A cloud-based identity and access management service for securing user authentication and resource access
Passkey registration fails at final verification with ErrorCode 4 due to duplicate UPN/proxyAddress in Entra ID
Problem
I encountered an issue where passkey registration appeared to work almost completely:
- the passkey was successfully created in Microsoft Password Manager
- I could name the passkey
- the passkey was saved locally/synced
- but the final registration step in My Sign-ins failed
The browser trace showed that the failure happened during:
POST https://mysignins.microsoft.com/api/authenticationmethods/verify
with:
{
"Type": 18,
"VerificationState": 3,
"DataUpdates": null,
"ErrorCode": 4,
"ErrorType": null
}
Root cause
In my case, the issue was caused by a duplicate identity reference in Microsoft Entra ID.
The account I was registering the passkey for had:
********@contoso.com **as its userPrincipalName.
However, another user object also had:
smtp:****@contoso.com **configured in its proxyAddresses.
This created an ambiguity when Microsoft services attempted to resolve the identity.
How to check
You can check whether the UPN exists as a proxy address on another account:
Get-MgUser `
-Filter "proxyAddresses/any(x:x eq 'smtp:******@contoso.com')" `
-Property Id,DisplayName,UserPrincipalName,ProxyAddresses |
Select-Object Id,DisplayName,UserPrincipalName,ProxyAddresses
Then check the actual account using the same address as its UPN:
Get-MgUser `
-Filter "userPrincipalName eq '******@contoso.com'" `
-Property Id,DisplayName,UserPrincipalName |
Select-Object Id,DisplayName,UserPrincipalName
If those queries return two different user objects, you have an identity conflict.
Solution
I removed the duplicate proxy address from the other user account.
In a hybrid environment, make the change on the authoritative on-premises AD object and let Entra Connect synchronize it.
After the duplicate proxyAddress was removed and the change had propagated to Entra ID, passkey registration worked immediately.