To enable security keys as a sign-in option for Windows 10 devices, the system administrator has to use Microsoft Intune. There are two options:

(1) for all users - a tenant wide Windows Hello for Business setting for all users

(2) for a group of users - an Identity Protection configuration policy for a group of users

Option 1: Tenant wide for all Users

Open a browser and sign-in to the Microsoft Intune portal.

 

Option 2:  Identity Protection configuration policy

The advantage of using a configuration policy is that you can assign it to a group of users instead of all users.

A new policy Enable FIDO2 for Signin has been successfully created. The next step is to assign the policy to the security group of choice

Enable combined security information registration

The second step is to enable combined security information registration. The feature needs to be enabled from the Azure (AD) Portal.


Enable FIDO2 security keys as Authentication method

The third step is to enable FIDO2 security keys as Authentication method in Azure Active Directory.