Discovered after trying to sign-into MS that the FIDO2 key was removed


  1. Posts : 145
    Windows 10 Home
       #1

    Discovered after trying to sign-into MS that the FIDO2 key was removed


    I don't use my Microsoft account for many services but when I need to sign-in to my MS account to use those, I've always been able to sign-in with the security key by Yubico. Its the blue key w/ a gold circle. I use a local account which suffices for most of the things I do on the desktop without needing to sign-in to MS

    The key was added to my account and set up using Edge way back when it first became Microsoft compliant. I discovered yesterday when trying to sign-in to MS using the security key that my key wasn't listed in the advanced security options any longer with the other verification options. No one else uses my desktop or has access to it or to any of my service accounts. The account was protected w/ 2-step verification using the authenticator. I do not believe the account was breached at all with these security measures that've been in place for years.

    The problem runs deeper than this though. After I discovered that the key was no longer listed as one of the options, I went to Windows settings and selected the key as one of the sign-in options. I changed my PIN and proceeded to sign-in.

    I followed the MS support instructions and added the key back from the Edge browser.

    Yet after I saw the key was added with a check mark next to it as an additional verification option to use, I signed out of my account from Edge. I then attempted to sign-in again selecting the security key as the option. I'll receive slightly different messages now in the steps to sign-in using the key than what used to appear before.

    Its as though the key is detected, the authentication request is successful after inserting the key in the USB port, but after touching the gold flashing light to unlock the private key stored in the FIDO2 security key, the process appears to break down. Its almost as though the token request with my signed nonce by touching the flashing light either isn't sent or either isn't verified.

    There wouldn't be a reason to perform a reset on the key and return it back to factory default settings when the same key works flawlessly with all my other accounts ! aka, Google, etc, etc

    I was going to reach out to Yubico, but this isn't an issue with any other account. . . the process only fails signing-in to my MS account. An attempt to sign-in fails with Firefox as well. I don't use a Windows Hello PIN.

    [EDIT] : there are no stupid questions here on TenForums so I want to ask one. I don't see anywhere stating the need to select Passwordless account under the advanced security options for the authentication process to be set up correctly. If so, then I shouldn't be concerned that Passwordless account is turned Off. Correct ?
      My Computer

  2.   My Computer


  3. Posts : 23,494
    Win 10 Home ♦♦♦19045.4412 (x64) [22H2]
       #3

    I can't help with your issue... I've never used the things you mention.
    But when I saw the topic title and your avatar, this was the very first thing I thought of...



    Last edited by Ghot; 12 Dec 2022 at 14:20.
      My Computer


  4. Posts : 145
    Windows 10 Home
    Thread Starter
       #4

    security key for Passwordless login


    a FIDO2 security key is one option of Passwordless login. Attached is a screenshot showing the advanced security options after I had re-added the same key.

    Discovered after trying to sign-into MS that the FIDO2 key was removed-microsoft-account-security_verification-options.jpg

    It's unclear whether the Passwordless account setting should now show as being turned ON after I re-added the key and I'm unable to recall if the Passwordless account setting ever used to be turned ON before this mysterious disappearance of the FIDO2 key

    - - - Updated - - -

    After clicking on the link to the ArgonSystems web page posted by commenter - Louis on Super User, a section titled under "User registration of FIDO security keys" is referring to a user first needing to register a security key and add it as an authentication method in their security information page in Azure.

    I don't recall this being a required step when originally setting up the key in early 2019. Sorry, I'm somewhat confused as to needing to register using the Azure MFA method
      My Computer


  5. Posts : 9,777
    Mac OS Catalina
       #5
      My Computer


  6. Posts : 145
    Windows 10 Home
    Thread Starter
       #6

    bro67 said:
    Thank you @bro67
    I'll read more of these threads as I look farther into this. The thread about half way down titled
    "Mysterious MFA error when trying to add FIDO2 key: AADSTS90013: Invalid input received from the user" appears to best describe the problem. It does mention having at least one Azure AD Multi-Factor Authentication method registered.

    These are mostly all recent posts. The above mentioned is dated October of this year. Perhaps the MS support engineers have enforced a change which may be a possible explanation for what happened
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:17.
Find Us




Windows 10 Forums