Follow https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkeys-fido2
Verify your Authentication method settings in the Microsoft Entra admin center. Under Authentication methods > Policies > Passkey (FIDO2), ensure Allow self-service setup is set to Yes. Also confirm the affected users are included in the policy's target scope. If Enforce attestation is enabled, verify the security keys are supported and not blocked by any configured AAGUID allow or block list.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin