How EZCMS helps you onboard to phishing-resistant methods
Deciding to go fully passwordless in Entra ID means using methods that do not rely on traditional passwords: certificate based authentication, hardware security keys, and mobile device authentication. Here is how each one works and how users get onboarded.
Choose a method
There are three passwordless methods in Entra ID. Each has its advantages and disadvantages, and most organizations implement two or even all three.
Entra ID Certificate Based Authentication (Entra CBA)
Entra CBA uses X.509 certificates to authenticate users. Those certificates can live in the Windows certificate store, on a smartcard, or on a YubiKey.
-
The oldest phishing-resistant method, used by governments around the world for decades
-
The most compatible option, precisely because of that long track record
-
Now fully cloud-based with Entra CBA and EZCMS, without the large server footprint onboarding used to need
FIDO2 Passkeys
FIDO2 is an industry standard developed by the FIDO Alliance to make passwordless authentication easier. It uses the same cryptographic algorithms as certificate based authentication.
-
The public key is registered with the identity provider instead of a certificate carrying the user's information
-
The same cryptographic security as certificate based authentication
-
None of the complex infrastructure smartcard deployments traditionally required
Passwordless phone authentication
The Microsoft Authenticator app is the third passwordless method Entra ID supports, and the one that needs no hardware to distribute.
-
No hardware to order or ship, since the credential lives on a phone the user already carries
-
Often paired with a hardware method for users who cannot use a phone at work
-
One of three methods most organizations combine on the way to being fully passwordless
Deploy EZCMS passwordless onboarding
Request a hardware key
A user requests a key from the EZCMS portal. Ordering and distribution logistics are handled for you, so the key ships to wherever that user actually is.
Watch the walkthroughAssign a YubiKey or smartcard
An administrator assigns the physical credential to the user, linking it to their Entra ID identity so it can be activated.
Enable remote onboarding
Remote users prove who they are and activate their own credential without visiting an office. On Premium that check can use Government ID plus Face ID verification.
Watch the walkthroughRecover a blocked key
If a user locks themselves out of their YubiKey, EZCMS can recover it rather than issuing a replacement device.
Secure your organization by going passwordless
Talk to one of our identity experts about the fastest way to get your workforce onto unphishable credentials.
Transparent pricing
View pricing detailsBasic
Self-service and IT desk onboarding for smartcards and FIDO2 keys
Premium
Most popular ✦Adds identity-proofed onboarding, bring your own CA, and SIEM export
Enterprise
Isolated infrastructure, on-premises deployment, and custom UI
Frequently asked questions
Entra CBA uses X.509 certificates to authenticate users. Those certificates can live in the Windows certificate store, on a smartcard, or on a YubiKey. It is the oldest phishing-resistant method and has been used by governments for decades, which makes it the most compatible option. Entra CBA and EZCMS now let you do it fully in the cloud, without the server footprint it used to require.
FIDO2 is an industry standard developed by the FIDO Alliance to make passwordless authentication easier. It uses the same cryptographic algorithms as certificate based authentication, but instead of a certificate carrying the user's information, the public key is registered with the identity provider. You get the cryptographic security of certificate based authentication without the complex infrastructure smartcards used to need.
Passwordless phone authentication with the Microsoft Authenticator app is the third method Entra ID supports. Each of the three methods has its own advantages and disadvantages, and most organizations implement two or even all three to get their whole workforce onto phishing-resistant credentials.
Once EZCMS is deployed in Azure with self-onboarding enabled, a user requests a hardware key from the EZCMS portal. EZCMS handles the ordering and distribution logistics, so the key ships to the user wherever they are.
An administrator assigns the key to the user in EZCMS, which links that physical credential to their Entra ID identity. From there the user can activate it themselves rather than going through the IT help desk.
Yes. Remote YubiKey and smartcard onboarding lets a user prove who they are and activate their credential without visiting an office. On Premium that identity check can use Government ID plus Face ID verification.
EZCMS supports recovering a blocked YubiKey, so a user who locks themselves out of their key can get back to a working credential instead of being issued a new device.