Known Issue: Unable to use a passkey to sign-in

Summary

Passkeys stored on a mobile device can only be used for cross-device authentication when Bluetooth communication between the computer and the mobile device is available. On shared or public computers where Bluetooth is disabled, unavailable, or restricted, users should use Microsoft Authenticator push notifications or another registered authentication method to complete MFA.

Body

Issue

A user has already registered a passkey and has been removed from the SMS MFA exemption group, meaning SMS can no longer be used to satisfy multifactor authentication (MFA).

When signing in on a shared or public workstation (for example, a classroom computer, computer lab workstation, or kiosk device), the user enters their password and is unexpectedly prompted with the message:

"Insert your security key into the USB port."

The user has never registered a physical FIDO2 security key and was expecting to see a QR code that would allow them to use their passkey from their mobile device.


Root Cause

This issue most commonly occurs when the computer being used does not have Bluetooth enabled or available.

Cross-device passkey authentication relies on Bluetooth to establish a secure connection between the workstation and the user's mobile device. When Bluetooth is unavailable, the sign-in process cannot offer the QR code-based passkey experience and may instead default to requesting a physical security key.


Resolution

To authenticate on computers that do not support Bluetooth-based passkey sign-in, users should register Microsoft Authenticator push notifications as an additional authentication method.

Register Microsoft Authenticator

  1. Install the Microsoft Authenticator app from the Apple App Store or Google Play Store.
  2. Open Microsoft Authenticator and sign in with your University of Windsor account.
  3. When prompted, authenticate using your existing passkey.
  4. Complete the registration process and enable push notifications for your account.
  5. Retry signing in on the workstation and choose Microsoft Authenticator notification as the MFA method.
  6. Approve the sign-in request on your mobile device to complete authentication.

Additional Information

Passkeys stored on a mobile device can only be used for cross-device authentication when Bluetooth communication between the computer and the mobile device is available. On shared or public computers where Bluetooth is disabled, unavailable, or restricted, users should use Microsoft Authenticator push notifications or another registered authentication method to complete MFA.

Details

Details

Article ID: 151793
Created
Wed 10/7/26 1:04 PM
Modified
Wed 10/7/26 1:06 PM