Cannot register Yubikey passkey name when saving name

Bjorn Wetzels 0 Reputation points
2025-12-16T06:17:14.4766667+00:00

I'm configuring a break-glass admin account. When logging in into the account to set up the additional authentication method, the USB key pops up, I enter the passkey and am prompted to give the key a name. When I press save, the system throws an error "We've run into a problem" .

I've since then tried with Edge, Edge in Private mode, Firefox and Firefox in private mode. I changed the name from numeric to alphanumeric, to longer names.

I have configured two accounts with two different yubikeys. Both have the same issue. What am I doing wrong here?

Windows for business | Windows Client for IT Pros | Devices and deployment | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2025-12-16T20:32:46.9433333+00:00

    Are you enforcing key restrictions in Entra? If so you will need to add these

    https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2

    • Enforce key restrictions should be set to Yes only if your organization wants to only allow or disallow certain security key models or passkey providers, which are identified by their AAGUID. You can work with your security key vendor to determine the AAGUID of the passkey. If the passkey is already registered, you can find the AAGUID by viewing the authentication method details of the passkey for the user.

  2. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2025-12-17T13:59:27.3566667+00:00

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.