TFA required but the app no longer displays passkeys

Sarah H 0 Reputation points
2026-03-09T20:11:02.4666667+00:00

TFA is required for me to access an ArcGIS online account that is outside my organization. In the past, I would sign in, a passkey would be sent to the app, and I’d be able to log in. Now, nothing ever shows up in the app. The AGOL account managers tried to have me set up my account again, but to do so requires TFA. I don’t know if this is an account connectivity issue or what but I need to be able to access this AGOL.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-09T20:11:18.5033333+00:00

    Follow these steps to regain access when two-factor prompts or passkeys no longer appear in Microsoft Authenticator:

    1. Confirm what the ArcGIS account is asking for
      ArcGIS Online can be configured to use:
      • Time-based one-time passcodes (6‑digit OTP), or
      • Passwordless/passkey (FIDO2) sign-in via Microsoft Authenticator.
      When prompted to sign in, check whether the page explicitly asks for:
      • A 6‑digit code from an authenticator app, or
      • Approval of a notification / passkey (face, fingerprint, PIN) on the device.
    2. Open Microsoft Authenticator and check the account entry
      • Open the app and tap the ArcGIS-related account entry.
      • If there is a line like “One-time password code” with a 6‑digit code, use that code on the ArcGIS sign-in page.
      • If there is no one-time password code and no passkey prompt appears when signing in, the registration for that account may be incomplete or removed.
    3. Check for orphaned or invalid passkeys
      If the ArcGIS sign-in is using a passkey (FIDO2) and the passkey was removed or invalidated on the identity provider side, the credential stored on the device becomes an orphaned passkey. In that case:
      • Remove the old passkey or account entry related to that ArcGIS login from the Authenticator app or from the device’s passkey manager.
      • After cleanup, the account owner (ArcGIS Online tenant admin) must re-register a new passkey for the account.
    4. If the account is locked behind MFA and cannot be re-registered
      Because the ArcGIS Online account is outside the organization and requires MFA to even start reconfiguration, only the ArcGIS Online tenant administrators or the identity provider admins (for example, Microsoft Entra ID admins, if that’s what backs the ArcGIS account) can:
      • Reset the MFA settings for that user, or
      • Remove the current Authenticator registration and allow re-registration.
      If there is no alternative admin path for the ArcGIS tenant, the tenant’s support team must open a support ticket with their identity provider’s Data Protection / account recovery team to reset MFA, similar to how tenant lockouts are handled when an admin loses access to Microsoft Authenticator.
    5. If nothing appears in Authenticator at all
      • Ensure the app is updated to the latest version and that notifications are allowed.
      • If the ArcGIS login is using passkeys via cross-device authentication (for example, browser on PC + phone), make sure Bluetooth and internet connectivity are enabled on both devices, as required for passkey cross-device flows.
      • If prompts still never arrive and no OTP is visible, the registration is almost certainly broken and must be reset by the ArcGIS/IdP admin as described above.

    In summary, the ArcGIS Online administrators (or their identity provider admins) must reset the MFA / passkey registration for that external account so a new Microsoft Authenticator registration or passkey can be created. Until that reset is done, sign-in will remain blocked because the existing passkey or OTP configuration is no longer valid.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.