Hardware OATH Tokens for Azure AD (Entra ID) and Microsoft 365 MFAQuick Answer: Microsoft Entra ID (formerly Azure AD) and Microsoft 365 support two ways to use a hardware OATH token for MFA: native hardware OATH token support, which requires an Entra ID Premium P1 or P2 license, or the software-token setup flow, which works without a premium license. Programmable tokens like Protectimus Slim NFC and Flex can be used either way. There are currently two ways to implement an Azure hardware token for Azure Multi-Factor Authentication: With classic OATH tokens for Azure MFA with hard-coded secret keys, such as Protectimus Two. To make use of one of these you’ll need a Microsoft Entra ID Premium P1 or P2 license, the same licensing tier that also gates on-prem bridging options like the Azure NPS Extension. With a programmable hardware token for Azure MFA Protectimus Slim NFC or Protectimus Flex which is a replacement for an authentication app from Microsoft. This Azure cloud MFA hardware token does not require a premium subscription account. In this article, we will describe how to set up both types of hardware tokens for Azure token-based authentication. All three devices can be bought here. Buy hardware token for Azure MFA Classic OATH hardware tokens for Azure MFA – how to set up Currently, Microsoft Entra ID supports tokens with passwords not longer than 128 characters and password life-span of 30 and 60 seconds. Protectimus Two hardware OTP tokens fit these requirements. The CSV file needs six columns (UPN, serial number, secret key, time interval, manufacturer, and model) with the header row included. A newer provisioning method, based on the Microsoft Graph API, adds SHA-256 token support and self-service activation. The classic CSV upload only recognizes SHA-1, requires a Global Administrator, and every token has to be activated manually. Once you choose and receive the Azure MFA OATH token you prefer you need to register your token with Azure. Below is the step-by-step guide on this simple process: Step 1. Prepare a CSV file that includes your UPN (user principal name), the serial number of the hardware token Azure MFA, the seed (secret key), time interval, make and model of the Azure AD MFA hardware token. Make sure to include a header row, the result should look something like this: Step 2. Once the CSV file is created and properly formatted it has to be imported. Go...
Read more