logo
search
MFA Security Issues

Fix FIDO2 Security Key Option Not Showing in Microsoft Entra ID

Huda QurayshiHuda Qurayshi Sep 30, 2026 869 views

Question details

The FIDO2 security key option is unavailable for users despite having multifactor authentication (MFA) and the FIDO2 policy enabled.

How to Fix FIDO2 Security Key Option Not Showing in Microsoft Entra ID
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Configuring user authentication methods and security key login in Microsoft Entra ID.
Observed behavior
FIDO2 security keys do not appear as an available authentication option for users during the sign-in or security setup process.
Before you start

Ensure you have Global Administrator or Authentication Policy Administrator privileges in your Microsoft Entra ID tenant before reviewing and modifying security configurations.

Solution 1Recommended

Consult Microsoft Entra Specialists via Microsoft Q&A

Because backend synchronization delays or specific tenant policy conflicts can hide FIDO2 options, escalating to Microsoft Entra specialists is the most effective approach to resolve this configuration issue.

Microsoft Entra ID relies on a complex hierarchy of conditional access and authentication method policies. If the FIDO2 key is enabled but not visible, it often requires tenant-level investigation by Microsoft support engineers or community experts.

1
Gather Configuration Details

Document your current Authentication methods policy for FIDO2. Note the targeted user scope (e.g., All users or specific groups) and check if any specific AAGUIDs (Authenticator Attestation GUIDs) are restricted.

2
Navigate to Microsoft Q&A

Open your web browser and visit the official Microsoft Q&A community platform where Azure and Entra ID specialists provide support.

3
Select the Appropriate Category

When creating a new question, apply the 'Azure' or 'Microsoft Entra ID' tags to ensure your query is routed to the correct product specialists.

4
Submit Your Request

Include your gathered policy configurations and clearly state that the FIDO2 option remains hidden despite the policy and MFA being enabled. Submit the post for investigation.

Consult Microsoft Entra Specialists via Microsoft Q&A
Include User Scope: Always mention the specific user scope affected in your forum post. Sometimes, overlapping legacy MFA policies can exclude certain groups inadvertently.
Free Microsoft Office alternative

Switch to WPS Office for a Streamlined Document Experience

While managing complex enterprise configurations like Microsoft Entra ID authentication can be challenging, managing your documents doesn't have to be. WPS Office offers a lightweight, highly compatible alternative to Microsoft Office that is easy to deploy and use without complex backend licensing.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install the Software: Run the downloaded installer file and follow the simple on-screen instructions.
  3. 3. Start Creating: Launch WPS Office and immediately begin working on your documents, spreadsheets, and presentations.
Fully compatible with Microsoft Office formats including Word, Excel, and PowerPoint files.Lightweight installation that doesn't rely on complex cloud identity synchronizations.Familiar user interface with zero learning curve for rapid onboarding.Comprehensive document security and local encryption features built-in.
microsoft office alternative - wps office

Frequently Asked Questions

Why is my FIDO2 security key policy enabled but not applying to users?

This frequently occurs if the user is not included in the allowed scope of the Authentication methods policy, or if there is a direct conflict with legacy MFA policies that override the newer settings.

Can I restrict FIDO2 security keys to specific manufacturers in Entra ID?

Yes, Microsoft Entra ID allows administrators to configure FIDO2 policies to restrict usage to specific Authenticator Attestation GUIDs (AAGUIDs), ensuring only approved hardware models can be registered.

How long does it take for FIDO2 policy changes to take effect?

Policy changes in Microsoft Entra ID can sometimes take up to 15 to 30 minutes to propagate across all user sessions and sign-in interfaces globally.