on machines already using FIDO Passkeys for primary authentication (from version 2.3.4 or later) or machines using password + step-up to version 2.4 or later, see Upgrading to Passwordless.

  3. Create a challenge group to control access to resources protected by the MFA Agent by specifying which users to challenge for passwordless authentication.
    The group can be a default Windows group or a group you create using the Windows Computer Management interface or AD. If you want to use a group other than a Windows default group, create it before configuring the Agent.
    Confirm that any group you create is recognized by AD and can be queried. For more information on creating groups, refer to your Microsoft Windows documentation.
    You can configure challenge settings with the GPO setting RSA Primary Authentication Challenge Group and determine how the MFA Agent treats users whose group membership cannot be determined with the GPO setting RSA Primary Authentication Challenge Settings.
    For more information, see the Group Policy Object Template Guide.

  4. Confirm that the following user requirements are met:
    To use passwordless authentication methods, users must register on RSA My Page and enroll one of the following authenticators:
    • RSA Authenticator app (iOS or Android), which supports Approve, Device Biometrics, QR Code, Authenticate OTP, and Mobile Passkey
    • SID700 Hardware Authenticators
    • A FIDO2-certified security key, such as the RSA DS100 or RSA IShield 2

    Users must register their FIDO2-certified Passkey on RSA My Page and set a PIN for it in order to be able to authenticate using FIDO Passkey.
    For more information about supported devices and apps, see CAS User Requirements on RSA Community.

  5. Confirm that the following Active Directory requirements are met:
    • Users must have valid Active Directory passwords to successfully authenticate for the first time.
    • The Smart card is required for interactive logon option in the Account tab of the Active Directory user properties should not be selected.

    Confirm that the following Active Directory Certificate Services requirements are met:

  6. Confirm that the following RSA Certificate Authority requirements are met:
    • The CA server must be reachable from the Agent machine.
    • Certificates used by the MFA Agent must be trusted by all Agent machines.
    • The Smartcard Logon certificate template must be available in the CA.
    • Administrators must have permission to create and manage certificate templates in AD.

For more information, see the Installation and Administration Guide.

 

Upgrading to Passwordless

This section describes how to upgrade machines that already use FIDO Passkeys for primary authentication. The upgrade process applies to RSA MFA Agent 2.3.4 or later upgrading to version 2.4 or later. After the upgrade, FIDO Passkey credentials remain valid, and users can continue to onboard other passwordless authentication methods.

For upgrade instructions for devices using password + step-up authentication, see the Upgrading to Passwordless section in Chapter 3: Installing MFA Agent in the Installation and Administration Guide.

Perform the following before upgrading the Agent on Active Directory machines using FIDO Passkeys for primary authentication.

  1. Update the CAS policy
    Update the existing policy (or create a new one) in the Cloud Administration Console to include FIDO Passkey or any of the supported primary authentication methods. Ensure the policy name is correctly reflected in the Cloud Access Service Access Policy GPO setting.
    Note: This is mandatory for machines that were previously FIDO Passkey-enabled. Failing to include FIDO Passkey will result in login issues post-upgrade.

  2. Download Agent Passwordless Public Key

    1. In the Cloud Administration Console, navigate to My Account > Company Settings > Company Information > Agent Passwordless Public Key and click Download.
    2. Open the downloaded .pem file and copy the contents starting from -----BEGIN PUBLIC KEY----- up to and including -----END PUBLIC KEY-----
    3. Paste the content into the Cloud Access Service Public Key for Passwordless Authentication GPO setting.
    4. Push the updated configurations using GPO and immediately upgrade the MFA Agent to the latest version.

For more information, see the Upgrading to Passwordless section in Chapter 3: Installing MFA Agent in the Installation and Administration Guide.

 

Set Up CAS

You or your CAS administrator must complete these tasks:

  • Connect and synchronize AD with CAS.
  • Create an access policy containing passwordless authentication methods as primary authentication methods. Do the following:
    1. Log in to your CAS tenant.
    2. In the Cloud Administration Console, go to Access > Policies.
    3. Create a new policy or edit an existing one. For instructions, see Add an Access Policy in Add, Clone, or Delete an Access Policy on RSA Community.
    4. In the Primary Authentication tab, add at least one of the supported primary authentication methods:
      • FIDO Passkey
      • QR Code (RSA Agent)
      • Device Biometrics (RSA Agent)
      • Mobile Passkey (RSA Agent)
      • Authenticate OTP
      • SecurID OTP
      • Emergency Access Code
    5. Click Save and Finish.
    6. Publish your changes.

  • If you want to use conditional authentication based on location or IP address, create trusted locations and trusted networks and configure the access policy to use them. For more information, see Create a Network Zone in Manage Networks and Add a Trusted Location in Add or Delete a Trusted Location on RSA Community.

  • Obtain the REST protocol RSA Authentication API Key for the Cloud Access Service. The Agent sends this key to the RSA Authentication API to securely identify authentication requests. For instructions, see Add an RSA Authentication API Key in Manage the RSA Authentication API Keys on RSA Community.

  • Obtain the REST Authentication URL for Cloud Access Service. The REST Authentication URL uses the following format:
    https://<hostname>:<port>/
    To obtain the <hostname>, in the Cloud Administration Console, go to Platform > API Access Management > Authentication API Keys.

  • Perform the following steps to download the Agent Passwordless Public Key from CAS:
    1. In the Cloud Administration Console, go to My Account > Company Settings.
    2. Navigate to Company Information.
    3. Under Agent Passwordless Public Key, click Download.
       

  • Perform the following steps to obtain the FIDO Relying Party ID from CAS:
    1. In the Cloud Administration Console, go to Platform > Identity Router.
    2. Select an identity router and click Edit.
    3. Click Registration.
    4. Get the FIDO Relying Party ID from the value in the Authentication Service Domain field.
    5. If not configured, the FIDO Relying Party ID will be extracted from the RSA Authentication API REST URL.

    If you want users to avoid additional authentication after a successful FIDO Passkey primary authentication, ensure that FIDO Passkey is configured as the Higher assurance level authentication method in the access policy compared to other methods.

Configure GPO Settings for Active Directory Passwordless Authentication

Configure the required RSA MFA Agent GPO settings with CAS connection values, certificate settings, and Passkey configurations to enable passwordless authentication for AD-joined and hybrid-joined devices.

The following GPO settings are required for allowing passwordless authentication for Active Directory users:

  • RSA Authentication API REST URL
  • RSA Authentication API Key
  • Cloud Access Service Access Policy
  • Configure Passwordless Authentication
  • Enable RSA Authentication
  • Exclude the Microsoft Password Credential Provider
  • Specify Logging Options
  • Active Directory CA Name, Active Directory CA Hostname, Certificate Template, Certificate Key Length, Certificate Subject
  • FIDO Relying Party ID
  • CAS Public Key for Passwordless Authentication
  • RSA Primary Authentication Challenge Group, RSA Primary Authentication Challenge Settings

The following GPO settings can also be configured for passwordless authentication:

  • Enable Proximity for Passwordless Authentication
  • Configure Additional Authentication for Passwordless-Excluded users
  • Disable Offline QR Code Authentication
  • Maximum offline QR code onboarding attempts
  • Specify the FIDO Custom Help Text for Registration
  • Specify the FIDO Custom Help Text to Set the FIDO Passkey PIN
  • Specify the FIDO Custom Help Text to Reset the Blocked FIDO Passkey
  • Specify the FIDO Custom Help Text for Invalid Credentials
  • Specify the Custom Help Text When Passwordless Authentication Cannot be Configured
  • Specify the Custom Help Text for Registration of Passwordless Authentication
  • Signing In with Windows Password When Passwordless Authentication is Unavailable
  • Disable Additional Authentication for Passwordless-Excluded Users during Offline Authentication

For instructions on retrieving the Active Directory CA Name, Active Directory CA Hostname, Certificate Template Name, and Certificate Subject Name, see the Connect the MFA Agent to the Authentication Service section in Chapter 6: Configure and Manage MFA Agent in the Installation and Administration Guide.

For the complete list of GPO settings, detailed descriptions, and configuration examples, refer to the Configure GPO Settings for Active Directory Passwordless Authentication section in Chapter 5: Enabling RSA MFA Agent on Active Directory and Hybrid Joined Machines in the Installation and Administration Guide.

 

Create Certificate Templates in Certificate Authority

You can either create a certificate template manually or use the RSA Passwordless Certificate Utility.

The RSA MFA Agent Passwordless Certificate Utility includes a PowerShell script (RSA_MFA_Agent_For_Windows_Passwordless_Certificate_Utility_v1.0.ps1) and a default JSON template (RSASmartcardTemplate.json) for managing certificate templates in an AD environment.

This command line utility automates the certificate template creation process required for the RSA MFA Agent for Microsoft Windows passwordless use cases.

The utility is available for download on the RSA ID Plus Downloads page on RSA Community.

The utility allows you to:

  • Create a template using the JSON configuration file
  • Customize template validity and renewal periods
  • Retrieve template details
  • Remove a template

For detailed installation steps and command and parameters definitions, see the Installation and Administration Guide.

For instructions to create a certificate template manually, see the Installation and Administration Guide.

 

RSA MFA Agent Authentication Utility

You can use the RSA MFA Agent Authentication Utility to test online and offline passwordless authentication. You can also use this utility to enable passwordless authentication. The Authentication Utility is automatically installed when you install the MFA Agent. You can ask your users to test authentication using this utility and share these instructions with them.

Procedure

  1. Sign in to a computer where the MFA Agent is installed.

  2. Click Start > RSA > RSA MFA Agent Authentication Utility.
    The Test Authentication tab opens by default.

  3. Enter the name of the user for whom you are testing authentication.
    Enter a simple name (for example, myuser) or an email address (for example, myuser@mydomain.com). This name is displayed for users and cannot be edited.

  4. If you entered a simple user name, specify the domain (for example, mydomain).
    Note: Passwordless authentication cannot be enabled for local user accounts.

  5. Click Test Online Authentication.

  6. Perform authentication using a supported passwordless method, such as FIDO Passkey, QR Code, Device Biometrics, Authenticate OTP, SecurID OTP, or Mobile Passkey.
    The MFA Agent verifies your credentials with CAS and prompts for additional authentication if required.
    If passwordless authentication is successfully enabled, a confirmation message appears.

  7. Wait 60 seconds after successful online authentication, and then click Test Offline Authentication.
    Authenticate again using a supported method.
    If offline passwordless authentication is successful, a confirmation message appears.

If authentication is successful, you can sign in to your computer without entering a password. For more information, see Passwordless Authentication Flows.

Passwordless Onboarding

The Passwordless Onboarding functionality enables users to onboard supported passwordless authentication methods so they can sign in using those methods.

First-Time Launch (No Onboarded Methods)

If the user has no onboarded methods, the following procedure applies:

  1. Click Passwordless Authentication Onboarding.
    The user is prompted to authenticate using the default method configured in the CAS access policy. Other supported passwordless authentication methods (also as configured in the access policy) are displayed under the More ways to sign in menu.
  2. Perform the authentication. A success message appears.
    If QR Code, Mobile Passkey, SecurID OTP, Authenticate OTP, or Biometrics was used to authenticate, all other non-FIDO supported methods are automatically onboarded. 
    If a FIDO Passkey was used, all supported methods, including FIDO Passkeys, are onboarded.

Note: The Emergency Access Code (EAC) authentication method appears only when configured by an administrator as needed, even while it is included in the access policy.

Onboarding More Methods

+ button is displayed for users who have at least one method yet to be onboarded. If all methods (QR Code, FIDO Passkey, Mobile Passkey, Authenticate OTP, SecurID OTP, and Device Biometrics) are already onboarded, the button does not appear.

     

    Passwordless Authentication Flows

    This section describes the flows of passwordless authentication for users' first and subsequent authentications.

     

    First Authentication (Onboarding)

    When users sign in or unlock their computers for the first time, the MFA Agent binds the passwordless authentication methods with the computer. The MFA Agent creates a Microsoft Virtual Smart Card and provisions it with a sign-in certificate for the user.

    Before the first passwordless authentication, users' computers must be connected to the network and the prerequisites must be satisfied.

    Procedure

    1. Users enter their Active Directory username in the passwordless credential provider.
    2. Users perform multi-factor authentication using passwordless authentication methods (FIDO Passkey, QR Code (RSA Agent), Device Biometrics (RSA Agent), SecurID OTP, Authenticate OTP, or Mobile Passkey (RSA Agent)).
      If QR Code, Mobile Passkey, SecurID OTP, Authenticate OTP, or Biometrics was used to authenticate, all other non-FIDO supported methods are automatically onboarded.
      If a FIDO Passkey was used, all supported methods, including FIDO Passkeys, are onboarded.
    3. The MFA Agent verifies with CAS and prompts users with additional authentication methods if configured.
    4. After successful authentication, the MFA Agent verifies and binds the passwordless authentication methods with the user's computer.
    5. The MFA Agent creates a Microsoft Virtual Smart Card.
    6. Users enter their Active Directory password in the passwordless credential provider.
    7. The MFA Agent provisions the Microsoft Virtual Smart Card with a sign-in certificate from Active Directory/RSA CA using the users' Active Directory password.
    8. Users gain access to the computer.

    Note: If the Active Directory password is expired, users are prompted to change their password. The old password is prefilled in the Change Password window. 

     

    Subsequent Authentications

    After the first authentication, users do not have to enter passwords because the passwordless authentication method is bound to the computer and the virtual smart card already exists. After the second authentication, users' computers may or may not be connected to the network for the subsequent authentications.

    Procedure

    1. Users perform the same initial steps as in First Authentication to enter the AD username and complete passwordless authentication.
    2. The MFA Agent verifies user credentials and may prompt for additional authentication methods, if required.
    3. During subsequent authentication, the MFA Agent verifies the authentication data, unlocks the local virtual smart card, and obtains the sign-in certificate.
    4. The MFA Agent sends the certificate to Microsoft Windows, which validates it and grants access to the computer.

     

    Configure Hybrid Joined Devices for the RSA MFA Agent

    The procedure to set up Microsoft Entra ID hybrid joined devices remains the same as for on-premises Active Directory joined machines.

    For more information about Microsoft Entra Hybrid Joined Devices, see Microsoft Entra Hybrid Joined Devices.

    Perform the following steps as detailed in this guide:

    1. Create an access policy containing passwordless authentication methods as primary authentication methods.
    2. Obtain the REST Authentication URL and the RSA Authentication API Key.
    3. Download the Agent Passwordless Public Key from CAS.
    4. Obtain the FIDO Relying Party ID from CAS.
    5. Configure the required RSA MFA Agent GPO settings with CAS connection values, certificate settings, and Passkey configurations to enable passwordless authentication for hybrid-joined devices.
      For the complete list of GPO settings, detailed descriptions, and configuration examples, refer to the Configure GPO Settings for Active Directory Passwordless Authentication section in Chapter 5: Enabling RSA MFA Agent on Active Directory and Hybrid Joined Machines in the Installation and Administration Guide.
    6. Create Certificate Templates in Certificate Authority.
    7. Test authentication or onboard/offboard authentication methods using the RSA MFA Agent Authentication Utility.