Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»macOS»Passwordless sign in to Office 365 on macOS
    macOS

    Passwordless sign in to Office 365 on macOS

    Peter KlapwijkBy Peter KlapwijkJuly 9, 2021Updated:July 9, 202113 Mins Read

    I have written some articles in the past related to the passwordless sign-in subject, but that usually described to experience on Windows devices. I described how to use FIDO2 security keys to sign in to Windows itself or use the key to sign in to Office 365/ Azure AD.
    On macOS, we are not able to sign in to the Mac itself by using a FIDO2 key, but by using the Microsoft Edge browser, we’re at least able to use a FIDO2 key to passwordless sign-in to Office 365! With Safari, this is unfortunately still not possible.

    The only challenge left for a Mac-only user is how to manage the key. On Windows, we have built-in support to manage a key. We can add or change a PIN via Windows settings, and also reset the key. That support isn’t available in macOS by default. To overcome this limitation for Mac users, one of the FIDO2 vendors, Feitian, published an application to manage their keys. I haven’t seen such an application yet from another vendor, but let me know in the comments if other vendors do have such an app for macOS.

    Let’s have a look in this article, how easy it is to set up our Feitian FIDO2 key to passwordless sign in to our Office 365 account.

    To use a FIDO2 security key with your Office 365 account, some setup needs to be done in Azure AD. I described these steps in this blog post.

    Setup the FIDO2 key

    I have a Feitian K26 USB C FIDO2 (Bio) key which I want to manage on my MacBook. For this, we can search in the App Store for Feitian and download the app BioPassFIDO2.

    Once installed, open the app and insert the key in the Mac.
    As this is a bio version, I can add multiple fingerprints to the key, so I don’t have to enter a PIN every time I use the key.
    But every FIDO2 key needs to be set up with a PIN, also the bio versions.

    To set up the key, open the app and insert the key into the Mac. Choose Add fingerprint and provide a new PIN code.
    Once the PIN is set, touch the key a few times with your finger until the app shows it’s all set.
    Optionally you can register multiple fingerprints.

    Below is a video of this process.

    Key registration in Office 365

    To use the key with Office 365, it first needs to be registered in our Azure AD account. Follow the below steps, to register the key. The registration process is equal to the process on a Windows device.

    • Sign in to https://mysignins.microsoft.com/security-info
    • Click Add method
    • Select Security key from the drop-down list
    • Click Add
    • Choose USB
    • Click Next
    • Wait for the redirection
    • Insert the key
    • Touch the key
    • Click Allow
    • Name the key
    • Click Next
    • You’r ready to go!

    Registration of the key is successful. We’re ready to sign in with our password to Office 365!

    Passwordless sign in experience

    This is the sign-in experience to Office 365 with a FIDO2 security key.

    That’s it for this post.

    Thanks for reading!

    Azure AD Browser Edge EMS Feitian FIDO2 Identity Management Intune macOS MEM Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Passwordless Security
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Add Security key option is missing from the Security info page

    November 20, 2020

    Manage Microsoft Edge Chromium extensions with Microsoft Intune

    February 18, 2020

    Welcome to my blog!

    September 10, 2016
    View 1 Comment

    1 Comment

    1. Walter Markus on July 10, 2021 08:23

      Hi Peter, nice article! I use the key from Yubico, there is also an macOS app to manage the key.

      Reply
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Create deployment ring groups for Microsoft Intune

    June 27, 2025

    Update Windows Defender during Windows Autopilot enrollments

    May 16, 2025

    Hide the “Turn on an ad privacy feature” pop-up in Chrome with Microsoft Intune

    April 19, 2025

    How to set Google as default search provider with Microsoft Intune

    April 18, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    • Bluesky 1.5K
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Teams Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Parth Savjadiya on Using Visual Studio with Microsoft Endpoint Privilege Management, some notes
    • Chris Johnson on Assign Deny Local Log On user right to an (Azure) AD group by using Microsoft Intune
    • Northernsky on Automatically wipe a Windows 10 device after a number of authentication failures
    • Henrik on Intune Driver update for Windows – Get applicable devices
    • Adam on Get notified on expiring Azure App Registration client secrets
    most popular

    Application installation issues; Download pending

    October 1, 2024

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How to change the Windows 11 language with Intune

    November 11, 2022

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS Bluesky
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}