Additional Microsoft Entra services and features related to identity, access, and network security
Error preventing MFA from being applied to breakglass account using a FIDO2 USB Key
Hi, We have an error when trying to use a Feitian ePass FIDO2 Security Key (FIDO2) to secure our breakglass account. It basically says our identity cannot be verified.
The background is that we are moving from on prem AD to hybrid Entra and are at the stage of configuring the breakglass account (in a Group called Emergency Access). We have P1 licensing. We have configured conditional access to replace the default security settings.
You can only register the key on the user account if you are already logged in with MFA. Temporarily adding OTP by SMS does not seem to be deemed a sufficient level of identification to add the key. It looks like it is going to work but ends with an error and the key is not added.
I seem to be going around in circles. Any advise, please?