Skip to content

Microsoft Entra passkey troubleshooting

Start with the failure point: registering a passkey, saving it to the expected provider, or using it at sign-in. These checks resolve the most common rollout issues.

The passkey option is missing

Confirm that the tenant authentication methods policy enables passkeys (FIDO2) for the user’s group. If key restrictions are enabled, verify that the authenticator provider’s AAGUID is allowed.

The wrong provider opens

On a phone with several passkey providers, the operating system may offer a different saved-password provider. Ask the user to choose another option and select the provider approved by IT.

Registration completes but sign-in fails

Check Entra sign-in logs and Conditional Access results. A report-only phishing-resistant MFA policy is the safest way to see who would be affected before enforcement.

A user replaced or lost a phone

First identify where the passkey was stored. For Apple Passwords/iCloud Keychain or Google Password Manager, losing one phone does not necessarily lose the synced passkey: help the user recover the same Apple or Google account on another approved device and confirm the passkey still works before removing anything from Security info. Removing that Entra method can revoke the synced credential on the user’s other devices too. If the lost phone might still be usable, follow the organisation’s device-lock, wipe and incident process even when the passkey itself is synced.

For a lost device-bound Microsoft Authenticator, Samsung Pass or Windows passkey, or a lost security key, verify the user through the organisation’s recovery process, use another registered method or issue a Temporary Access Pass if required, remove only the unavailable credential, and register an approved replacement. Keep a tested recovery method before the next loss occurs.

A safe rollout pattern

Start with a pilot group, exclude two cloud-only emergency access accounts, monitor report-only results, then widen the group in controlled stages.

Source: Microsoft Entra passkey FAQ, including synced and device-bound recovery behaviour.