logo
search
MFA Security Issues

Fix Entra MFA Prompting for Security Key Instead of Authenticator

Maira MehtabMaira Mehtab Sep 22, 2026 868 views

Question details

Users are being asked to provide a physical security key for Multi-Factor Authentication instead of receiving a prompt via their default Microsoft Authenticator app.

Product
Microsoft Entra ID
Device & OS
not provided
Scenario
A user is attempting to sign in to their enterprise Microsoft account and needs to complete the Multi-Factor Authentication step.
Observed behavior
The sign-in process defaults to requesting a registered YubiKey or FIDO2 security key rather than sending a push notification to the Microsoft Authenticator app.
Before you start

Ensure you have Authentication Policy Administrator or Global Administrator privileges in your Microsoft Entra tenant before attempting to view or modify Conditional Access policies.

Solution 1Recommended

Review Authentication Methods and Conditional Access Policies

Check your tenant's Conditional Access rules to ensure they aren't enforcing an authentication strength that strictly requires a phishing-resistant physical security key over the Authenticator app.

Microsoft Entra ID evaluates Authentication Strengths configured in Conditional Access policies. If a policy requires 'Phishing-resistant MFA', it will prioritize FIDO2 security keys (like YubiKey) over standard Microsoft Authenticator push notifications. Reviewing these policies is the first step to resolving unexpected prompts.

1
Sign in to the Admin Center

Log in to the Microsoft Entra admin center using an account with the necessary administrator credentials.

2
Navigate to Authentication Methods

Go to Protection > Authentication methods > Policies to review the priority and enablement status of both Microsoft Authenticator and FIDO2 security keys.

3
Check Conditional Access Rules

Navigate to Protection > Conditional Access > Policies. Review any active policies applied to the affected users, specifically checking the 'Grant' controls for 'Require authentication strength'.

4
Adjust Authentication Strengths

If a policy is strictly enforcing phishing-resistant MFA, modify the policy or user assignment if standard Authenticator app push notifications are deemed acceptable for that specific sign-in scenario.

User Bypass Option: During the sign-in prompt, users can typically click 'Sign in another way' to manually select the Microsoft Authenticator app if it is permitted by the policy.
Free Microsoft Office alternative

Try WPS Office for a Seamless, Local Workflow

While resolving complex Microsoft Entra ID and MFA cloud login issues, you may find yourself locked out of your cloud-based documents. WPS Office provides a robust, lightweight, and completely free alternative that allows you to easily edit your files locally without relying on complicated enterprise cloud authentication.

  1. 1. Download the Installer: Visit the official WPS website and click 'Download WPS Office Free' to get the latest version.
  2. 2. Install the Software: Run the downloaded installer and follow the quick setup wizard to install the suite on your computer.
  3. 3. Open Your Files Instantly: Launch WPS Office and open your existing Word, Excel, or PowerPoint documents to continue working immediately.
Fully compatible with Microsoft Office formats including DOCX, XLSX, and PPTX.Edit local documents seamlessly without requiring complex MFA sign-ins or cloud connectivity.Lightweight installation with blazing fast startup times.Familiar, easy-to-use interface that makes migrating from Microsoft Office effortless.
microsoft office alternative - wps office

Frequently Asked Questions

Can users manually choose the Authenticator app if prompted for a security key?

Yes, if the Conditional Access policies allow it, users can click 'Sign in another way' on the login screen and select the Microsoft Authenticator app from their registered methods.

Why does Entra ID prioritize physical security keys over the Authenticator app?

Entra ID evaluates FIDO2 security keys as a stronger, phishing-resistant authentication method. If your tenant's Conditional Access policies are set to require high authentication strengths, the system will default to the most secure method available.

How can a user set Microsoft Authenticator as their default sign-in method?

Users can navigate to the 'Security info' section of their My Sign-Ins portal (mysignins.microsoft.com). From there, they can select 'Default sign-in method' and change it to Microsoft Authenticator, provided organizational policies permit it.

Does WPS Office require a Microsoft Entra ID account to function?

No, WPS Office operates independently and does not require a Microsoft Entra ID or Microsoft account to function. It allows you to create, edit, and save documents locally without any enterprise cloud login dependencies.