A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Based on the described behavior, the passkey is likely being created locally on the device but not successfully registered on the authentication server, which then causes the error at the final “Done” step.
Use these steps to clear the bad passkey entries and retry:
- Delete any locally stored passkeys in Microsoft Authenticator
- On Android: Open Microsoft Authenticator → tap the account name → Settings → Delete passkey.
- On iOS: Open Microsoft Authenticator → tap the account name → Settings → Delete passkey.
Repeat for any passkeys that show for this work account.
- Delete any server-side passkeys for this account
- Go to your account’s Security info page (for work or school, this is typically under Security info / My Security info).
- Find any passkey/FIDO2 or Authenticator passkey entries for this account and select Delete for each one.
This ensures there are no partially registered or invalid passkeys.
- Register the passkey again from scratch
- Start from the official Security info / My Security info page for the account and choose to add a passkey.
- When using cross‑device registration on Android, ensure:
- Bluetooth is enabled on both the device where the sign‑in/registration is started and the mobile device.
- Both devices are in range and connected to the internet.
- Follow the prompts until the device says the passkey was created and you are returned to the Security info page.
- When prompted, give the passkey a name and select Done.
- If the same error appears again
- Immediately go back into Authenticator and delete the newly created passkey (as in step 1).
- Then delete any corresponding passkey entries that may have appeared in Security info (step 2).
- Retry registration once more.
- If the organization is blocking the passkey provider or cross‑device use
- Some organizations do not allow authenticating or registering passkeys via Bluetooth/cross‑device flows or specific passkey providers. In that case, an admin must review and adjust the passkey configuration for the tenant.
- Provide the correlation ID and timestamp already captured to the organization’s Microsoft Entra administrator so they can check Entra sign‑in and audit logs and, if needed, open a support case with Microsoft.
Even if Microsoft Authenticator MFA is already set up, the organization can still require a separate passkey registration for passwordless sign‑in; this is expected behavior in some security configurations.
References: