Fix YubiKey FIDO2 Security Keys Not Available in Office on Mac
Question details
User is unable to use YubiKey FIDO2 security keys for Microsoft Office authentication on macOS, resulting in missing options and application hangs.

- Product
- Microsoft 365 for Mac
- Device & OS
- Mac
- Scenario
- Attempting to sign in to Microsoft 365 applications, such as Teams, on a Mac using a YubiKey 5 device.
- Observed behavior
- The security-key authentication option is unavailable. While Intune Single Sign-On works during initial Company Portal enrollment, Teams hangs, and subsequent sign-ins only offer Microsoft Authenticator.
Ensure your macOS is fully updated and that you have administrator access to the Microsoft 365 tenant, as resolving FIDO2 authentication issues typically requires adjusting organization-wide security policies.
Verify Tenant Configuration and Intune SSO Extension
Because FIDO2 support varies by macOS version and Office application, your Microsoft 365 administrator must verify tenant authentication policies and SSO settings.
Microsoft 365 for Mac does not natively support FIDO2 security keys in every Office authentication scenario out of the box. Proper functioning relies heavily on specific Intune SSO extension configurations and Azure AD authentication policies.
Log in to the Microsoft 365 Admin Center using enterprise administrator credentials.
Navigate to the authentication policies in Microsoft Entra ID and verify that FIDO2 security keys are enabled and targeted for macOS devices.
Review the Intune Single Sign-On (SSO) extension settings to ensure macOS profiles are fully configured with Microsoft-recommended SSO URLs.
Check the Azure portal sign-in logs for Teams and Office apps to identify exactly where the authentication hang occurs on the Mac.
If the issue persists, open a Microsoft 365 business support request directly from the Admin Center for tenant-specific troubleshooting.

Switch to WPS Office for a Streamlined Mac Experience
If complex Microsoft 365 authentication policies and SSO issues are disrupting your workflow on macOS, consider switching to WPS Office. It provides a lightweight, hassle-free environment for document creation without relying on complex enterprise sign-in configurations.
- 1. Download WPS Office: Visit the official WPS website and download the macOS installation package.
- 2. Install and Launch: Follow the on-screen instructions to install the suite and open the application directly on your Mac.
- 3. Open Existing Files: Drag and drop your existing Microsoft Office files into WPS Office to continue working immediately.

Frequently Asked Questions
Why does my YubiKey work on Windows but not on Mac for Microsoft 365?
FIDO2 security key support for Microsoft 365 varies by platform. While Windows has deep native integration via Windows Hello and Entra ID, macOS requires specific Intune SSO extensions and tenant configurations that may not be fully deployed in your environment.
What should I do if Microsoft Teams hangs during authentication on my Mac?
This often indicates a conflict with the Intune Single Sign-On extension on macOS. Try clearing the Teams desktop client cache, and ask your IT admin to verify the Microsoft-recommended SSO URLs in your device management profile.
Can I force Office for Mac to prompt for a FIDO2 security key?
End-users cannot force this prompt if the tenant policy defaults to Microsoft Authenticator or another method for macOS. Your Microsoft 365 administrator must configure the authentication methods policy to explicitly allow and prioritize FIDO2 for Mac devices.




