# IT Pro related questions – IdP, SSO

# What identity providers can be used with Dizzion DaaS and Cloud PC?

Dizzion supports SAML2 and OAuth-based identity providers for accessing customer, organization, and admin interfaces. For end-user access—including LaunchPad, Launch Link, the Progressive Web App (PWA), and the Session API—authentication can be done using SAML2, OAuth, or SAT (Secure Anonymous Tokens).

# Can Active Directory be used to log in to Virtual Desktop or Application?

<span lang="en-NL">Yes, each Frame account can be integrated with Microsoft Active Directory, allowing end users to log in to their virtual desktop or application using their AD credentials. However, access to the LaunchPad, Launch Link, or PWA still uses SAML, OAuth, or SAT. For a seamless experience, Frame SSO (Single Login) can be enabled to streamline authentication across both layers.</span>

# Can EntraID be used to log in to Virtual Desktop or Application?

<span lang="en-NL">Yes, each Frame account can be integrated with Microsoft EntraID, allowing end users to log in to their virtual desktop or application using their EntraID credentials. However, access to the LaunchPad, Launch Link, or PWA still uses SAML, OAuth, or SAT. For a seamless experience, Frame SSO (Single Login) can be enabled to streamline authentication across both layers.</span>

# Can I enforce MFA and conditional access policies for logins?

<span lang="en-NL" style="font-size: 12.0pt; line-height: 115%; font-family: 'Aptos',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Aptos; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: #0C00; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;">Yes, the configured SAML2 or OAuth IdP enforces MFA and Conditional Access rules.</span>

# Does Dizzion DaaS and Cloud PC support passkeys (KeyPass)?

<span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Yes </span><span class="NormalTextRun SCXW139934858 BCX0">–</span><span class="NormalTextRun SCXW139934858 BCX0"> </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> DaaS and Cloud PC fully support passkeys, assuming your </span><span class="NormalTextRun CommentStart CommentHighlightPipeRest CommentHighlightRest SCXW139934858 BCX0">Identity Provider and Windows environment support them</span><span class="NormalTextRun CommentHighlightPipeRest SCXW139934858 BCX0">.</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
</span><span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">If your IdP allows passkey authentication, customers may use it to access both the </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> Console and Windows virtual desktops within </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> sessions.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

<span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> does not block the use of passkeys (sometimes referred to as </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">KeyPass</span><span class="NormalTextRun SCXW139934858 BCX0">).</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
</span><span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">If your Identity Provider (IdP) supports passkeys (FIDO2 / </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">WebAuthn</span><span class="NormalTextRun SCXW139934858 BCX0">), then </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> supports them as well.</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
</span><span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Customers can use passkeys to sign in to the </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> Console and into Windows VMs / Cloud PCs</span><span class="NormalTextRun SCXW139934858 BCX0"> as well as withing the sessions</span><span class="NormalTextRun SCXW139934858 BCX0">, provided that the required IdP and OS configurations are in place.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

#### <span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span><span class="TextRun SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0" data-ccp-parastyle="heading 1">What is supported</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{"134245418":true,"134245529":true,"335559738":360,"335559739":80}"> ?</span>

<div class="SCXW139934858 BCX0" id="bkmrk-if-your-idp-%28microso"><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">If your IdP (Microsoft Entra ID, Okta, Duo, etc.) allows FIDO2 passkeys, users can authenticate to the </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> Console using a passkey.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">If your Windows VM or Cloud PC is Entra ID–joined (or in a hybrid identity setup that supports FIDO2), users can also use passkeys to log into the VM session.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> does not restrict or block any passkey method; all authentication policies come from your IdP.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div></div>#### <span class="TextRun SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun CommentStart CommentHighlightPipeRest CommentHighlightRest SCXW139934858 BCX0" data-ccp-parastyle="heading 1">Requirements</span></span><span class="EOP CommentHighlightPipeRest SCXW139934858 BCX0" data-ccp-props="{"134245418":true,"134245529":true,"335559738":360,"335559739":80}"> </span>

<span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun CommentStart CommentHighlightPipeRest CommentHighlightRest SCXW139934858 BCX0">To use passkeys with </span><span class="NormalTextRun SpellingErrorV2Themed CommentHighlightRest SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun CommentHighlightRest SCXW139934858 BCX0">:</span></span><span class="EOP CommentHighlightPipeRest SCXW139934858 BCX0" data-ccp-props="{}"> </span>

<div class="SCXW139934858 BCX0" id="bkmrk-your-idp-must-suppor"><div class="OutlineElement Ltr SCXW139934858 BCX0">  
</div><div class="ListContainerWrapper SCXW139934858 BCX0">1. <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Your IdP must support </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">WebAuthn</span><span class="NormalTextRun SCXW139934858 BCX0">/FIDO2/passkeys.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">2. <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Passkeys must be enabled as an authentication method in the IdP.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">3. <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">The user’s device and browser must support passkeys (Edge, Chrome, Safari, Windows Hello, FIDO2 hardware keys, Android/iOS passkeys).</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">4. <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">The VM or Cloud PC must be joined to the identity system in a supported configuration (typically Microsoft Entra ID join)</span><span class="NormalTextRun SCXW139934858 BCX0"> and initial login (first login to VM) needs to be done with the password due Microsoft requirements, meaning that </span><span class="NormalTextRun SCXW139934858 BCX0">passkey can only be used with Cloud PC and Persistent VMs in </span><span class="NormalTextRun SpellingErrorV2Themed SCXW139934858 BCX0">Dizzion</span><span class="NormalTextRun SCXW139934858 BCX0"> DaaS Frame scenario (non-persistent VMs are not supported)</span><span class="NormalTextRun SCXW139934858 BCX0">.</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div></div>#### <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Example: Using Passkeys with Microsoft Entra ID</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

<span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">If customers want to enable passkeys via Microsoft Entra ID, here are the official setup guides:</span></span><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

<span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Microsoft Documentation:</span></span>

<div class="SCXW139934858 BCX0" id="bkmrk-overview-of-passkeys"><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Overview of passkeys (FIDO2) in Entra ID</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
    </span>[<span class="TextRun Underlined SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0" data-ccp-charstyle="Hyperlink">https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2</span></span>](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2?utm_source=chatgpt.com)<span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div></div><div class="SCXW139934858 BCX0" id="bkmrk-enable-passkeys-%28fid"><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Enable passkeys (FIDO2 security keys) in Entra ID</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
    </span>[<span class="TextRun Underlined SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0" data-ccp-charstyle="Hyperlink">https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2</span></span>](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2?utm_source=chatgpt.com)<span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Registering a passkey for a user</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
    </span>[<span class="TextRun Underlined SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0" data-ccp-charstyle="Hyperlink">https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-passkey</span></span>](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-passkey?utm_source=chatgpt.com)<span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Sign in to Windows with a passkey (FIDO2)</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
    </span>[<span class="TextRun Underlined SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0" data-ccp-charstyle="Hyperlink">https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-sign-in-passkey</span></span>](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-sign-in-passkey?utm_source=chatgpt.com)<span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="ListContainerWrapper SCXW139934858 BCX0">- <span class="TextRun SCXW139934858 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0">Passkeys using Microsoft Authenticator (optional)</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW139934858 BCX0"><span class="SCXW139934858 BCX0"> </span>  
    </span>[<span class="TextRun Underlined SCXW139934858 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW139934858 BCX0" data-ccp-charstyle="Hyperlink">https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-authenticator-passkey</span></span>](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-authenticator-passkey?utm_source=chatgpt.com)<span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"> </span>

</div><div class="OutlineElement Ltr SCXW139934858 BCX0">  
</div></div><span class="EOP SCXW139934858 BCX0" data-ccp-props="{}"></span>