MFA authentication

mike wanaoni 0 Reputation points
2026-10-11T05:02:25.28+00:00

I enforced passkey authentication but i had not set up a passkey, so getting back to the account through password is impossible, it falls back to passkey and says not found

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-11T05:04:06.63+00:00

    Another Microsoft Entra administrator must issue a Temporary Access Pass (TAP) so you can register the first passkey; if no administrator, emergency account, or authenticated admin session remains, open a tenant-lockout case with Microsoft Support.

    If another administrator can access the tenant

    The affected account cannot create its own TAP. Before issuing one, the administrator should check Entra admin center → Entra ID → Monitoring & health → Sign-in logs for the failed attempt and review its Conditional Access details.

    If an authentication-strength or Conditional Access policy blocks the security-information registration flow, TAP alone might not resolve the loop. Temporarily correct that policy or exclude only the affected account, then issue the TAP. An exclusion reduces account protection: limit it to this account, keep it active only for recovery, monitor sign-ins, and remove it immediately afterward. Passkey registration failures should also be investigated through audit logs.^1^

    Then perform these steps:

    1. Enable TAP for the affected account
      • Sign in to the Microsoft Entra admin center.
      • Go to Entra ID → Authentication methods → Policies → Temporary Access Pass.
      • Select Enable, include the affected user or an appropriate group, and save.
      • Updating this policy requires at least Authentication Policy Administrator.^2^
    2. Create the TAP
      • Go to Entra ID → Users → affected user → Authentication methods.
      • Select Add authentication method → Temporary Access Pass.
      • Set its activation and duration, select Add, and securely record the displayed TAP—the value cannot be viewed again after closing the dialog.
      • An Authentication Administrator can issue one for a member; a Privileged Authentication Administrator can issue one for members or administrators. Neither can issue a TAP to themselves.^2^
    3. Register the passkey
      • Open https://mysignins.microsoft.com/security-info.
      • Enter the affected account’s user principal name and then the TAP.
      • Select Add sign-in method and register the passkey.
      • With a single-use TAP, complete registration within 10 minutes of signing in. If necessary, issue another TAP.^2^

    If you still have another previously registered MFA method, it can instead bootstrap the first passkey without a TAP.^3^

    After access is restored:

    • Remove any temporary Conditional Access exclusion and confirm the intended authentication policy applies again.
    • Review the account’s sign-in logs for unexpected access.
    • Register at least two authentication methods so loss of one does not cause another lockout.^3^

    If this is the only administrator account

    Check first for an excluded emergency/break-glass administrator, another Global or Privileged Role Administrator, partner administrative access, or an already authenticated admin browser session. Do not sign out of any working session.

    If none exists, this is a full tenant lockout and cannot be repaired by resetting the password: open a case with Microsoft Support and describe it as:

    Complete Microsoft Entra tenant lockout after enforcing passkey authentication; no registered passkey and no accessible administrator or emergency account.

    When portals are inaccessible, Microsoft documents using its customer-service phone channel. Microsoft performs high-assurance tenant-ownership verification and then helps designated Global Administrators recover access to the existing tenant.^4^


    References

    1. Perform account recovery in Microsoft Entra ID
    2. Configure Temporary Access Pass to register passwordless authentication methods
    3. Plan a phishing-resistant passwordless authentication deployment in Microsoft Entra ID
    4. Plan for tenant recoverability
    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.