Microsoft prompting for 'Security Key' as the default MFA method? Entra Admin Center

HernanJimenez-0754 20 Reputation points
2024-12-10T03:55:27.4633333+00:00

Hello all,

I have Microsoft Authenticator App, and Security Key (YubiKey) registered as MFA methods. However, Microsoft seems to prompt for Security Key as default on both company device and personal mobile devices. In my org, we need to provide users with both methods in case users choose not to enroll with personal devices. Prompting for Security Key as default is inconvenient to our users as it creates extra steps for them to cancel out, and navigate to "Other ways to sign in" in the Authenticator App. Another issue is unable to enroll "Security Key" without first enrolling with Authenticator App.

Has Microsoft fixed this issue, or has anyone found a fixed for this?

Details:

MFA deployed through Conditional Access Policies

Per-User MFA is disabled

SSPR only has Security Questions enabled

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 119.8K Reputation points MVP Volunteer Moderator
    2024-12-10T07:31:08.8333333+00:00

    Do you have the system-preferred MFA method feature enabled? It will prioritize the "most secure" methods first, as detailed here: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-system-preferred-multifactor-authentication


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.