A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Yes. This usually happens when the passkey was created locally on the phone but was not fully registered, or when the iPhone is not configured to let Microsoft Authenticator act as the passkey provider.
Try this end-to-end cleanup and re-registration flow on the iPhone:
- Confirm device support.
- iPhone must be running iOS 17 or later.
- Check iPhone passkey provider settings.
- On iOS 18: go to Settings > General > Autofill & Passwords.
- On iOS 17: go to Settings > Passwords > Password Options.
- Make sure AutoFill Passwords and Passkeys is turned on.
- Under Autofill From, make sure Authenticator is selected.
- In Microsoft Authenticator, remove any failed local passkey.
- Open Authenticator.
- Tap the account.
- Tap Settings > Delete passkey.
- This is important if the app shows that the passkey already exists or a previous attempt partially completed.
- Remove the stale server-side entry if it still exists.
- Go to Security info at https://mysignins.microsoft.com/security-info.
- If a passkey entry exists for that phone attempt, delete it there too.
- Recreate the passkey using the recommended flow.
- Open Microsoft Authenticator on the iPhone.
- Add the work or school account if it is not already there, or open the existing account.
- Tap Create a passkey.
- Complete MFA.
- If prompted, set up a screen lock.
- When prompted, enable Authenticator as the passkey provider.
- Return to Authenticator and finish the setup.
- If creation still fails, use the browser-based Security info flow instead.
- Sign in with MFA to Security info.
- Select + Add sign-in method > Passkey in Microsoft Authenticator.
- Follow the prompts to open Authenticator and complete setup there.
- If the failure happens only during cross-device setup, verify these prerequisites.
- Both devices must have Bluetooth enabled.
- Both devices must be in range and connected to the internet.
- They do not need to be on the same network.
- If the phone is new, create the new passkey first and only then remove old passkeys.
- A passkey from the PC is separate from the iPhone setup.
- After the new iPhone passkey works, remove obsolete passkeys.
Two common causes match this exact symptom:
- The passkey was stored locally in Authenticator, but registration on the authentication server timed out or was blocked.
- Authenticator was not enabled as the iPhone passkey provider.
If the error changes to “the passkey already exists”, delete the local Authenticator passkey and retry registration.
- Register passkeys in Authenticator on Android and iOS devices
- Register passkeys in Authenticator on Android and iOS devices
- Troubleshoot signing in with a passkey
- Troubleshoot signing in with a passkey
- Set up a passkey in Microsoft Authenticator
- Transfer Microsoft Authenticator account entries to a new phone