Microsoft account online starts asking for a USB security key even though I never used any

Filippo bandini 60 Reputation points
2026-05-06T12:14:26.87+00:00

I have several authentication methods set up on my Microsoft (https://account.live.com/) account, including a Samsung passkey, but I definitely do not have any USB passkey configured.

Recently, Microsoft has started prompting me to use a USB passkey by default, even though I have never set one up. When I try to add a new authentication method—such as face recognition, fingerprint, PIN, or a passkey—the system immediately asks for a USB passkey.

I can still sign in using my password and SMS verification, but this behavior seems incorrect. It appears to be a bug, as the system is requesting a USB passkey that is not configured in my account.

Microsoft 365 and Office | Subscription, account, billing | Other | Windows

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-06T12:14:50.7366667+00:00

    The behavior is consistent with how Microsoft now prioritizes passkeys/FIDO2 security keys once any passkey method is present, even if no USB key was explicitly registered.

    Key points from current behavior and documentation:

    1. Passkeys and security keys are treated as the same sign-in category
      • Passkeys (including platform passkeys like Samsung/Android, Windows Hello, etc.) and FIDO2 USB/NFC security keys are surfaced under the same option: “Face, fingerprint, PIN, or security key”.
      • When a passkey has been used recently, Microsoft services can default to a passkey/FIDO2 flow instead of password, and the browser/OS then decides which authenticator to offer (platform passkey, phone, or USB/NFC key).
      • For work/school accounts, if a passkey was last used, the sign-in page automatically prompts for Face, fingerprint, PIN, or security key without asking for a password first. This is described for Entra ID, but the same UX pattern is used for Microsoft accounts.
    2. Why a “USB key” prompt appears even if none was set up
      • The browser/OS WebAuthn dialog is generic and supports multiple authenticators (built‑in passkey on phone/PC, external USB key, NFC key). The UI often mentions inserting or using a “security key” even when the actual available authenticator is a platform passkey (such as Samsung passkey or Windows Hello).
      • Because a passkey is already registered on the account, the sign-in flow prefers this passwordless method and immediately triggers the WebAuthn dialog, which may visually emphasize USB keys even though the same dialog is used for platform passkeys.
    3. Adding new methods but being forced into the USB/passkey dialog
      • When Add a new way to sign in or verify is selected and Face, Fingerprint, PIN, or Security Key is chosen, the system intentionally launches the passkey/FIDO2 flow first. This is by design for passwordless-first accounts.
      • Some sensitive changes (like adding phone numbers or certain security info) may still require entering the account password explicitly, even if passkeys are enabled. This is expected and documented: a password continues to exist “in the background” and is required for some operations.
    4. How to work around and stabilize sign-in
      • Ensure at least one non-passkey method is fully configured and working (e.g., password + SMS or Microsoft Authenticator). For example, set up Microsoft Authenticator as an additional method and use it when the passkey dialog is confusing or unavailable.
      • When the sign-in page appears, explicitly choose Other ways to sign in or Sign-in options, then select Password or SMS instead of Face, fingerprint, PIN, or security key. This bypasses the passkey dialog.
      • If a passkey on a device has become “orphaned” (stored locally but no longer valid in the account directory), it can cause confusing prompts. In that case, remove the passkey from the device/authenticator and re-register a fresh passkey:
        1. Remove the old passkey from the device or passkey authenticator.
        2. Re-register a new passkey from the account’s security/advanced security page.
    5. When this is likely a real issue
      • If no passkey/security key is listed under the account’s security info but the sign-in page still insists on a USB key and does not allow switching to Other ways to sign in, this can indicate an orphaned or stale credential on the device side. Cleaning up local passkeys and re-adding them, or using another browser/device to adjust security info, is the recommended path.

    In summary, the prompt for a “USB security key” is a generic passkey/FIDO2 dialog that appears once any passkey is present and recently used. It does not necessarily mean a USB key was configured, and the account can still be accessed via password/SMS or other methods by choosing Other ways to sign in and, if needed, re-registering passkeys.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    4 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.