Fix Entra MFA Prompting for Security Key Instead of Authenticator
Question details
Users are being asked to provide a physical security key for Multi-Factor Authentication instead of receiving a prompt via their default Microsoft Authenticator app.
- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- A user is attempting to sign in to their enterprise Microsoft account and needs to complete the Multi-Factor Authentication step.
- Observed behavior
- The sign-in process defaults to requesting a registered YubiKey or FIDO2 security key rather than sending a push notification to the Microsoft Authenticator app.
Ensure you have Authentication Policy Administrator or Global Administrator privileges in your Microsoft Entra tenant before attempting to view or modify Conditional Access policies.
Review Authentication Methods and Conditional Access Policies
Check your tenant's Conditional Access rules to ensure they aren't enforcing an authentication strength that strictly requires a phishing-resistant physical security key over the Authenticator app.
Microsoft Entra ID evaluates Authentication Strengths configured in Conditional Access policies. If a policy requires 'Phishing-resistant MFA', it will prioritize FIDO2 security keys (like YubiKey) over standard Microsoft Authenticator push notifications. Reviewing these policies is the first step to resolving unexpected prompts.
Log in to the Microsoft Entra admin center using an account with the necessary administrator credentials.
Go to Protection > Authentication methods > Policies to review the priority and enablement status of both Microsoft Authenticator and FIDO2 security keys.
Navigate to Protection > Conditional Access > Policies. Review any active policies applied to the affected users, specifically checking the 'Grant' controls for 'Require authentication strength'.
If a policy is strictly enforcing phishing-resistant MFA, modify the policy or user assignment if standard Authenticator app push notifications are deemed acceptable for that specific sign-in scenario.
Seek Specialized Support on Microsoft Q&A
If the policies appear correct but the issue persists, escalate the configuration issue to Microsoft Q&A for targeted assistance.
Try WPS Office for a Seamless, Local Workflow
While resolving complex Microsoft Entra ID and MFA cloud login issues, you may find yourself locked out of your cloud-based documents. WPS Office provides a robust, lightweight, and completely free alternative that allows you to easily edit your files locally without relying on complicated enterprise cloud authentication.
- 1. Download the Installer: Visit the official WPS website and click 'Download WPS Office Free' to get the latest version.
- 2. Install the Software: Run the downloaded installer and follow the quick setup wizard to install the suite on your computer.
- 3. Open Your Files Instantly: Launch WPS Office and open your existing Word, Excel, or PowerPoint documents to continue working immediately.

Frequently Asked Questions
Can users manually choose the Authenticator app if prompted for a security key?
Yes, if the Conditional Access policies allow it, users can click 'Sign in another way' on the login screen and select the Microsoft Authenticator app from their registered methods.
Why does Entra ID prioritize physical security keys over the Authenticator app?
Entra ID evaluates FIDO2 security keys as a stronger, phishing-resistant authentication method. If your tenant's Conditional Access policies are set to require high authentication strengths, the system will default to the most secure method available.
How can a user set Microsoft Authenticator as their default sign-in method?
Users can navigate to the 'Security info' section of their My Sign-Ins portal (mysignins.microsoft.com). From there, they can select 'Default sign-in method' and change it to Microsoft Authenticator, provided organizational policies permit it.
Does WPS Office require a Microsoft Entra ID account to function?
No, WPS Office operates independently and does not require a Microsoft Entra ID or Microsoft account to function. It allows you to create, edit, and save documents locally without any enterprise cloud login dependencies.




