diff --git a/includes/configure/tab-intro.md b/includes/configure/tab-intro.md index c9c293a8c5..31046b2203 100644 --- a/includes/configure/tab-intro.md +++ b/includes/configure/tab-intro.md @@ -1,9 +1,9 @@ --- author: paolomatarazzo ms.author: paoloma -ms.date: 08/15/2023 +ms.date: 08/20/2024 ms.topic: include ms.service: windows-client --- -The following instructions provide details how to configure your devices. Select the option that best suits your needs. \ No newline at end of file +The following instructions provide details about how to configure your devices. Select the option that best suits your needs. \ No newline at end of file diff --git a/windows/security/docfx.json b/windows/security/docfx.json index d7c7571c0e..1a7808e2b1 100644 --- a/windows/security/docfx.json +++ b/windows/security/docfx.json @@ -54,6 +54,7 @@ } }, "contributors_to_exclude": [ + "aditisrivastava07", "alekyaj", "alexbuckgit", "American-Dipper", @@ -64,17 +65,14 @@ "dstrome2", "garycentric", "jborsecnik", + "padmagit77", "rjagiewich", "rmca14", "shdyas", "Stacyrch140", "tiburd", "traya1", - "v-dihans", - "v-stchambers", - "v-stsavell", - "padmagit77", - "aditisrivastava07" + "v-stsavell" ], "searchScope": [ "Windows 10" diff --git a/windows/security/identity-protection/credential-guard/configure.md b/windows/security/identity-protection/credential-guard/configure.md index fee6dbbc20..b965f14e38 100644 --- a/windows/security/identity-protection/credential-guard/configure.md +++ b/windows/security/identity-protection/credential-guard/configure.md @@ -404,4 +404,4 @@ bcdedit /set vsmlaunchtype off [CSP-1]: /windows/client-management/mdm/policy-csp-deviceguard#enablevirtualizationbasedsecurity -[INT-1]: /mem/intune/configuration/settings-catalog +[INT-1]: /mem/intune/configuration/custom-settings-configure diff --git a/windows/security/identity-protection/passkeys/index.md b/windows/security/identity-protection/passkeys/index.md index 44f695a852..be6abe05f7 100644 --- a/windows/security/identity-protection/passkeys/index.md +++ b/windows/security/identity-protection/passkeys/index.md @@ -1,11 +1,11 @@ --- title: Support for passkeys in Windows description: Learn about passkeys and how to use them on Windows devices. -ms.collection: +ms.collection: - tier1 ms.topic: overview ms.date: 11/07/2023 -appliesto: +appliesto: - ✅ Windows 11 - ✅ Windows 10 --- @@ -31,7 +31,7 @@ FIDO protocols prioritize user privacy, as they're designed to prevent online se ### Passkeys compared to passwords -Passkeys have several advantages over passwords, including their ease of use and intuitive nature. Unlike passwords, passkeys are easy to create, don't need to be remembered, and don't need to be safeguarded. Additionally, passkeys are unique to each website or application, preventing their reuse. They're highly secure because they're only stored on the user's devices, with the service only storing public keys. Passkeys are designed to prevent attackers to guess or obtain them, which helps to make them resistant to phishing attempts where the attacker may try to trick the user into revealing the private key. Passkeys are enforced by the browsers or operating systems to only be used for the appropriate service, rather than relying on human verification. Finally, passkeys provide cross-device and cross-platform authentication, meaning that a passkey from one device can be used to sign in on another device. +Passkeys have several advantages over passwords, including their ease of use and intuitive nature. Unlike passwords, passkeys are easy to create, don't need to be remembered, and don't need to be safeguarded. Additionally, passkeys are unique to each website or application, preventing their reuse. They're highly secure because they're only stored on the user's devices, with the service only storing public keys. Passkeys are designed to prevent attackers to guess or obtain them, which helps to make them resistant to phishing attempts where the attacker might try to trick the user into revealing the private key. Passkeys are enforced by the browsers or operating systems to only be used for the appropriate service, rather than relying on human verification. Finally, passkeys provide cross-device and cross-platform authentication, meaning that a passkey from one device can be used to sign in on another device. [!INCLUDE [passkey](../../../../includes/licensing/passkeys.md)] @@ -113,7 +113,7 @@ Pick one of the following options to learn how to save a passkey, based on where :::row::: :::column span="4"::: - 4. Select your linked device name (e.g. **Pixel**) > **Next** + 4. Select your linked device name (for example, **Pixel**) > **Next** :::column-end::: :::row-end::: :::row::: @@ -241,7 +241,7 @@ Pick one of the following options to learn how to use a passkey, based on where :::row::: :::column span="4"::: - 4. Select your linked device name (e.g. **Pixel**) > **Next** + 4. Select your linked device name (for example, **Pixel**) > **Next** :::column-end::: :::row-end::: :::row::: @@ -311,12 +311,86 @@ Starting in Windows 11, version 22H2 with [KB5030310][KB-1], you can use the Set > [!NOTE] > Some passkeys for *login.microsoft.com* can't be deleted, as they're used with Microsoft Entra ID and/or Microsoft Account for signing in to the device and Microsoft services. +## Passkeys in Bluetooth-restricted environments + +For passkey cross-device authentication scenarios, both the Windows device and the mobile device must have Bluetooth enabled and connected to the Internet. This allows the user to authorize another device securely over Bluetooth without transferring or copying the passkey itself. + +Some organizations restrict Bluetooth usage, which includes the use of passkeys. In such cases, organizations can allow passkeys by permitting Bluetooth pairing exclusively with passkey-enabled FIDO2 authenticators. + +To limit the use of Bluetooth to only passkey use cases, use the [Bluetooth Policy CSP][CSP-8] and the [DeviceInstallation Policy CSP][CSP-7]. + +### Device configuration + +[!INCLUDE [tab-intro](../../../../includes/configure/tab-intro.md)] + +#### [:::image type="icon" source="../../images/icons/intune.svg" border="false"::: **Intune/CSP**](#tab/intune) + +To configure devices with Microsoft Intune, [you can use a custom policy][INT-2] with these settings: + +| Setting | +|--| +|