Unable to Enrol FIDO2 Security Keys in a Hybrid AD Environment

Oliver Harris 40 Reputation points
2026-07-28T03:01:07.4533333+00:00

Hi everyone, we have enabled FIDO2 authentication in Entra ID, but our domain users are still unable to enrol their security keys. Could this be caused by a missing hybrid identity configuration, authentication method setting, or on-premises AD requirement?

Windows for business | Windows 365 Business
0 comments No comments

Answer accepted by question author

Marcin Policht 101K Reputation points MVP Volunteer Moderator
2026-07-28T03:28:21.9366667+00:00

Follow https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkeys-fido2

Verify your Authentication method settings in the Microsoft Entra admin center. Under Authentication methods > Policies > Passkey (FIDO2), ensure Allow self-service setup is set to Yes. Also confirm the affected users are included in the policy's target scope. If Enforce attestation is enabled, verify the security keys are supported and not blocked by any configured AAGUID allow or block list.


If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

hth

Marcin

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.