## TL;DR
Security key registration failures come from three places: the Authentication methods policy does not allow keys for the user, the browser blocks the ceremony, or the key itself is incompatible. Check policy first, then browser, then the key, and you will find it fast.

## The query
```text
webauthn security key registration failing in entra id
```

## Use this when
- enrollment wizard errors when the key is touched
- browser never shows the security-key prompt
- one key model works and another does not

## Not for
- phone-based authenticator problems
- smart card logon to Windows (different stack)
- sign-in failures with an already-registered key

## Steps
1. Confirm the user is in scope for Passkey (FIDO2) in the Authentication methods policy, with no exclusions. Expected output: policy targets the user
2. Have the user retry in Edge or Chrome; the security info page must load over HTTPS. Expected output: the browser shows the security-key prompt
3. Try a different USB port or a direct connection without a hub, and enter the key PIN if it has one. Expected output: the key lights up or asks for touch
4. Test the key on another machine to isolate a faulty key. Expected output: the key works elsewhere or is confirmed faulty
5. Check whether attestation restrictions in the policy block that key model. Expected output: the key model is allowed or the restriction is relaxed per policy

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_L9BquggW5UHFGCr99r-rXQ
