webauthn security key registration failing in entra id
Fixes WebAuthn security key registration failures in Entra ID: policy scope, browser support, and key compatibility checks. Use when the enrollment ceremony errors out or never starts. Not for authenticator-app issues.
TL;DR
Security key registration failures come from three places: the Authentication methods policy does not allow keys for the user, the browser blocks the ceremony, or the key itself is incompatible. Check policy first, then browser, then the key, and you will find it fast.
The query
webauthn security key registration failing in entra idUse this when
- enrollment wizard errors when the key is touched
- browser never shows the security-key prompt
- one key model works and another does not
Not for
- phone-based authenticator problems
- smart card logon to Windows (different stack)
- sign-in failures with an already-registered key
Steps
- Confirm the user is in scope for Passkey (FIDO2) in the Authentication methods policy, with no exclusions. Expected output: policy targets the user
- Have the user retry in Edge or Chrome; the security info page must load over HTTPS. Expected output: the browser shows the security-key prompt
- Try a different USB port or a direct connection without a hub, and enter the key PIN if it has one. Expected output: the key lights up or asks for touch
- Test the key on another machine to isolate a faulty key. Expected output: the key works elsewhere or is confirmed faulty
- Check whether attestation restrictions in the policy block that key model. Expected output: the key model is allowed or the restriction is relaxed per policy
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_L9BquggW5UHFGCr99r-rXQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.