Password-less authentication
While reading the previous section, you might have thought, what about password-less sign-in authentication? Good point!
Microsoft aims to make setting passwords easier; our strategy is a four-step approach where we deploy replacement offerings, reduce the password surface area, transition to password-less deployment, and finally, eliminate passwords.
Figure 13.30 – Password-less phases
Password-less authentication is a way to log on to your Windows 10 Enterprise endpoint without entering your password. One of the most common approaches to do this is via a so-called YubiKey security key. You have them for USB-C, USB, and other devices, such as an Apple device. Other options are to use text messages or the Microsoft Authenticator app.
Figure 13.31 – YubiKey
Let's talk about the YubiKey. The end user experience looks very similar to how you normally log on to Windows. While you are...