How EZCMS helps you onboard to phishing-resistant methods

Deciding to go fully passwordless in Entra ID means using methods that do not rely on traditional passwords: certificate based authentication, hardware security keys, and mobile device authentication. Here is how each one works and how users get onboarded.

Choose a method

There are three passwordless methods in Entra ID. Each has its advantages and disadvantages, and most organizations implement two or even all three.

Entra ID Certificate Based Authentication (Entra CBA)

Entra CBA uses X.509 certificates to authenticate users. Those certificates can live in the Windows certificate store, on a smartcard, or on a YubiKey.

  • The oldest phishing-resistant method, used by governments around the world for decades

  • The most compatible option, precisely because of that long track record

  • Now fully cloud-based with Entra CBA and EZCMS, without the large server footprint onboarding used to need

FIDO2 Passkeys

FIDO2 is an industry standard developed by the FIDO Alliance to make passwordless authentication easier. It uses the same cryptographic algorithms as certificate based authentication.

  • The public key is registered with the identity provider instead of a certificate carrying the user's information

  • The same cryptographic security as certificate based authentication

  • None of the complex infrastructure smartcard deployments traditionally required

Passwordless phone authentication

The Microsoft Authenticator app is the third passwordless method Entra ID supports, and the one that needs no hardware to distribute.

  • No hardware to order or ship, since the credential lives on a phone the user already carries

  • Often paired with a hardware method for users who cannot use a phone at work

  • One of three methods most organizations combine on the way to being fully passwordless

Deploy EZCMS passwordless onboarding

01

Request a hardware key

A user requests a key from the EZCMS portal. Ordering and distribution logistics are handled for you, so the key ships to wherever that user actually is.

Watch the walkthrough
02

Assign a YubiKey or smartcard

An administrator assigns the physical credential to the user, linking it to their Entra ID identity so it can be activated.

03

Enable remote onboarding

Remote users prove who they are and activate their own credential without visiting an office. On Premium that check can use Government ID plus Face ID verification.

Watch the walkthrough
04

Recover a blocked key

If a user locks themselves out of their YubiKey, EZCMS can recover it rather than issuing a replacement device.

Secure your organization by going passwordless

Talk to one of our identity experts about the fastest way to get your workforce onto unphishable credentials.

Transparent pricing

View pricing details

Basic

Self-service and IT desk onboarding for smartcards and FIDO2 keys

$1 / user / month

Enterprise

Isolated infrastructure, on-premises deployment, and custom UI

Custom / user / month

Frequently asked questions

Entra CBA uses X.509 certificates to authenticate users. Those certificates can live in the Windows certificate store, on a smartcard, or on a YubiKey. It is the oldest phishing-resistant method and has been used by governments for decades, which makes it the most compatible option. Entra CBA and EZCMS now let you do it fully in the cloud, without the server footprint it used to require.

FIDO2 is an industry standard developed by the FIDO Alliance to make passwordless authentication easier. It uses the same cryptographic algorithms as certificate based authentication, but instead of a certificate carrying the user's information, the public key is registered with the identity provider. You get the cryptographic security of certificate based authentication without the complex infrastructure smartcards used to need.

Passwordless phone authentication with the Microsoft Authenticator app is the third method Entra ID supports. Each of the three methods has its own advantages and disadvantages, and most organizations implement two or even all three to get their whole workforce onto phishing-resistant credentials.

Once EZCMS is deployed in Azure with self-onboarding enabled, a user requests a hardware key from the EZCMS portal. EZCMS handles the ordering and distribution logistics, so the key ships to the user wherever they are.

An administrator assigns the key to the user in EZCMS, which links that physical credential to their Entra ID identity. From there the user can activate it themselves rather than going through the IT help desk.

Yes. Remote YubiKey and smartcard onboarding lets a user prove who they are and activate their credential without visiting an office. On Premium that identity check can use Government ID plus Face ID verification.

EZCMS supports recovering a blocked YubiKey, so a user who locks themselves out of their key can get back to a working credential instead of being issued a new device.