User with hardware OAUTH token gets error "you cannot use codes from this device" when trying to use generated code

Andrew 31 Reputation points
2023-06-30T08:51:03.8133333+00:00

I have one testing user in our Azure tenant with assigned and activated OAUTH hardware token, but when such user tries to use it for MFA, following error message appears "you cannot use codes from this device". If some random code is entered, the error message differs aka the generated code is correct, but cannot be used from some reason?err2

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,522 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 17,641 Reputation points Microsoft Employee
    2023-07-04T11:13:21.4333333+00:00

    @Andrew

    Thank you for posting your query on Microsoft Q&A. From above error message we could understand that end user is not able to use TOTP issued from Hardware token device.

    Please do correct me if this is not the case by responding in the comments section.

    This error could be caused due to various reasons, to identify the same kindly validate the following:

    • If customer have 5 or more devices registered with hardware token, authenticator app, if yes, then kindly suggest them to remove authenticator from any of the device and retry.
    • Validate what error do we see in Azure AD sign in logs, if you could share the screenshot removing PII, user, device and application ID.
    • Click on view details of the error message above and share the time stamp and correlation id, complete screenshot would be preferred.
    • Also validate if you have migrated to Authentication methods from legacy MFA, if yes then hardware token must be enabled.

    User's image

    User's image

    Please do let me know if you have any further queries.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.