Fix FIDO2 Security Key Option Not Showing in Microsoft Entra ID
Question details
The FIDO2 security key option is unavailable for users despite having multifactor authentication (MFA) and the FIDO2 policy enabled.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Configuring user authentication methods and security key login in Microsoft Entra ID.
- Observed behavior
- FIDO2 security keys do not appear as an available authentication option for users during the sign-in or security setup process.
Ensure you have Global Administrator or Authentication Policy Administrator privileges in your Microsoft Entra ID tenant before reviewing and modifying security configurations.
Consult Microsoft Entra Specialists via Microsoft Q&A
Because backend synchronization delays or specific tenant policy conflicts can hide FIDO2 options, escalating to Microsoft Entra specialists is the most effective approach to resolve this configuration issue.
Microsoft Entra ID relies on a complex hierarchy of conditional access and authentication method policies. If the FIDO2 key is enabled but not visible, it often requires tenant-level investigation by Microsoft support engineers or community experts.
Document your current Authentication methods policy for FIDO2. Note the targeted user scope (e.g., All users or specific groups) and check if any specific AAGUIDs (Authenticator Attestation GUIDs) are restricted.
Open your web browser and visit the official Microsoft Q&A community platform where Azure and Entra ID specialists provide support.
When creating a new question, apply the 'Azure' or 'Microsoft Entra ID' tags to ensure your query is routed to the correct product specialists.
Include your gathered policy configurations and clearly state that the FIDO2 option remains hidden despite the policy and MFA being enabled. Submit the post for investigation.

Switch to WPS Office for a Streamlined Document Experience
While managing complex enterprise configurations like Microsoft Entra ID authentication can be challenging, managing your documents doesn't have to be. WPS Office offers a lightweight, highly compatible alternative to Microsoft Office that is easy to deploy and use without complex backend licensing.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install the Software: Run the downloaded installer file and follow the simple on-screen instructions.
- 3. Start Creating: Launch WPS Office and immediately begin working on your documents, spreadsheets, and presentations.

Frequently Asked Questions
Why is my FIDO2 security key policy enabled but not applying to users?
This frequently occurs if the user is not included in the allowed scope of the Authentication methods policy, or if there is a direct conflict with legacy MFA policies that override the newer settings.
Can I restrict FIDO2 security keys to specific manufacturers in Entra ID?
Yes, Microsoft Entra ID allows administrators to configure FIDO2 policies to restrict usage to specific Authenticator Attestation GUIDs (AAGUIDs), ensuring only approved hardware models can be registered.
How long does it take for FIDO2 policy changes to take effect?
Policy changes in Microsoft Entra ID can sometimes take up to 15 to 30 minutes to propagate across all user sessions and sign-in interfaces globally.




