Do you have the system-preferred MFA method feature enabled? It will prioritize the "most secure" methods first, as detailed here: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-system-preferred-multifactor-authentication
Microsoft prompting for 'Security Key' as the default MFA method? Entra Admin Center

Hello all,
I have Microsoft Authenticator App, and Security Key (YubiKey) registered as MFA methods. However, Microsoft seems to prompt for Security Key as default on both company device and personal mobile devices. In my org, we need to provide users with both methods in case users choose not to enroll with personal devices. Prompting for Security Key as default is inconvenient to our users as it creates extra steps for them to cancel out, and navigate to "Other ways to sign in" in the Authenticator App. Another issue is unable to enroll "Security Key" without first enrolling with Authenticator App.
Has Microsoft fixed this issue, or has anyone found a fixed for this?
Details:
MFA deployed through Conditional Access Policies
Per-User MFA is disabled
SSPR only has Security Questions enabled
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
-
Vasil Michev 119.8K Reputation points MVP Volunteer Moderator
2024-12-10T07:31:08.8333333+00:00