Error adding Yubikey to Security Info

James 26 Reputation points
2019-12-23T14:27:20.263+00:00

Hi, I am following the Ms docs for going passwordless however, when I add my Security Key (add method) on the myprofile page I get the error below after naming it

We detected that this particular key type has been blocked by your organization. Contact your administrator for more details and try registering a different type of key.

Any ideas?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,562 questions
{count} vote

Accepted answer
  1. Pavel Otych 81 Reputation points
    2019-12-23T19:45:41.977+00:00

    Hi, I suggest you check Authentication Methods in Azure and have a look at Key Restriction Policy -> "Enforce key restrictions" should be se to "No" unless you're limiting usage to specific keys.

    What kind of Yubikey are using? If it's an older model you can try to disable "Enforce attestation" if the above doesn't help. This disables the requirement for trusted certificate usage and will allow self-signed certificate of the key itself.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Rendy Laurens 1 Reputation point
    2019-12-30T12:12:03.177+00:00

    I have add the AAGUID in Azure.

    Go to authentication methods - Authentication method policy

    Azure AD - Security - authentication methods.
    Go to FIDO2 Security Key.

    Enforce attestation
    YES

    And

    Restrict specific keys
    ALLOW


    And for the AAGUID check this website
    https://support.yubico.com/support/solutions/articles/15000028710-yubikey-hardware-fido2-aaguids