logo
search
MFA Security Issues

Fix Microsoft Entra Defaulting to Security Key for MFA

John WilsonJohn Wilson Sep 28, 2026 869 views

Question details

Users are prompted to use a security key by default during sign-in, overriding other registered methods like the Microsoft Authenticator app.

Fix Microsoft Entra Defaulting to Security Key for MFA
Product
Microsoft Entra
Device & OS
not provided
Scenario
Users attempting to sign in using Multi-Factor Authentication (MFA) are forced to manually switch from the default security key prompt to their preferred method.
Observed behavior
Microsoft Entra defaults to prompting for a security key, even when Microsoft Authenticator and a YubiKey are registered, forcing users to click 'select other sign-in methods'.
Before you start

Ensure you are logged in to the Microsoft Entra admin center with at least the Authentication Policy Administrator role to review and modify tenant-level authentication settings.

Solution 1Recommended

Review Authentication Method Policies and Conditional Access

Verify if Conditional Access policies or Authentication Strengths are forcing phishing-resistant methods (like FIDO2 security keys) as the default.

Microsoft Entra uses Authentication Strengths to determine which MFA methods are acceptable. If a Conditional Access policy requires 'Phishing-resistant MFA', Entra will prioritize security keys over standard Authenticator push notifications.

1
Access Entra Security Settings

Log in to the Microsoft Entra admin center and navigate to 'Protection' > 'Authentication methods'.

2
Check Authentication Strengths

Review the 'Authentication strengths' policies to see if a strict phishing-resistant requirement is applied to the affected users.

3
Review Conditional Access Policies

Go to 'Protection' > 'Conditional Access' and check if any active policies scoped to these users mandate FIDO2/security keys.

4
Verify Temporary Access Pass Settings

Ensure that Temporary Access Pass (TAP) configurations are not overriding standard MFA registrations during the onboarding flow.

Review Authentication Method Policies and Conditional Access
System Preference Behavior: Microsoft Entra introduced system-preferred multifactor authentication, which automatically prompts users with the most secure method they have registered. FIDO2 security keys rank higher than Authenticator push notifications.
Free Microsoft Office alternative

Looking for a Secure and Free Office Suite?

While resolving Microsoft Entra identity and MFA configurations, consider WPS Office as a lightweight, secure, and free alternative to Microsoft Office. It offers robust local document editing without complex cloud identity dependencies.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install WPS Office: Run the downloaded installer and follow the on-screen instructions to complete the setup.
  3. 3. Open and Edit Microsoft Formats: Launch WPS Office and directly open your existing Word, Excel, or PowerPoint files with perfect formatting preservation.
Completely free, lightweight, and easy to deploy across your organizationSeamlessly compatible with Microsoft Office file formats (.docx, .xlsx, .pptx)Built-in robust PDF editor and advanced document security featuresFamiliar user interface requiring zero learning curve for seamless migration
microsoft office alternative - wps office

Frequently Asked Questions

Why does Microsoft Entra prioritize security keys over the Authenticator app?

Through a feature called system-preferred multifactor authentication, Entra automatically prompts users with the most secure authentication method they have registered. FIDO2 security keys are considered phishing-resistant and rank higher in security than standard Authenticator push notifications.

Can individual users change their default sign-in method?

Yes, users can manage their default sign-in method by navigating to the 'Security info' page in their Microsoft 'My Account' portal and selecting their preferred default authentication option.

Why does enrolling a security key require the Authenticator app first?

To register a highly privileged credential like a FIDO2 security key, Microsoft requires the user to prove their identity using a previously established strong authentication method, which is often the Microsoft Authenticator app or a Temporary Access Pass (TAP) issued by an administrator.