Passwordless authentication
While reading the previous section, you might have thought, what about passwordless sign-in authentication? Good point!
Microsoft aims to make setting passwords easier; their strategy is a four-step approach where we deploy replacement offerings, reduce the password surface area, transition to passwordless deployment, and, finally, eliminate passwords.
Figure 13.33: Passwordless phases
Passwordless authentication is a way to log on to your Windows Enterprise endpoint without entering your password. One of the most common approaches to do this is via a so-called YubiKey security key. You have them for USB-C, USB, and other devices, such as an Apple device. Other options are to use text messages or the Microsoft Authenticator app.
Figure 13.34: YubiKey
Let’s talk about the YubiKey. The end user experience looks very similar to how you normally log on to Windows. While you normally log on with either Windows Hello or your...