Fix Microsoft 365 MFA Permissions Error with FIDO2 Login
Question details
A Microsoft 365 Global Administrator break-glass account successfully logs in using password and phone authentication but encounters a permissions error when attempting to authenticate using a FIDO2 security key.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Logging into a Microsoft 365 break-glass Global Administrator account using different multi-factor authentication methods.
- Observed behavior
- The administrator account functions correctly with phone authentication but throws a permissions error when a FIDO2 security key is used.
Ensure you have access to an alternative Global Administrator account to review your tenant's security settings and avoid getting locked out while troubleshooting the break-glass account.
Review Entra ID Policies and Consult Microsoft Support
Verify your Conditional Access settings and contact the Microsoft Entra support community to align FIDO2 authentication permissions.
Differences in authentication success between phone and FIDO2 methods usually stem from how Conditional Access policies and Authentication Method policies are configured in Microsoft Entra ID (formerly Azure AD). A break-glass account must be explicitly excluded from restrictive policies, and FIDO2 must be properly enabled for the tenant.
Sign in to the Microsoft Entra admin center as an administrator. Go to Protection > Authentication methods > Policies and verify that 'FIDO2 security key' is enabled and applies to the break-glass account.
Navigate to Protection > Conditional Access. Ensure that your break-glass account is explicitly excluded from policies that might block FIDO2 tokens (such as location-based or device-compliance policies).
If policies are correctly configured and the permissions error persists, open a support ticket with the dedicated Microsoft Entra or MFA support community for specialized investigation into the FIDO2 configuration.
Try WPS Office for a Seamless and Free Productivity Experience
While you troubleshoot complex Microsoft 365 administration and MFA issues, consider using WPS Office for your local and daily productivity needs. WPS Office is a lightweight, highly compatible, and free alternative to Microsoft Office that lets you handle documents, spreadsheets, and presentations without being blocked by complex cloud authentication setups.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick on-screen instructions to install the suite.
- 3. Open Your Documents: Launch WPS Office and instantly open and edit your existing Word, Excel, and PowerPoint files.

Frequently Asked Questions
Why does my FIDO2 key fail when phone authentication works?
This discrepancy typically occurs because Conditional Access or Authentication Method policies in Microsoft Entra ID have different restrictions for physical security keys versus phone authenticators. For example, a policy might require a compliant device, which a FIDO2 token alone cannot satisfy.
What is a break-glass account in Microsoft 365?
A break-glass account is an emergency access Global Administrator account used specifically when standard administrative accounts are locked out or inaccessible. It is usually excluded from strict Conditional Access policies to guarantee access during an emergency.
How do I enable FIDO2 security keys in my Microsoft 365 tenant?
To enable FIDO2 keys, an administrator must log in to the Microsoft Entra admin center, navigate to Protection > Authentication methods > Policies, select 'FIDO2 security key', and switch the toggle to 'Enable' for the desired users or groups.




