passwordless security key sign-in

Abdelilah Ait Bendra 11 Reputation points
2022-03-06T12:56:11.433+00:00

Hi,
i have enabled passwordless security key sign-in to on-premises resources by using Azure AD following instructions on this article :

https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-security-key-on-premises

my device is hybrid Azure AD-joined Windows 10 devices

My problem:

i am working from home and i get access to entreprise local ressources trough vpn connection, but each time my computer is note connected to vpn i get this message error when trying to login to my session using the security key : Sorry, try that again. there was an issue with the server

180461-20220304-203457.jpg

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

6 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2022-03-07T22:12:52.957+00:00

    Hi @Abdelilah Ait Bendra ,

    Problem summary

    Unable to log on remotely with security key and receiving the error, "Sorry, try that again. There was an issues with the server."

    Cause

    There is a known issue where FIDO2 cached credentials will fail after a period of time, and since you mention that this happens when you're not connected to the VPN, it sounds like this is the problem.

    Troubleshooting

    If you connect to the VPN (line of sight to a DC), then lock/unlock with FIDO2, does it work again?

    For users without "line of sight" to a domain controller, there is an issue related to the cached credential such that sign-in will work for a while (12-48 hours or so) then fail with the error message "Sorry Try that Again. There was an issues with the server"

    If you are connected to the VPN and have "line of sight" to a domain controller and FIDO2 still does not work, you can capture the authlogs data and analyze kerberos.etl to determine why that failure is occurring.

    The issue is present in the latest Windows 11 builds and some Windows 10 builds.

    The bug has been reported and the product team is actively working on a fix, but it is still pending. https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/how-to-password-less-fido2-security-key-sign-in-to-windows-10/ba-p/1434583/page/2#comments

    -

    If this answer helps resolve your question, please consider marking as answer so that others in the community with similar questions can more easily find a solution.


  2. Abdelilah Ait Bendra 11 Reputation points
    2022-03-08T07:10:55.223+00:00

    Hi @Marilee Turscak-MSFT
    I confirm that the authentication with the key works immediately once connected to vpn (line of sight to a DC)


  3. Nick Davidson 1 Reputation point
    2022-04-27T14:43:35.537+00:00

    @Marilee Turscak-MSFT Any updates on this issue?

    0 comments No comments

  4. Klein, N (Niels) 1 Reputation point
    2022-05-04T10:06:08.007+00:00

    @Marilee Turscak-MSFT Another small bump. Also suprised around the slow progress, or does it simply mean that the population using this solution is that minimal?


  5. Akos Horvath 1 Reputation point
    2022-09-19T11:33:35.027+00:00

    Any update on this?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.