Share via

Phishing-resistant MFA CA allows passkey enrollment but fails with generic WebAuthn error

Adrien LARMET 0 Reputation points
2026-05-19T20:01:34+00:00

Title: Phishing-resistant MFA CA allows passkey enrollment but fails with generic WebAuthn error

My tenant is currently locked: no Global Administrator account can sign in anymore.

I think I may have hit a weird edge case with Entra Conditional Access + Authentication Strengths.

What I configured:

  • Conditional Access targeting all admin roles
  • All cloud apps
  • Grant → Require authentication strength
  • Authentication strength = Phishing-resistant MFA

What’s strange:

Accounts that already had a phishing-resistant method registered BEFORE the CA policy work fine.

But for admin accounts without an existing PR MFA method:

  • Entra correctly redirects them to passkey / WHfB registration
  • the registration process appears to complete
  • then it fails with a completely generic error like: “Something went wrong” or “”This might be due to a timeout, a canceled request or a private browsing window »

The weird part is:

  • this happens across multiple PCs
  • multiple admin accounts
  • iPhone too
  • Microsoft Authenticator passkeys
  • Windows Hello for Business

It honestly looks like the passkey is successfully created locally on the device, but never properly registered/accepted by Entra afterwards.

What makes me think this may not simply be “working as designed”:

  • Audit mode showed no failures before enforcement
  • Existing PR MFA methods continue to work
  • Entra DOES allow/pass users into the enrollment flow
  • the failure happens only at the very end with a generic WebAuthn-style error message instead of a proper Conditional Access policy violation

Microsoft support already reproduced the issue through screen sharing and escalated the case.

Has anyone seen this behavior specifically with:

  • Authentication Strengths
  • Phishing-resistant MFA
  • Microsoft Authenticator passkeys
  • WHfB enrollment after CA enforcement?
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Adrien LARMET 0 Reputation points
    2026-05-20T08:52:37.77+00:00

    It’s working again.

    I finally managed to access the tenant by signing into a PC with my admin account and configuring Windows Hello. The PIN failed, but fingerprint authentication finally worked and let me back in.

    I disabled the CA immediately and created a proper break-glass account. I fully admit I was careless, but honestly Microsoft also shares some responsibility here because this whole flow is clearly not mature enough yet.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.