Floor and warehouse workers vs EntraID ?

Posted by povlhp@reddit | sysadmin | View on Reddit | 39 comments

What are people using for floor and warehouse workers when it comes to EntraID signin ?

Microsoft is offering QR codes (limited lifetime) with a PIN, but there is some logistics aound this. Employees already have a small NFC chip for opening doors etc (Not sure if MIFARE) - But Microsoft does not seem to support NFC except for FIDO.

Employees are using custom apps on Android, and other stuff as well. Thin clients with a remote desktop (usually shared user, and sign-in to individual apps). But main need for MFA is for EntraID SSPR.

What are other companies doing ? We can't demand employees use their own device for anything.

What options are there for cheap NFC capable FIDO2 keys ? We might need 50k devices over time, but likely would want to run a smaller test.

We already use Yubikey FIDO2 for high-priv admins - but they are too expensive for tens of thousand employees. And will be an extra somewhat bulky device on top of

I still see cheap TOTP hardware tokens as an option as well, if cheap enough. But that is not passwordless, but will at least give them a MFA for password reset. Users have very limited access, and only from internal IPs. Our main challenge is that they are now all cloud identities.