Share via

Need to register Yubikey

Parvatham Laxminarayana 0 Reputation points
2026-04-08T10:33:49.72+00:00

I lost Yubikey and new one is available with me. Now how to register and login

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-04-08T10:34:09.4566667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Because the original YubiKey is lost, it must be treated as compromised and removed from the account, then the new key can be registered as a fresh sign-in method.

    For Microsoft Entra ID accounts using Microsoft Authenticator and hardware keys (like YubiKey), the supported flows in the provided context are for passkeys (FIDO2) and certificate-based authentication. The general pattern is:

    1. Remove the old key or passkey from the account
      • If the lost key was registered as a passkey in Microsoft Authenticator on Android or iOS:
        • Open the Authenticator app.
        • Tap the account name.
        • Go to Settings and choose Delete passkey (wording differs slightly between Android and iOS but follows this pattern).
        • If the passkey still appears under Security info, go to Security info and select Delete next to that passkey.
    2. Register a new passkey (or new hardware key) for sign-in
      • From a browser, sign in to Security info.
      • Select Add sign-in method.
      • Choose Passkey and select Add.
      • Complete multifactor authentication (MFA) with any existing method that still works. If no MFA method is available, an Authentication Policy Administrator must issue a Temporary Access Pass so that strong authentication can be completed before registering the new passkey.
      • When the security dialog appears asking where to save the passkey:
        • If the organization allows saving a passkey to a security key (such as a YubiKey), choose Security Key.
        • Insert or connect the new YubiKey when prompted.
        • Create or enter the PIN for the YubiKey and perform the required gesture (touch the key) when requested.
        • Finish the dialog and return to Security info.
      • Optionally rename the new sign-in method, then select Done.
    3. If using Microsoft Authenticator on mobile for passkeys
      • The easiest way is to add a passkey directly in the Authenticator app on Android or iOS (supported on iOS 17+ and Android 14+). After adding, confirm that the new passkey appears under Security info.
    4. If using certificate-based authentication with YubiKey on Android
      • Ensure Microsoft Authenticator is installed before Company Portal.
      • When signing in and choosing Use Certificate or smart card, plug in or tap the YubiKey (USB or NFC) and select the certificate from the YubiKey.
    5. If registration errors occur (for example, “passkey already exists”)
      • Delete any locally created passkey in Authenticator (tap account → SettingsDelete passkey), then retry the registration from Security info.

    If no working MFA method remains and no admin can issue a Temporary Access Pass, a support case with Microsoft (Data Protection team) is required to restore access before a new YubiKey can be registered.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.