Pre-provisioning / Programming a Nitrokey 3 with a generated secret for Microsoft Entra ID as Microsoft 365 admin

We are thinking about pre-provisiong Nitrokey 3C NFC or Nitrokey 3A NFC keys for Microsoft Entra ID users.

Is that possible using nitropy or Nitrokey App 2?

We did not find a guide in the documentation.

Helpful ressources we found:
Guide by yubico (Administrator registration (alternative method) paragraph)
Hardware OATH tokens (preview) information from Microsoft
Microsoft prefers passkeys (Nitrokey) from now on information from Microsoft

Thanks!

As far as I can see the yubico guide configures a feature Nitrokey supports as well, but has no dedicated GUI workflow for (yet; not sure what the mentioned recovery code is - maybe the programmed secret). Using another method, e.g. passkeys, should definitely offer you most flexibility, also because MS will provide the workflows to manage compatible (/certified?) tokens.

But my experience is limited is that respect and I reply foremost to point you to the available documented options. The tokens have a number of features that can serve for authentication: Guides - Nitrokey Documentation
For the doc it’s easiest to enter a search term on the left, you won’t find all guides via the hierarchical tree for a device.

We started working on such a solution but don’t have a release date yet. Would you be interested to become a beta tester of such?

Yes, we would love to help you help us. :smiling_face: