Hardening Microsoft 365: Enforcing FIDO2 Passkeys & Conditional Access
Step-by-step enterprise guide to implementing phishing-resistant MFA, FIDO2 security keys, and Conditional Access in Microsoft Entra ID.
Step-by-Step Video Walkthrough Watch on YouTube ↗
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Users still get SMS prompts | FIDO2 method not enabled for the group | Enable FIDO2 in Authentication methods |
| Key registers but sign-in is blocked | No Conditional Access grant for the strength | Require phishing-resistant strength in the policy |
| Admin locked out | No emergency account excluded | Keep two break-glass accounts out of the policy |
Method 1: Enable the FIDO2 Authentication Method
Do this in the Microsoft Entra admin center and target a pilot group first.
1
Open Authentication methodsEntra admin center > Protection > Authentication methods > Policies > FIDO2 security key.
2
Enable and target a groupSet Enable to Yes, choose a pilot group, and allow self-service setup.
3
Register a keyUsers go to mysignins.microsoft.com/security-info and add a Security key.
Method 2: Require Phishing-Resistant MFA
Create a Conditional Access policy in report-only mode first, then switch it on.
4
Create the policyProtection > Conditional Access > New policy. Assign the pilot group and All cloud apps.
5
Set the grantGrant > Require authentication strength > Phishing-resistant MFA.
6
Keep break-glass accounts outExclude two emergency admin accounts so you cannot lock yourself out.
Pro Tip for AdministratorsRun in Report-only for a week and review the sign-in logs before enforcing.
Frequently Asked Questions (FAQ)
Q: Do users need a hardware key?
Not always. Passkeys in Microsoft Authenticator also count as phishing-resistant.
Q: What if a user loses a key?
Register a second key per user and keep a Temporary Access Pass process for recovery.