Hardware OATH Tokens for Azure AD (Entra ID) and Microsoft 365 MFA

Quick Answer: Microsoft Entra ID (formerly Azure AD) and Microsoft 365 support two ways to use a hardware OATH token for MFA: native hardware OATH token support, which requires an Entra ID Premium P1 or P2 license, or the software-token setup flow, which works without a premium license. Programmable tokens like Protectimus Slim NFC and Flex can be used either way.

There are currently two ways to implement an Azure hardware token for Azure Multi-Factor Authentication:

  • With classic OATH tokens for Azure MFA with hard-coded secret keys, such as Protectimus Two. To make use of one of these you’ll need a Microsoft Entra ID Premium P1 or P2 license, the same licensing tier that also gates on-prem bridging options like the Azure NPS Extension.
  • With a programmable hardware token for Azure MFA Protectimus Slim NFC or Protectimus Flex which is a replacement for an authentication app from Microsoft. This Azure cloud MFA hardware token does not require a premium subscription account.

In this article, we will describe how to set up both types of hardware tokens for Azure token-based authentication. All three devices can be bought here.

Classic OATH hardware tokens for Azure MFA – how to set up

Currently, Microsoft Entra ID supports tokens with passwords not longer than 128 characters and password life-span of 30 and 60 seconds. Protectimus Two hardware OTP tokens fit these requirements.

The CSV file needs six columns (UPN, serial number, secret key, time interval, manufacturer, and model) with the header row included. A newer provisioning method, based on the Microsoft Graph API, adds SHA-256 token support and self-service activation. The classic CSV upload only recognizes SHA-1, requires a Global Administrator, and every token has to be activated manually.

Once you choose and receive the Azure MFA OATH token you prefer you need to register your token with Azure. Below is the step-by-step guide on this simple process:

Step 1. Prepare a CSV file that includes your UPN (user principal name), the serial number of the hardware token Azure MFA, the seed (secret key), time interval, make and model of the Azure AD MFA hardware token. Make sure to include a header row, the result should look something like this:

How to add OATH tokens to Azure MFA

Step 2. Once the CSV file is created and properly formatted it has to be imported. Go to the Microsoft Entra admin center and browse to Entra ID, then to Multifactor authentication. On the MFA page choose OATH tokens and click the “Upload” button. Upload your CSV file; the upload process might take a few minutes.

Azure two-factor authentication hardware tokens setup

Step 3. Click the “Refresh” button. If the CSV file was uploaded successfully you will see a list of your Azure AD hardware tokens, if the file had an error you will be notified on the same page:

File uploaded successfully:

Azure Multi Factor authentication Oath hardware tokens setup

File uploaded with errors:

Azure 2-factor authentication OATH hardware tokens

Step 4. Now you need to activate your Azure multi-factor authentication hardware token. If you have multiple tokens, you should activate them one by one. Click the “Activate” button at the lattermost column on the right and enter the password generated by the corresponding Azure MFA token. After that, click the “Verify” button.

Azure OATH tokens setup

Step 5. Once the MFA server accepts your one-time password you will get a message confirming the activation of the Microsoft Azure token you selected from the list and there should appear a check mark in the corresponding “Activated” column. Now your token is successfully activated and can be used to log in.

OATH tokens for Azure MFA setup - activated

Step 6. 2FA settings in the user account.

OATH tokens will be automatically set as a main 2FA method.

NOTE! If any other 2-factor authentication method is registered for a user, they can use several two-factor authentication methods at once. For example, I activated a 2FA app Protectimus SMART as a 2FA methos, in this case, both one-time passwords from hardware token and 2FA app will work when I enter any of them in this field:

Azure MFA OATH token setup - step 7

If you want to use only a hardware OATH token for Azure 2-factor authentication, login to your account and deactivate other two-factor authentication methods.

  1. Go to your account settings page at https://myaccount.microsoft.com/?ref=MeControl
  2. Navigate to the Security Info tab.
  3. Delete two-factor authentication methods you don’t need.
Azure MFA OATH token setup - step 8

Programmable hardware tokens for Azure MFA

As has already been mentioned above – to use a classic Microsoft Azure MFA hardware token you need to have a premium subscription. But we know that not everyone is ready to pay 6 euros per month per one user. If you are not ready to pay too, programmable hardware tokens Protectimus Slim NFC or Protectimus Flex is the way to go for you. These tokens are recognized as authentication apps by the Azure MFA system, so you do not need a premium license to use them.

Adding Protectimus Slim NFC or Protectimus Flex as a recognized second factor of authentication to your Azure MFA is pretty straightforward. All you need to do is log into the MFA setup page, configure the authentication to recognize your Azure authentication token and program the device itself to be used for Azure MFA. The whole process takes mere minutes and is described in detail here.

The Protectimus Slim NFC token comes in a slim card format with an E-ink display and can be reprogrammed via NFC using a dedicated Android app. The programmable TOTP token Protectimus Flex takes a key-fob form instead, with a battery life indicator, for anyone who prefers attaching it to a keyring rather than carrying a card. Both tokens are supplied with pre-programmed secret keys and can be added to Entra ID through its OATH hardware tokens workflows, including CSV import. Alternatively, they can be reprogrammed with the secret generated during Entra ID’s software-token setup flow, allowing them to be used without the premium license required for native hardware OATH token support.

Common Scenarios

Hardware OATH tokens are useful for frontline employees who do not have company-issued smartphones and in no-BYOD environments where personal devices cannot be used for work authentication. They are also practical where phones are restricted or cannot be carried, such as production floors, laboratories, clean rooms, and other controlled environments. At shared workstations or kiosks, each employee can use an individual Entra ID account and personal hardware token.

For system administrators, IT administrators, and other privileged users, organizations may prefer a dedicated authentication device that is issued, controlled, and recovered by the company instead of relying on an authenticator installed on a personal phone. Dedicated hardware authenticators may also be required by specific internal security or compliance policies.

Hardware tokens are similarly practical for contractors and temporary workers: the organization can issue a token, recover it when the assignment ends, and reassign it to another user. In hybrid Entra ID and Active Directory environments, the same token-based approach can also be used to protect on-premises Windows, RDP, and domain access with MFA for Active Directory.

Common questions

1. What about time-drift support in Azure MFA?

Microsoft Entra ID corrects token time drift automatically. For tokens with a 30-second interval, it accepts drift of up to ±1 day during activation and ±1 minute at each sign-in; for 60-second tokens, the ranges are ±2 days and ±2 minutes. But if you’d like to keep time drift issue under control, use Protectimus Slim NFC or Protectimus Flex tokens, which have a time synchronization feature now. The time is resynchronized when a secret key is flashed to the token.

2. Why hardware token is better for Azure MFA than 2FA apps, SMS, and phone calls?

A hardware token is by far the most bulletproof protection you can get for your data stored on a cloud. Such a device generates secure passwords without and needs no network connection whatsoever. With a hardware token you have an impenetrable wall between your data and anyone who tries to steal it. There’s simply no way for hackers to infect the device or intercept the generated codes. And if a hardware token is stolen or lost you most probably will notice it immediately, whereas with an infected app or intercepted SMS you might not know any damage is done before it’s too late.

3. Can I order hardware token with my company logo?

If you want Protectimus Slim NFC you can have the device branded even if your order is as small as one token. With Protectimus TWO custom branding is offered for orders over 1000 devices.

4. Does Protectimus Slim NFC support multiple secret keys (seeds)?

No, this token allows for one seed at a time. But Protectimus Slim NFC can be programmed to work for a different resource once you stop using the one you initially programmed it for.

5. Does Microsoft Entra ID call it “Azure AD” or “Entra ID” in the admin center?

Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. The underlying MFA and OATH token functionality is unchanged: only the admin center labeling and some menu paths were renamed.

6. Do I need a Microsoft Entra ID Premium license for a Protectimus hardware token?

It depends on how you add the token. Adding it through Entra ID’s native hardware OATH token workflow, including CSV import, requires a Premium license. Protectimus Slim NFC and Flex can also be reprogrammed with the secret generated during Entra ID’s software-token setup flow, and used this way they work without a Premium license.

Read more:

Subscribe To Our Newsletter

Join our mailing list to receive the latest news and updates from our team.

You have Successfully Subscribed!

Author: Anna

If you have any questions about two-factor authentication and Protectimus products, ask Anna, and you will get an expert answer. She knows everything about one-time passwords, OTP tokens, 2FA applications, OATH algorithms, how two-factor authentication works, and what it protects against. Anna will explain the difference between TOTP, HOTP, and OCRA, help you choose a token for Azure MFA, and tell you how to set up two-factor authentication for Windows or Active Directory. Over the years with Protectimus, Anna has become an expert in cybersecurity and knows all about the Protectimus 2FA solution, so she will advise on any issue. Please, ask your questions in the comments.

Share This Post On

1 Comment

  1. The Upload is greyed out for me. Do I have to be Global Admin or can a helpdesk role work?

    Post a Reply

Submit a Comment

Your email address will not be published. Required fields are marked *

Subscribe To Our Newsletter

Subscribe To Our Newsletter

Join our mailing list to receive the latest news and updates from Protectimus blog.

You have successfully subscribed!

Share This