Fido2 Security Key option unavailable.

Daniel Woffard 0 Reputation points
2026-08-07T18:12:06.68+00:00

I'm having a similar issue to the following question.

https://learn.microsoft.com/en-us/answers/questions/1289804/cannot-see-fido2-authentication-method-in-the-user

I would like to set up a Fido2 key on several accounts. The My Sign Ins page is not giving me or my users the option to add a Fido2 Security Key to the account

https://mysignins.microsoft.com/security-info

Screenshot 2026-08-07 111321

^It's just not showing up as an available option^

All of the settings in Entra are (As far as I know) set to allow it:

Screenshot 2026-08-07 110754

Screenshot 2026-08-07 111110

However we don't have a license for Intune on each of the accounts we manage in question so I cannot modify the following setting in Intune:

Screenshot 2026-08-07 104436

Because it is just coming up with the following despite me being both a global admin and having intune admin priveleges:

Screenshot 2026-08-07 105909

I'm concerned that it's that setting that I need to change and I'll need to sign up for an Intune subscription to access it.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author

AI answer

2026-08-07T18:12:31.83+00:00

The missing option on My Sign-Ins is not explained by the Intune setting shown.

For users to register a FIDO2 security key, the supported requirements in the available documentation are:

  1. Passkey (FIDO2) must be enabled and targeted to the users in Entra ID > Security > Authentication methods > Policies.
  2. Allow self-service setup must be enabled for the Passkey (FIDO2) policy.
  3. The user must have a physical FIDO2 and Microsoft-compliant security key approved by the organization.
  4. Registration is done from Security info after the user signs in and completes MFA.
  5. The user must be on a supported device and browser.

Based on the screenshots, the main items to verify are:

  1. In Microsoft Entra admin center go to Entra ID > Security > Authentication methods > Policies > Passkey (FIDO2).
  2. Confirm Enable is On.
  3. Confirm the affected users are included under Enable and Target.
  4. Confirm Allow self-service set-up is checked.
  5. Confirm each target has at least one passkey profile assigned.
  6. If Enforce attestation is enabled in the assigned profile, verify the security key model is supported by that profile and not blocked by any AAGUID restriction.

Important limitations that can also prevent registration:

  • Guest users cannot register passkey (FIDO2) credentials.
  • If a user is in an excluded group in the Passkeys (FIDO2) authentication method policy, that blocks FIDO2 registration and sign-in entirely.
  • If key restrictions are changed and an allowed AAGUID is removed later, previously registered keys can stop working for sign-in.

For the registration flow itself, the documented path is:

  1. Open Security info.
  2. Sign in and complete MFA.
  3. Select Add sign-in method.
  4. Choose Passkey.
  5. Select Security key when prompted for where to save the passkey.

So the correct option in the current UI is Passkey, not a separate menu item labeled FIDO2 security key. The security key choice appears during the passkey registration flow.

The Intune Windows Hello for Business / Use security keys for sign-in setting is relevant to Windows sign-in scenarios, not to whether the My Sign-Ins page offers passkey registration. Nothing in the provided documentation states that an Intune subscription is required just to make the Security info page show the passkey registration path.

If the users still do not get the security key path after selecting Passkey, the supported checks from the available guidance are:

  • verify they are in scope for the Passkey (FIDO2) policy,
  • verify Allow self-service setup is enabled,
  • verify the key is FIDO2 and Microsoft-compliant,
  • verify the browser/device is supported,
  • verify the users are not guest users.

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Daniel Woffard 0 Reputation points
    2026-08-07T20:41:36.47+00:00

    This is the solution. There used to be an option for Security Keys but now it's just a part of the Passkey section and you have to allow it to store the key on your computer before you can tell it to save to the Fido2 key. Very frustrating but it did give me the correct answer.

    Choose Passkey. Select Security key when prompted for where to save the passkey. So the correct option in the current UI is Passkey, not a separate menu item labeled FIDO2 security key. The security key choice appears during the passkey registration flow.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.