logo
search
MFA Security Issues

Fix Microsoft 365 MFA Permissions Error with FIDO2 Login

Maira MehtabMaira Mehtab Sep 27, 2026 869 views

Question details

A Microsoft 365 Global Administrator break-glass account successfully logs in using password and phone authentication but encounters a permissions error when attempting to authenticate using a FIDO2 security key.

Product
Microsoft 365
Device & OS
not provided
Scenario
Logging into a Microsoft 365 break-glass Global Administrator account using different multi-factor authentication methods.
Observed behavior
The administrator account functions correctly with phone authentication but throws a permissions error when a FIDO2 security key is used.
Before you start

Ensure you have access to an alternative Global Administrator account to review your tenant's security settings and avoid getting locked out while troubleshooting the break-glass account.

Solution 1Recommended

Review Entra ID Policies and Consult Microsoft Support

Verify your Conditional Access settings and contact the Microsoft Entra support community to align FIDO2 authentication permissions.

Differences in authentication success between phone and FIDO2 methods usually stem from how Conditional Access policies and Authentication Method policies are configured in Microsoft Entra ID (formerly Azure AD). A break-glass account must be explicitly excluded from restrictive policies, and FIDO2 must be properly enabled for the tenant.

1
Check Authentication Methods

Sign in to the Microsoft Entra admin center as an administrator. Go to Protection > Authentication methods > Policies and verify that 'FIDO2 security key' is enabled and applies to the break-glass account.

2
Review Conditional Access Policies

Navigate to Protection > Conditional Access. Ensure that your break-glass account is explicitly excluded from policies that might block FIDO2 tokens (such as location-based or device-compliance policies).

3
Contact Microsoft Entra Support

If policies are correctly configured and the permissions error persists, open a support ticket with the dedicated Microsoft Entra or MFA support community for specialized investigation into the FIDO2 configuration.

Best Practice: Emergency access (break-glass) accounts should ideally have their credentials and security keys stored securely offline, and their usage should be heavily monitored via Entra ID audit logs.
Free Microsoft Office alternative

Try WPS Office for a Seamless and Free Productivity Experience

While you troubleshoot complex Microsoft 365 administration and MFA issues, consider using WPS Office for your local and daily productivity needs. WPS Office is a lightweight, highly compatible, and free alternative to Microsoft Office that lets you handle documents, spreadsheets, and presentations without being blocked by complex cloud authentication setups.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install WPS Office: Run the setup file and follow the quick on-screen instructions to install the suite.
  3. 3. Open Your Documents: Launch WPS Office and instantly open and edit your existing Word, Excel, and PowerPoint files.
Highly compatible with Microsoft Office formats (.docx, .xlsx, .pptx).Lightweight suite that installs quickly and runs smoothly on all devices.Familiar user interface requiring no learning curve for Microsoft Office users.Allows for efficient local document editing without mandatory cloud MFA setups.
microsoft office alternative - wps office

Frequently Asked Questions

Why does my FIDO2 key fail when phone authentication works?

This discrepancy typically occurs because Conditional Access or Authentication Method policies in Microsoft Entra ID have different restrictions for physical security keys versus phone authenticators. For example, a policy might require a compliant device, which a FIDO2 token alone cannot satisfy.

What is a break-glass account in Microsoft 365?

A break-glass account is an emergency access Global Administrator account used specifically when standard administrative accounts are locked out or inaccessible. It is usually excluded from strict Conditional Access policies to guarantee access during an emergency.

How do I enable FIDO2 security keys in my Microsoft 365 tenant?

To enable FIDO2 keys, an administrator must log in to the Microsoft Entra admin center, navigate to Protection > Authentication methods > Policies, select 'FIDO2 security key', and switch the toggle to 'Enable' for the desired users or groups.