Reviewed by Brian Kinane · SetupPasskeys product author · 20 July 2026
Microsoft Entra passkey troubleshooting
Start with the failure point: registering a passkey, saving it to the expected provider, or using it at sign-in. These checks resolve the most common rollout issues.
The passkey option is missing
Confirm that the tenant authentication methods policy enables passkeys (FIDO2) for the user’s group. If key restrictions are enabled, verify that the authenticator provider’s AAGUID is allowed.
The wrong provider opens
On a phone with several passkey providers, the operating system may offer a different saved-password provider. Ask the user to choose another option and select the provider approved by IT.
Registration completes but sign-in fails
Check Entra sign-in logs and Conditional Access results. A report-only phishing-resistant MFA policy is the safest way to see who would be affected before enforcement.
A user replaced or lost a phone
Remove the old authentication method from the user’s security info, issue a Temporary Access Pass if required, and register a fresh passkey on the replacement device.
A safe rollout pattern
Start with a pilot group, exclude two cloud-only emergency access accounts, monitor report-only results, then widen the group in controlled stages.