This guide provides instructions to configure Microsoft Entra ID-joined devices and Microsoft Entra ID hybrid-joined devices for RSA MFA Agent 2.5 or later for Microsoft Windows.
The Agent uses Microsoft Entra ID–trusted RSA Certificate Authority (CA) certificates to provide secure passwordless signin for users on Microsoft Entra ID-joined and hybrid-joined devices. Users must register a FIDO Passkey or RSA Authenticator and use it along with their Entra ID password for the first authentication. Subsequent authentications require only a supported passwordless method.
Supported passwordless methods include FIDO Passkey, QR Code, Mobile Passkey, Device Biometrics, Authenticate OTP, SecurID OTP, and Emergency Access Code.
Passwordless authentication is supported when the Agent connects directly to the Cloud Access Service (CAS), or in hybrid deployments that use Authentication Manager (AM) 8.9 or later. Both passwordless and password + step-up authentication are supported on AD-joined and AD/Entra ID hybrid-joined devices. Hybrid-joined devices follow the same configuration steps as AD-joined devices.
The Agent supports Microsoft Entra ID Commercial from version 2.3.3 onwards and Microsoft Entra ID Government from version 2.3.6 onwards.
This guide contains instructions for the following:
- Configure Microsoft Entra ID Joined Devices for the RSA MFA Agent
- Configure Hybrid Joined Devices for the RSA MFA Agent
Configure Microsoft Entra ID Joined Machines for the RSA MFA Agent
To configure passwordless authentication for users on Entra ID-joined devices, follow the below steps.
- Confirm that Prerequisites are met.
- Register the Agent on Microsoft Entra ID.
- Set Up CAS.
- Configure Microsoft Entra ID.
- Configure the Agent with the RSA MFA Agent Config Utility.
- Test authentication or onboard/offboard authentication methods using the RSA MFA Agent Authentication Utility.
- See Passwordless Authentication Flows for details about the flow of the first and subsequent passwordless authentications.
Prerequisites
- Confirm that the system requirements are met. See the System Requirements section in Chapter 2: Preparing for Installation in the Installation and Administration Guide.
- Install or upgrade the Agent. For fresh installations, refer to Chapter 3: Installing MFA Agent in the Installation and Administration Guide.
If you are upgrading the MFA Agent on Entra ID machines using password only or password + step-up to version 2.4 or later, see Upgrading to Passwordless. - Connect the RSA MFA Agent machine with Microsoft Entra ID by following the instructions given here. You can verify that the device was successfully joined to the Microsoft Entra ID by navigating to Azure Home > Microsoft Entra ID > Overview > Manage > Devices > Total number of devices.
- Create a challenge group under Azure Home > Microsoft Entra ID > Overview > Manage > Groups. Add one or more users to this challenge group.
This group name must also be added as a challenge group name in the configuration text file for the RSA MFA Agent as follows:
ChallengeGroupName=<AD name, e.g. MSEntraID>\<challenge-group-name>
For more information, see RSA MFA Agent Config Utility. - Confirm that the following user requirements are met:
To use passwordless authentication methods, users must register on RSA My Page and enroll one of the following authenticators:
-
- RSA Authenticator app (iOS or Android), which supports Approve, Device Biometrics, QR Code, Authenticate OTP, and Mobile Passkey
- SID700 Hardware Authenticators
- A FIDO2-certified security key, such as the RSA DS100 or RSA IShield 2
Users must register their FIDO2-certified Passkey on RSA My Page and set a PIN for it in order to be able to authenticate using FIDO Passkey.
For more information about supported devices and apps, see CAS User Requirements on RSA Community. -
- Confirm that the following Microsoft Entra ID requirements are met:
-
- Make sure all the users who you intend to challenge with passwordless authentication are part of an Entra ID Group, (e.g., CBAGroup) and are synchronized to CAS through SCIM.
- Make sure a proper Global Administrator Role is present in Entra ID, and login as a Privilege Authentication Administrator.
- Entra ID-supported MDM, such as Intune, must be configured.
Upgrading to Passwordless
The below upgrade instructions are applicable when upgrading from Entra ID joined machines that are using password only or password + step-up authentication to version 2.4 or later.
- Install the RSA Root CA Certificate. For instructions, see Step 8 under Set Up CAS.
- Upgrade RSA MFA Agent to the latest version.
- Implement passwordless configuration as detailed in this guide.
Register the Agent on Entra ID
Microsoft Entra ID app registration is the process of registering the RSA MFA Agent with Microsoft Entra ID to obtain the necessary credentials to securely access Azure services and APIs. This registration provides the MFA Agent with the necessary permissions to interact with Azure services, making the MFA Agent and services more secure and accessible.
To register an application on the Azure Tenant, perform the following steps.
Procedure
- To register a new application in Microsoft Entra ID, go to Azure Home > Microsoft Entra ID > Overview > Manage > App registrations, and then click New registration. Fill in the required fields. Under Supported account types, choose the application access type based on your account type.
- Note down the parameters such as Tenant ID and Client ID for the application.
- Generate a Client Secret for this application. From the left-side pane, click Manage > Certificates & secrets. Click New client secret. You will be prompted to add the client secret with a description and certificate expiry days. After providing the required data, the client secret will be generated and displayed under Client Secret in the Value column. Client Secret values cannot be viewed except immediately after creation. Be sure to save the secret when created before leaving the page. These values can also be securely stored in Azure Key Vault.
- Go to Manage > API permissions, and click Add a permission.
- Select Microsoft APIs > Microsoft Graph > Application permissions, and assign the minimum permissions User.ReadBasic.All and GroupMember.Read.All to the application
Set Up CAS
- Create an access policy containing passwordless authentication methods as primary authentication methods. Do the following:
- In the Cloud Administration Console, go to Access > Policies.
- Create a new policy or edit an existing one. For instructions, see Add an Access Policy in Add, Clone, or Delete an Access Policy on RSA Community.
- In the Primary Authentication tab, add at least one of the supported primary authentication methods:
- FIDO Passkey
- QR Code (RSA Agent)
- Device Biometrics (RSA Agent)
- Mobile Passkey (RSA Agent)
- Authenticate OTP
- SecurID OTP
- Emergency Access Code - Click Save and Finish.
- Publish your changes.
- If you want to use conditional authentication based on location or IP address, create trusted locations and trusted networks and configure the access policy to use them. For more information, see Create a Network Zone in Manage Networks and Add a Trusted Location in Add or Delete a Trusted Location on RSA Community.
- Obtain the REST protocol RSA Authentication API Key for the Cloud Access Service. The Agent sends this key to the RSA Authentication API to securely identify authentication requests. For instructions, see Add an RSA Authentication API Key in Manage the RSA Authentication API Keys on RSA Community.
- Obtain the REST Authentication URL for Cloud Access Service. The REST Authentication URL uses the following format:
https://<hostname>:<port>/
To obtain the <hostname>, in the Cloud Administration Console, go to Platform > API Access Management > Authentication API Keys. - Perform the following steps to download the Agent Passwordless Public Key from CAS:
-
- In the Cloud Administration Console, go to My Account > Company Settings.
- Navigate to Company Information.
- Under Agent Passwordless Public Key, click Download.
- Perform the following steps to obtain the FIDO Relying Party ID from CAS:
-
- In the Cloud Administration Console, go to Platform > Identity Router.
- Select an identity router and click Edit.
- Click Registration.
- Get the FIDO Relying Party ID from the value in the Authentication Service Domain field.
- If not configured, the FIDO Relying Party ID will be extracted from the RSA Authentication API REST URL.
If you want users to avoid additional authentication after a successful FIDO Passkey primary authentication, ensure that FIDO Passkey is configured as the Higher assurance level authentication method in the access policy compared to other methods.
- Configure the OAuth Client. Perform the following steps:
-
- In the Cloud Administration Console, go to Platform > API Access Management.
- Click Add API Client.
- Enter the required details in the Basic Information tab.
- Navigate to the Authentication tab. From the Client Authentication drop-down menu, select CLIENT_SECRET_BASIC.
- In the Client Secret field, RSA recommends using the Generate Secret button. If you will paste your own secret key, make sure that the secret does not exceed 256 alphanumeric characters and has no line breaks.
- In the Permissions tab, select the checkboxes for Agent and rsa.agent.cert.
- Click Save and Finish, and publish your changes.
- Download the Root CA Certificate. Perform the following steps:
-
- In the Cloud Administration Console, go to My Account > Company Settings.
- Navigate to the Agent CA Services tab.
- Under CA Certificate, click Download Certificate.
- Copy and save the CRL Distribution Point URL.
Configure Microsoft Entra ID
Follow the below steps to configure Entra ID for passwordless authentication.
- Create a PKI container object. Perform the following steps:
-
- Sign in to the Microsoft Entra ID admin center as a Privilege Authentication Administrator and navigate to Entra ID > Security > Public key infrastructure (Preview).
- Click + Create PKI, then enter a Display Name.
- Click Create, then click Refresh to refresh the list of PKIs.
- Upload the RSA Root CA into the PKI container object. Perform the following steps:
- Click on + Add certificate authority.
-
In the Add certificate authority dialog box, do the following:
-
- Select the RSA CA file obtained from CAS.
- Select Yes under Is this certificate authority the root?
- In the Certificate Revocation List URL field, paste the CRL URL obtained from CAS in Step 8 under Set Up CAS.
Note: The Delta Certificate Revocation List URL can be blank, and the Issuer hints flag is enabled by default. - Click Save.
- Verify the thumbprint and CRL URL of the Root CA to confirm that the correct CA is uploaded.
- Click on + Add certificate authority.
- Enable certificate-based authentication. Perform the following:
- In the Microsoft Entra ID admin center, navigate to Entra ID > Security > Authentication Methods > Policies.
- Select Certificate-based Authentication.
- Under Enable and Target, click Enable.
- Under Include, select Select groups and target specific groups (recommended). RSA also recommends providing a user group name that includes all the intended users that are synced to CAS.
- Click Save.
- Configure Authentication Binding. Perform the following steps:
-
-
Navigate to Security > Authentication Methods > Policies > Certificate-based Authentication, and switch to the Configure tab.
- Under Authentication Binding, do the following:
- Set the Default authentication strength to Multi-factor (default, recommended).
- Set the Required Affinity Binding to Low (default) or High.
- Click Add Rule.
- In the Add authentication binding policy rule dialog box, select the Certificate Issuer checkbox.
- From the Filter CAs by PKI drop-down menu, select the PKI you created.
- From the Certificate Issuer drop-down menu, select the Root CA you uploaded.
- Under Authentication Strength, select Single-factor authentication.
- Under Affinity Binding, select Low.
- Click Add.
- In the Certificate-based authentication settings tab, scroll to the Username Binding section.
- Map certificate fields (e.g., Subject CN, SAN UPN) to Entra ID user attributes (e.g., userPrincipalName). Do the following:
-
-
-
- Click Add Rule.
- From the Certificate field drop-down menu, select PrincipalName.
- From the User attribute drop-down menu, select userPrincipalName.
- Click Add.
- Affinity binding is set to Low by default.
- Verify your changes and click Acknowledgment, then click Save.
-
Configure the Agent with the RSA MFA Agent Config Utility
For Microsoft Entra ID joined devices, Agent settings can be configured using the file generated below. Agent configuration settings for Microsoft Entra ID joined devices are not set through GPO settings.
Follow the below steps to configure the Agent using the RSA MFA Agent Config Utility.
Generate and Configure the Template File
- Open the command prompt as an administrator.
- Run the following command to generate a template text file:
$ RSA_MFA_Agent_Config_Utility_For_Microsoft_Entra_ID.exe -g <text file name e.g. RSA_MFA_Agent_Config.txt>
This command creates a template text file <text file name> which contains the key-value pairs needed for the RSA MFA Agent. - Update the key-value pairs in the generated configuration file. Enable or disable the keys by setting the flag to 0 or 1, and enter the required values after KeyValue=.
The values of the following keys need to be configured in order to enable passwordless authentication:
- Azure Tenant ID, Azure Client ID, Azure Client Secret, Azure Cloud Region
- RSA Authentication API Key, RSA Authentication API REST URL
- Cloud Access Service Access Policy
- Cloud Access Service Public Key for Passwordless Authentication
- RSA Authentication OAuth2 Client ID, RSA Authentication OAuth2 Client Secret
- FIDO Relying Party ID
- Enable RSA authentication
- Configure Passwordless Authentication
- Specify logging options
- RSA Primary Authentication Challenge Group, RSA Primary Authentication Challenge Settings
For more information about each key-value pair, see Configure Passwordless Authentication for Microsoft Entra ID Joined Machines in the Installation and Administration Guide.
Generate PowerShell Script
Use the configured text file to create a PowerShell script with the following command:
$ RSA_MFA_Agent_Config_Utility_For_Microsoft_Entra_ID.exe -i <text file name e.g. RSA_MFA_Agent_Config.txt> -o <script file name e.g. RSA_MFA_Agent_Config.ps1>
This command generates a PowerShell script file with the name given in the command, which will configure the Windows machine for the RSA MFA Agent.
Upload the Script to MDM and Deploy It
- Log in to an MDM portal.
- Upload the generated PowerShell script.
- Select the appropriate device group under Included groups during the upload process.
The MDM will deploy and execute the PowerShell script on all devices in the selected groups to configure them for the Agent.
Install Root CA Certificate
Install the Root CA Certificate on the machines. Download the certificate as detailed in in Step 8 under Set Up CAS. Use an MDM tool to install this Root CA Certificate to the computer's Trusted Root Certificate Authority.
Install the Agent
After completing the above configuration steps, install the RSA MFA Agent 2.5 on Microsoft Windows 10 or later.
To install the RSA MFA Agent for a group of Entra ID users, use any MDM to push the Agent. See Install the Agent for Entra ID Users Using Intune in the Installation and Administration Guide for steps you can follow to install and configure the Agent using Microsoft Intune. The instructions provided are only applicable for fresh Agent installations on devices not previously enrolled.
RSA MFA Agent Authentication Utility
You can use the RSA MFA Agent Authentication Utility to test online and offline passwordless authentication. You can also use this utility to enable passwordless authentication. The Authentication Utility is automatically installed when you install the MFA Agent. You can ask your users to test authentication using this utility and share these instructions with them.
Procedure
- Sign in to a computer where the MFA Agent is installed.
- Click Start > RSA > RSA MFA Agent Authentication Utility.
The Test Authentication tab opens by default. - Enter the name of the user for whom you are testing authentication.
Enter a simple name (for example, myuser) or an email address (for example, myuser@mydomain.com). This name is displayed for users and cannot be edited. - If you entered a simple user name, specify the domain (for example, mydomain).
Note: Passwordless authentication cannot be enabled for local user accounts. - Click Test Online Authentication.
- Perform authentication using a supported passwordless method, such as FIDO Passkey, QR Code, Device Biometrics, Authenticate OTP, SecurID OTP, or Mobile Passkey.
The MFA Agent verifies your credentials with CAS and prompts for additional authentication if required.
If passwordless authentication is successfully enabled, a confirmation message appears. - Wait 60 seconds after successful online authentication, and then click Test Offline Authentication.
Authenticate again using a supported method.
If offline passwordless authentication is successful, a confirmation message appears.
If authentication is successful, you can sign in to your computer without entering a password. For more information, see Passwordless Authentication Flows.
Passwordless Onboarding
The Passwordless Onboarding functionality enables users to onboard supported passwordless authentication methods so they can sign in using those methods.
First-Time Launch (No Onboarded Methods)
If the user has no onboarded methods, the following procedure applies:
- Click Passwordless Authentication Onboarding.
The user is prompted to authenticate using the default method configured in the CAS access policy. Other supported passwordless authentication methods (also as configured in the access policy) are displayed under the More ways to sign in menu. - Perform the authentication. A success message appears.
If QR Code, Mobile Passkey, SecurID OTP, Authenticate OTP, or Biometrics was used to authenticate, all other non-FIDO supported methods are automatically onboarded.
If a FIDO Passkey was used, all supported methods, including FIDO Passkeys, are onboarded.
Note: The Emergency Access Code (EAC) authentication method appears only when configured by an administrator as needed, even while it is included in the access policy.
Onboarding More Methods
A + button is displayed for users who have at least one method yet to be onboarded. If all methods (QR Code, FIDO Passkey, Mobile Passkey, Authenticate OTP, SecurID OTP, and Device Biometrics) are already onboarded, the + button does not appear.
Passwordless Authentication Flows
This section describes the flows of passwordless authentication for users' first and subsequent authentications.
First Authentication
When users sign in or unlock their computers for the first time, the MFA Agent binds the passwordless authentication methods with the user's computer. The MFA Agent creates a Microsoft Virtual Smart Card and provisions it with a sign-in certificate for the user. Before the first passwordless authentication, users' computers must be connected to the network and the prerequisites must be satisfied.
Procedure
- Users enter their Entra ID username in the passwordless credential provider.
- Users perform multi-factor authentication using passwordless authentication methods (FIDO Passkey, QR Code (RSA Agent), Device Biometrics (RSA Agent), SecurID OTP, Authenticate OTP, or Mobile Passkey (RSA Agent)).
If QR Code, Mobile Passkey, SecurID OTP, Authenticate OTP, or Biometrics was used to authenticate, all other non-FIDO supported methods are automatically onboarded.
If a FIDO Passkey was used, all supported methods, including FIDO Passkeys, are onboarded. - The MFA Agent verifies with CAS and prompts users with additional authentication methods if configured.
- After successful authentication, the MFA Agent verifies and binds the passwordless authentication methods with the user's computer.
- The MFA Agent creates a Microsoft Virtual Smart Card.
- Users enter their Entra ID password in the passwordless credential provider.
- The MFA Agent provisions the Microsoft Virtual Smart Card with a sign-in certificate from RSA CA using the users' Entra ID password.
- Users gain access to the computer.
Note: If the Entra ID password is expired, users are prompted to change their password.
Subsequent Authentications
After the first authentication, users do not have to enter passwords because the passwordless authentication method is bound to the computer and the virtual smart card already exists. After the second authentication, users' computers may or may not be connected to the network for the subsequent authentications.
Procedure
- Users perform the same initial steps as in First Authentication to enter their Entra ID username and complete passwordless authentication.
- The MFA Agent verifies user credentials and may prompt for additional authentication methods, if required.
- During subsequent authentication, the MFA Agent verifies the authentication data, unlocks the local virtual smart card, and obtains the sign-in certificate.
- The MFA Agent sends the certificate to Microsoft Windows, which validates it and grants access to the computer.
Configure Hybrid Joined Devices for the RSA MFA Agent
The procedure to set up Microsoft Entra ID hybrid joined devices remains the same as for on-premises Active Directory joined machines.
For more information about Microsoft Entra Hybrid Joined Devices, see Microsoft Entra Hybrid Joined Devices.
Follow the below steps. For more details, see the Passwordless Authentication in Windows MFA Agent for Active Directory Quick Setup Guide.
- Create an access policy containing passwordless authentication methods as primary authentication methods.
- Obtain the REST Authentication URL and the RSA Authentication API Key.
- Download the Agent Passwordless Public Key from CAS.
- Obtain the FIDO Relying Party ID from CAS.
- Configure the required RSA MFA Agent GPO settings with CAS connection values, certificate settings, and Passkey configurations to enable passwordless authentication for hybrid-joined devices.
For the complete list of GPO settings, detailed descriptions, and configuration examples, refer to the Configure GPO Settings for Active Directory Passwordless Authentication section in Chapter 5: Enabling RSA MFA Agent on Active Directory and Hybrid Joined Machines in the Installation and Administration Guide. - Create Certificate Templates in Certificate Authority.
- Test authentication or onboard/offboard authentication methods using the RSA MFA Agent Authentication Utility.
Related Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory 980Number of Views Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 675Number of Views Microsoft Entra ID External MFA - RSA Ready Implementation Guide 638Number of Views RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide 1.89KNumber of Views Troubleshooting RSA MFA Agent for Microsoft Windows 4.42KNumber of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Authenticator 4.6 for iOS and Android Quick Start Guides RSA Authentication Manager Upgrade Process AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' RSA Authenticator 6.2.2 for Windows Administrator Guide