MH IT SOLUTION — Production Tech Knowledge Base & IT Troubleshooting Guides ▶ YouTube Channel

Hardening Microsoft 365: Enforcing FIDO2 Passkeys & Conditional Access

MH IT SOLUTION Editorial Team · Updated August 18, 2026 · 9 min readAdvanced

Step-by-step enterprise guide to implementing phishing-resistant MFA, FIDO2 security keys, and Conditional Access in Microsoft Entra ID.

Step-by-Step Video Walkthrough   Watch on YouTube ↗

Common Symptoms and Quick Fixes

Symptom Likely Cause Quick Fix
Users still get SMS prompts FIDO2 method not enabled for the group Enable FIDO2 in Authentication methods
Key registers but sign-in is blocked No Conditional Access grant for the strength Require phishing-resistant strength in the policy
Admin locked out No emergency account excluded Keep two break-glass accounts out of the policy

Method 1: Enable the FIDO2 Authentication Method

Do this in the Microsoft Entra admin center and target a pilot group first.

1

Open Authentication methodsEntra admin center > Protection > Authentication methods > Policies > FIDO2 security key.
2

Enable and target a groupSet Enable to Yes, choose a pilot group, and allow self-service setup.
3

Register a keyUsers go to mysignins.microsoft.com/security-info and add a Security key.

Method 2: Require Phishing-Resistant MFA

Create a Conditional Access policy in report-only mode first, then switch it on.

4

Create the policyProtection > Conditional Access > New policy. Assign the pilot group and All cloud apps.
5

Set the grantGrant > Require authentication strength > Phishing-resistant MFA.
6

Keep break-glass accounts outExclude two emergency admin accounts so you cannot lock yourself out.
Pro Tip for AdministratorsRun in Report-only for a week and review the sign-in logs before enforcing.

Frequently Asked Questions (FAQ)

Q: Do users need a hardware key?

Not always. Passkeys in Microsoft Authenticator also count as phishing-resistant.

Q: What if a user loses a key?

Register a second key per user and keep a Temporary Access Pass process for recovery.

Leave a Reply

Your email address will not be published. Required fields are marked *