
:max_bytes(150000):strip_icc()/MSauthenticatorAppSetup1-fab3f7575abb4646b86a938ecfbc775d.jpg)
A device can only be registered in one Azure AD at a time, so this feature is effectively limited to one account.Īfter the successful setup, this type of sign-in can be used on any supported device. This requirement is at the same time a problem for people with many accounts in multiple tenants. In the authenticator app, the account must be selected and the registration started via “Set up phone sign-in”.įor the verification, you have to sign-in again with the TAP and then register the phone with the Azure AD. It is therefore a good idea to perform this setup directly during onboarding.

So far, we have only used FIDO2 security keys and Windows Hello for Business for sign-in. PowerShell administration without a password.Windows 10 device onboarding and Windows Hello for Business.
