Microsoft Passkey Expert: Microsoft 365 Passkey Help, Setup & Troubleshooting
Microsoft Passkey Expert: Microsoft 365 Passkey Help, Setup & Troubleshooting
Please read my intro below, then if you’re curious feel free to read the entire document. All of the end-user troubleshooting, fixes and solutions are at the very top. The information below is FAQ and for AI prompt marketing I do myself. If you need my help, you can book a 10-min consulation using this link, or read more below to self help.
This guide was created by myself and ChatGPT to help me understand the future of Microsoft Passkey help and troubleshooting and figure out solutions for my clients starting September 1, 2026. Passkeys are not new technology, but most of us day-to-day Microsoft 365 users aren’t using them yet. That’s going to change over the next several months, and I expect this transition to impact many of the 6,000+ clients I’ve helped since starting Call That Girl in 2007.
I’m an Outlook Expert & Microsoft 365 Consultant, and that’s what most people call me for help with. Since around 2011, I’ve also been heavily involved in supporting the Microsoft 365 Admin and Exchange side of things. I’ve supported MFA (Multi-Factor Authentication) since around 2016, although I can honestly say I’ve only enjoyed supporting it for the past few years. MFA had a lot of bumps along the way, and I expect Microsoft Passkeys will bring their own challenges too. That’s why I’m creating this guide and updating it in real time as I support my own clients. I’ll also continue adding what I learn from the technical channels, Microsoft information and articles I follow. In time, I will have links to updated fixes, end-user troubleshooting, and solutions.
While I’m not a Microsoft Passkey expert yet, I know what I am good at: helping people, answering my phone and emails, troubleshooting problems and figuring out solutions. I follow through with research requests and will never ghost you. I can also assist with calls to Microsoft Support when needed.
I expect many Microsoft 365 users will have questions and some difficult challenges along the way, including possible lockouts, login problems and confusion about what they’re being asked to do. My goal with this guide is to document what I learn and help people figure it out. I’m figuring this out in the trenches with my clients, documenting what works, and I can help you figure yours out too.
If you want to add to this article, please email me lisa@callthatgirl.biz. I’m happy to have co-authors as this document builds.
Now, on to the document. The information farther down includes Microsoft Passkey FAQs, technical information and additional research I’ve compiled with the help from ChatGPT.
Jump to a Major Section
Client Passkey Problems & Calls
New Computer & Account Confusion
CALL THAT GIRL
A field manual for Microsoft 365, Outlook, Windows, MFA and account-recovery calls
| Purpose: Build a repeatable diagnostic process for real-world small-business passkey problems—especially when personal Microsoft accounts, Windows logins, Office licensing and Microsoft 365 business identities are tangled together. |
Prepared for Lisa Hendrickson • Call That Girl
Working Draft — Version 1 • August 26, 2026
How to Use This Guide
This is a technician’s working manual, not a promise that every Microsoft account can be recovered. Use it to identify the identity involved, preserve any working access, collect evidence, choose the safest recovery path and document the result.
This can be used by end users as well but take note of the golden rule:
| Golden rule: Do not remove a working Outlook profile, sign a client out of their only working session, delete an authentication method, reset a phone or change an administrator until you know what recovery path remains. This includes deleting Windows profiles, DNS records or frankly, anything unless absolutely required. |
- Start with the Five-Identity Map before touching settings.
- Treat an open Outlook window as potentially cached access, not proof that the client can sign in again.
- Record exact wording, screenshots and account names before changing anything.
- Never ask the client to email or text passwords, PINs, one-time codes, passkeys or recovery codes.
- When ownership or authority is unclear, stop and verify before proceeding.
Official Microsoft Source List
(I have a feeling these sources will invaluable to us technicians)
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication — https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement
- FAQ for Microsoft-provided SMS and voice retirement — https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq
- Passkeys (FIDO2) authentication method in Microsoft Entra ID — https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2
- Enable passkeys (FIDO2) in Microsoft Entra ID — https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkeys-fido2
- Register passkeys in Microsoft Authenticator — https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-passkey-authenticator
- Passkey FAQs for Microsoft Entra ID — https://learn.microsoft.com/en-us/entra/identity/authentication/passkey-faq
- Troubleshoot signing in with a passkey — https://support.microsoft.com/en-us/accounts-billing/security/troubleshoot-signing-in-with-a-passkey
- Create and save a passkey — https://support.microsoft.com/en-us/accounts-billing/security/create-save-passkey
- Manage saved passkeys — https://support.microsoft.com/en-us/accounts-billing/security/manage-your-saved-passkeys
- Temporary Access Pass — https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass
- Microsoft Entra passkey on Windows (preview) — https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-entra-passkeys-on-windows
- Set up a security key as a verification method — https://support.microsoft.com/en-us/accounts-billing/work-school/set-up-a-security-key-as-your-verification-method
- Emergency access accounts — https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access
Microsoft Passkey Problems and Calls I Expect From Clients
Will Microsoft Passkeys Lock You Out of Outlook?
-
Why Can Outlook Keep Working When Your Sign-In Is Broken?
-
What Causes Outlook to Ask for a Passkey?
-
Should You Remove and Re-Add the Outlook Profile?
-
When Should You Call an Outlook Professional?
Microsoft Passkeys With a Local Windows Account
-
Does a Local Windows Account Prevent Microsoft 365 Passkeys?
-
Do You Need a Windows PIN?
-
Will the Passkey Change How You Sign Into Windows?
-
Where Should the Passkey Be Stored?
Office Home With Microsoft 365 Business Email
-
Why Are the Office License and Outlook Email Different Accounts?
-
Which Microsoft Account Needs the Passkey?
-
How Can You Identify the Office Activation Account?
-
What Problems Appear on a New Computer?
What Happens to Microsoft Authenticator Passkeys When You Get a New Phone?
-
Do Authenticator Passkeys Transfer From the Old Phone?
-
What Should You Do Before Trading In a Phone?
-
How Can an Administrator Help After the Old Phone Is Gone?
-
What Backup Methods Should Be Prepared?
Microsoft Passkeys for People Without Smartphones
-
Can a Flip Phone Create a Passkey?
-
Can You Use a Physical Security Key?
-
Can Windows Hello Store the Passkey?
-
What Should Seniors and Caregivers Prepare?
How to Find Your Microsoft 365 Global Administrator Before a Lockout
-
What Does a Global Administrator Do?
-
Why Isn’t the Person Paying the Bill Always the Administrator?
-
What If GoDaddy or Another IT Company Controls the Tenant?
-
Why Should a Small Business Have a Second Administrator?
Microsoft Passkey Troubleshooting: Common Errors and Safe Fixes
-
Why Does Microsoft Say No Passkeys Are Available?
-
What Does This Passkey Can No Longer Be Used Mean?
-
Why Does the QR Code Fail to Connect?
-
Why Does Microsoft Say the Passkey Already Exists?
Common call: A working password does not necessarily mean the account has completed the authentication method Microsoft or the organization is requesting. Confirm the tenant policy and the exact registration prompt before making changes.
My Microsoft 365 Password Works, So Why Do I Need a Passkey?
Common call: A passkey may have been created for the wrong Microsoft identity, saved with a different provider, or not completed on the server. Compare the account shown in the prompt with the passkey listed in Security Info before deleting or recreating anything.
I Created a Passkey but Microsoft Keeps Asking Me Again
Common call: The client can still use Outlook or Microsoft 365, but Microsoft repeatedly prompts them to register a passkey. First identify the exact account being challenged and preserve any working sessions before changing authentication methods.
Microsoft Keeps Asking Me to Set Up a Passkey
The Old Computer Died and the Client Bought a New PC
The passkey existed only on the old computer
What the client says:
“I thought Microsoft saved everything in my account.”
What happened:
The Microsoft 365 passkey was stored inside Windows Hello on the dead computer. It was not synced to the new computer.
Possible recovery:
- Passkey or Authenticator on the phone
- Physical security key
- Another registered MFA method
- Temporary Access Pass issued by an authorized administrator
- Another Global Administrator resets the user’s authentication methods
Worst case:
The dead computer contained the only passkey, the client is the only administrator, and no alternative authentication method exists.
The old computer had Windows Hello, but the client thinks the PIN was the passkey
What the client says:
“My PIN was 1234, but the new computer won’t accept it.”
What happened:
The old Windows Hello PIN belonged to that particular Windows device. It was not necessarily the Microsoft account password, and it does not automatically work on the new PC.
Complication:
The client may not know the actual personal Microsoft account or Microsoft 365 password because they have used the PIN for years.
Windows was signed into a personal Microsoft account
What the client says:
“I signed into Microsoft, but my business email isn’t there.”
What happened:
The client signed the new computer into the personal Microsoft account that previously controlled Windows—not the Microsoft 365 Business account that owns Exchange.
They may now have:
- Windows connected to client@hotmail.com
- Office activated by spouse@outlook.com
- Outlook using client@business.com
- OneDrive connected to the wrong personal account
- A passkey accidentally created for the personal account
The client cannot identify which Microsoft account configured the old PC
Possible discoveries:
- Windows belonged to the client’s spouse’s Microsoft account.
- The account used an old Comcast, Gmail, Hotmail or Outlook address.
- The account belongs to a former employee.
- The Amazon/Dell/Best Buy setup person created the account.
- The client knows the Windows PIN but not the account password.
- Recovery email and phone information are obsolete.
- The new PC creates an entirely new personal Microsoft account because the client cannot recover the old one.
Office was licensed through a personal Microsoft 365 subscription
What the client says:
“I pay for Microsoft 365, so why can’t I install Outlook?”
Potential reasons:
- The subscription belongs to a different personal Microsoft account.
- The subscription expired.
- A spouse was sharing Microsoft 365 Family with the client.
- The old PC used a one-time Office license.
- Office came preinstalled but was never associated properly.
- The client has Microsoft 365 Business email but no desktop-app license.
- The personal Office account and business Exchange account are being confused.
This will look like one passkey problem, but it may be two separate jobs: Office activation and Exchange authentication.
Outlook email was Exchange, but important data was stored locally
A new Exchange profile should resynchronize server-based email, calendar and contacts. But the client may also have had:
- Local PST archives
- POP email
- “This computer only” folders
- Local-only contacts or calendars
- Autocomplete history
- Signatures
- Rules stored only on the client
- Templates
- Locally attached archive files
- Email from accounts no longer active
- An Outlook profile containing disconnected mailboxes
Worst case:
You successfully recover the Microsoft account and Exchange mailbox—but years of locally stored Outlook data died with the old computer.
That needs to be clearly explained:
Account recovery, passkey recovery and Outlook data recovery are three different things.
OneDrive signed into the wrong account
What the client says:
“My desktop and documents didn’t come back.”
Possible causes:
- Old PC backed up to personal OneDrive.
- New PC is signed into business OneDrive.
- The opposite happened: old PC used business, new PC uses personal.
- The client had two OneDrive clouds with similar names.
- Files never finished syncing before the PC died.
- Sync was paused or broken.
- Files were only local despite showing OneDrive folder names.
- The client unknowingly created a new empty Microsoft account.
- Files were shared from a spouse’s or former employee’s account.
- Known Folder Backup restores an older or incomplete version.
The client creates the passkey during new-PC setup
This can produce several mistakes:
- Passkey is created for the personal Windows account, not Microsoft 365 Business.
- It is saved under the wrong Windows profile.
- The client doesn’t know where Windows saved it.
- Windows Hello is created before the identity map is completed.
- The new computer is accidentally registered with the business.
- The user accepts “Allow my organization to manage this device” without understanding it.
- The client creates a new Windows PIN and believes it changed the email password.
- Office signs into whichever account Windows presented first.
- Edge saves credentials under a newly created personal profile.
The phone contains the surviving passkey
This is the good scenario—provided that:
- The phone still works.
- The passkey belongs to the correct business account.
- The phone has internet access and Bluetooth enabled.
- The client knows the phone-unlock PIN.
- Authenticator has not been deleted or reset.
- The tenant still permits that passkey provider.
- The client can complete the cross-device QR process.
The new PC can use the phone’s passkey to authenticate without having the old PC.
The phone has Authenticator, but not an Authenticator passkey
What the client says:
“The account is in Authenticator, so I know the passkey is there.”
Not necessarily. The phone may contain:
- Authenticator push notifications
- Rotating one-time codes
- Passwordless phone sign-in
- A passkey
- An old or disconnected account entry
You will need to identify the actual method, not merely confirm that the account appears in the app.
Windows Local Accounts, PINs and Windows Hello
Local Windows account with no password
What the client says: “I don’t have a Microsoft password. My computer just opens.”
Most likely: The Windows local account may have no password while Outlook uses a separate Microsoft 365 work identity.
Check: Settings > Accounts > Your info; Office Account; Outlook address; work-account Security Info.
Action: Do not convert the Windows account merely to solve the Exchange passkey problem. Choose a supported phone/security-key method or deliberately configure Windows Hello storage if appropriate.
No Windows PIN
What the client says: “Microsoft is asking for a PIN, but I never made one.”
Most likely: The requested PIN may be a Windows Hello PIN, phone-unlock PIN or physical-key PIN.
Check: Identify which device and credential provider owns the prompt.
Action: Create the correct local PIN only after explaining what it protects. Document that it is device-specific.
Client forgets Windows Hello PIN
What the client says: “My email password doesn’t work in the PIN box.”
Most likely: A local Windows Hello PIN is being requested, not the Microsoft 365 password.
Check: Use Sign-in options and determine whether PIN recovery is available for that account type.
Action: Recover or recreate Windows Hello through the appropriate account flow; preserve BitLocker/recovery information and working profiles.
Personal Microsoft Account Versus Work or School Account
- Personal accounts commonly end in outlook.com, hotmail.com or live.com, but can also use another email address.
- Work or school accounts belong to an Entra tenant and are administered by the organization.
- Personal-account recovery and Entra administrator recovery are different processes.
- A personal Microsoft account passkey does not satisfy a work tenant’s passkey requirement.
- Edge and Windows may automatically surface the personal identity first.
Office Home Licensing With Business Exchange
Office is personal but email is business
What the client says: “I pay Microsoft every year and Outlook has my business email.”
Most likely: Office may be activated through Microsoft 365 Family/Home while Exchange is licensed in a separate business tenant.
Check: In an Office app, inspect Account/Product Information; then inspect Outlook account settings and Microsoft 365 admin ownership separately.
Action: Keep the licensing identity and mailbox identity documented. Create the passkey for the challenged business account, not simply the account paying for Office.
Activation failure appears during passkey rollout
What the client says: “The passkey broke my Office.”
Most likely: A personal Office subscription may have expired or changed while a separate work-account authentication prompt appeared.
Check: Check Office activation state and the exact account requesting authentication.
Action: Resolve activation and Exchange authentication as separate incidents.
SMS-Only and Voice-Only MFA Users
SMS is the only method
What the client says: “Microsoft always texts me a code. Why can’t it keep doing that?”
Most likely: The user is directly in the retirement risk group if Microsoft-provided SMS/voice is their only available MFA method.
Check: Review the user’s registered methods and tenant Authentication Methods policy.
Action: Register an approved phishing-resistant method before February 1, 2027 and verify it. Preserve SMS during the transition while it remains supported and useful for onboarding.
User snoozes every prompt
What the client says: “I clicked skip and Outlook worked, so I thought it was fixed.”
Most likely: The registration campaign allowed postponement; no remediation occurred.
Check: Review Security Info and confirm whether a passkey actually exists.
Action: Complete and test registration now. Explain that February enforcement is blocking under Microsoft’s published plan.
Clients Without a Compatible Smartphone
- Do not assume the client must buy a new smartphone before assessing alternatives.
- Consider a tenant-approved physical FIDO2 security key.
- Consider Windows-based passkey storage only when the tenant policy and Windows Hello prerequisites are deliberately configured.
- For organizations with a valid ongoing telephony requirement, investigate Microsoft’s customer-managed telecom option and its cost/administration implications.
- Document accessibility, dexterity, vision and caregiver needs before choosing hardware.
| Do not promise: A flip phone that receives SMS does not itself become a passkey device. |
Lost, Replaced, Reset or Broken Phones
New phone restored from backup
What the client says: “Authenticator came back, so why is the passkey missing?”
Most likely: Microsoft Authenticator passkeys are device-bound and do not sync or restore to the new phone.
Check: Determine whether any alternate method, admin or Temporary Access Pass is available.
Action: Use the surviving method or authorized administrator to bootstrap a new passkey. Register and test the new credential before deleting stale entries.
Stop condition: The user is the only administrator and no alternate authentication or recovery path exists.
Old phone is still available
What the client says: “I’m trading this phone in today.”
Most likely: The old device may contain the only usable passkey.
Check: Verify a new passkey and alternate method on the replacement device first.
Action: Do not wipe or surrender the old phone until sign-in on the new device is proven.
Phone was stolen
What the client says: “My phone and passkey are gone.”
Most likely: The credential is unavailable and the device may still have active sessions.
Check: Confirm another method/admin; review sign-in risk and sessions if authorized.
Action: Revoke sessions as appropriate, remove the lost credential only after replacement access exists, and follow incident-response procedures.
Microsoft Authenticator Problems
Account appears in Authenticator but no passkey exists
What the client says: “My account is already in the app.”
Most likely: Authenticator registration for approvals/codes does not automatically mean an Authenticator passkey was created.
Check: Open the account entry and Security Info; identify the listed method type.
Action: Use Create a passkey or Security Info registration for the correct work account.
Passkey exists locally but not on the server
What the client says: “It says the passkey already exists, but Microsoft keeps asking.”
Most likely: A registration timeout may have stored the passkey locally without completing server registration.
Check: Compare Authenticator’s local credential with Security Info.
Action: Follow Microsoft’s guidance to delete the orphaned local passkey and retry—only after confirming no valid server-side/working credential is being removed.
Android cannot create the passkey
What the client says: “The option is there but creation fails.”
Most likely: Android version, secure hardware, passkey-provider selection or attestation may be incompatible.
Check: Check Android 14+ requirement, current app, screen lock, Secure Element/TEE support and provider settings.
Action: Update where appropriate or select an approved alternative such as a physical security key.
QR Code, Bluetooth and Cross-Device Problems
QR code scans but devices do not connect
What the client says: “It scans and then says it couldn’t connect.”
Most likely: Bluetooth, proximity, internet, proxy filtering or required endpoints may block the hybrid flow.
Check: Both devices online; Bluetooth enabled; physically near; current browser/OS; corporate filtering.
Action: Retry once after correcting prerequisites. Use same-device registration or another approved method if cross-device remains blocked.
Client tries to scan QR code on the same phone
What the client says: “How do I scan my own screen?”
Most likely: The cross-device workflow was opened on the device that must scan it.
Check: Identify where the passkey is intended to live.
Action: Use same-device registration in Authenticator/Security Info or display the QR code on a separate computer.
Outlook Still Works but Web Sign-In Fails
Cached Outlook access
What the client says: “My email works, so I’m not locked out.”
Most likely: Outlook may be using a still-valid cached token while interactive authentication is broken.
Check: Test web access in a separate private window without closing Outlook or clearing credentials.
Action: Treat the live Outlook session as fragile evidence. Repair authentication before token expiration, update or profile recreation forces reauthentication.
Outlook says Need Password
What the client says: “I keep typing the password and nothing happens.”
Most likely: The embedded Microsoft sign-in may require MFA/passkey registration, not another password entry.
Check: Open the complete authentication window and identify the account and requested method.
Action: Resolve identity/authentication first. Do not remove the Outlook profile as the first step.
Unknown Global Administrator and Tenant Ownership
- Identify the tenant using the business domain and Microsoft 365 sign-in.
- Ask who originally purchased Microsoft 365.
- Check for GoDaddy, reseller or MSP relationships.
- Locate billing emails and prior Microsoft support records.
- Identify every admin account without changing roles.
- Verify that at least one authorized admin can sign in with a strong method.
- Create an authorized recovery plan and second admin only with owner approval.
| Stop condition: If nobody can prove ownership or administrative authority, do not attempt to bypass Microsoft verification or take control of the tenant. The client must complete Microsoft’s ownership/recovery process. |
Determine Which Microsoft Account Is Being Challenged
The client says Microsoft keeps asking for a passkey
What the client says: “Microsoft keeps asking me to make a key.”
Most likely: A work account has entered a registration campaign, but the prompt may be appearing inside Outlook, Office, Edge or a browser profile that is signed into another identity.
Check: Read the full account address on the prompt. Compare it with Windows, Office activation and Outlook.
Action: Map all identities first. Complete registration only for the intended work or school account.
Stop condition: The displayed account is unknown, belongs to a former employer or is not owned by the client.
The passkey was created for the wrong account
What the client says: “I already did this, but it keeps asking again.”
Most likely: A passkey may have been created for the personal Microsoft account while the Microsoft 365 work account remains unregistered.
Check: Inspect the personal account security dashboard and the work account Security Info separately.
Action: Confirm which account contains the passkey. Register the correct work account before removing anything from the personal account.
The same email address appears as personal and work
What the client says: “It gives me a choice between personal and work, but they have the same email.”
Most likely: Microsoft can have separate consumer and Entra identities using the same sign-in name.
Check: Test each identity in a private browser and record what service/dashboard opens.
Action: Label the accounts in documentation and browser profiles. Never assume a password or passkey applies to both.
The Old Computer Was Stolen
The stolen-PC case is both an access problem and a security incident.
The stolen PC contained a Windows Hello passkey
The thief has the physical device containing the private credential. The credential should still require the victim’s PIN or biometric, but you should treat it as exposed equipment.
Recommended response:
- Preserve or establish access from a safe device.
- Verify the client has another authentication method.
- Revoke the stolen device’s active Microsoft sessions.
- Disable or remove the stolen device from management where applicable.
- Review recent Entra sign-ins.
- Remove the stolen computer’s passkey from the work account after replacement access is working.
- Remove the device from the personal Microsoft account if it appears there.
- Change passwords if compromise is suspected—not simply because passkeys exist.
- Notify the client’s IT/security provider if the business has one.
- Document the date, device and actions taken.
Microsoft Passkey Technician Notes and Training
Registering a Passkey Successfully
Registration Preflight
- Confirm the correct work or school account.
- Confirm passkeys are enabled for the user in Entra Authentication Methods policy.
- Confirm the selected passkey profile allows the intended provider/type.
- Confirm supported OS and current Authenticator version.
- Confirm the phone or device has a PIN, passcode or biometric lock.
- Confirm internet access; for cross-device flows confirm internet on both devices and Bluetooth.
- Confirm the user can complete recent MFA or has a valid Temporary Access Pass.
Recommended Registration Sequence
- Preserve all working sessions.
- Capture existing authentication methods.
- Sign in to the work account’s Security Info using a known-good method.
- Choose the intended passkey method/provider.
- Complete the local device unlock or key PIN step.
- Name the passkey clearly with device and date.
- Verify it appears in Security Info.
- Test it in a private browser without destroying the original working session.
- Add a second recovery/authentication method where policy permits.
- Document where the credential is stored and who owns the device.
Signing In With a Passkey
At sign-in, Microsoft may offer the same-device passkey, a QR-code cross-device flow or a physical security key. The device storing the private credential must be available and unlocked locally.
- Same-device: choose the passkey and unlock it with the device’s PIN or biometric.
- Cross-device: scan the QR code with the device that stores the passkey; keep Bluetooth and internet enabled.
- Security key: insert or tap the key, then enter the security-key PIN—not necessarily the Windows PIN.
- If the wrong provider opens, cancel safely and select another sign-in option; do not delete credentials as the first response.
Temporary Access Pass Recovery
A Temporary Access Pass (TAP) is a time-limited code issued by an authorized Entra administrator. It can bootstrap registration of a new passwordless method and assist when a user loses a strong authentication method.
- TAP must be enabled in the tenant’s Authentication Methods policy.
- The target user must be included in the policy.
- An appropriate administrator creates the TAP for the user.
- Use the TAP within its configured lifetime and single-use/multi-use limits.
- Register and test the replacement method before the TAP expires.
- Never send a TAP through an insecure channel or retain it after use.
Shared Accounts, Shared Mailboxes and Shared Computers
Everyone shares one Microsoft 365 user
What the client says: “We all use the same email and password.”
Most likely: A person/device-bound passkey exposes an already poor shared-identity design.
Check: Determine whether this should be individual users with delegated access to a shared mailbox.
Action: Recommend individual licensed identities and proper shared mailbox permissions. Do not attach the organization’s only passkey to one employee without a recovery design.
Shared computer
What the client says: “Three employees use the same PC.”
Most likely: The passkey may be stored in the wrong Windows profile or unlocked by a shared PIN.
Check: Map Windows profiles, browser profiles and work accounts.
Action: Use separate Windows identities where practical and document which passkey belongs to which account/profile.
Third-Party IT, GoDaddy and Reseller-Controlled Tenants
- Confirm whether the third party has delegated administration or owns billing/provisioning.
- Do not remove partner relationships during an authentication emergency unless the owner understands the consequences.
- Ask the provider to identify an authorized admin who can reset methods or issue a TAP.
- Record what CTG can control versus what must be completed by the provider.
- Bill for coordination time under the signed client agreement.
Physical FIDO2 Security Keys
- Confirm FIDO2 compatibility and tenant passkey policy before purchase.
- Choose the correct connector: USB-A, USB-C and/or NFC.
- Create a unique security-key PIN and distinguish it from the Windows PIN.
- Register a backup key where policy and risk justify it.
- Label keys without exposing the full account identity.
- Store the backup separately from the primary computer and key.
- Document custody when the user is an employee or contractor.
Determine Where the Passkey Can Be Stored
| Storage choice | Best fit | Risks / prerequisites |
| Microsoft Authenticator | Most users with supported iPhone or Android devices | iOS 17+ or Android 14+ for Authenticator passkeys; screen lock; compatible secure hardware; device-bound and not synced. |
| Synced passkey provider | Users who deliberately manage credentials in an approved ecosystem | Provider must be allowed by tenant policy; recovery and sync behavior depends on provider. |
| Windows Hello container | Personal/unregistered Windows device or multiple Entra accounts where configured | Windows Hello required; Entra policy/profile required; current Windows Entra passkey feature is documented as preview. |
| Physical FIDO2 key | No smartphone, regulated use or backup method | Compatible key, tenant policy, key PIN and safe duplicate/storage plan. |
Error Message Troubleshooting Library
| Message / symptom | Likely causes | First safe action |
| No passkeys available | Wrong provider/account, no screen lock, missing credential or unsupported device. | Confirm account, provider, device lock and where the credential was registered. |
| This passkey can no longer be used | Credential deleted, changed PIN/biometric relationship or stale local entry. | Use another sign-in method, create a new valid passkey, then remove stale entries. |
| We couldn’t use your device to verify your identity | Passkey no longer valid on that device. | Choose another available method; inspect account and device passkey lists. |
| Passkey already exists | Existing valid registration or orphaned local credential after timeout. | Compare Security Info with the local provider before deletion. |
| Device couldn’t connect | Bluetooth/internet/proximity/proxy or endpoint issue. | Verify both devices online and Bluetooth enabled; keep them near each other. |
| Something went wrong | Account, device, provider, connectivity, policy or service issue. | Capture correlation/time/error details; verify prerequisites instead of repeating blindly. |
| Need password in Outlook | Expired token or interactive authentication/passkey challenge hidden behind Outlook. | Open the full sign-in experience; preserve the Outlook profile. |
High-Risk Stop Conditions
- The client cannot establish ownership or authorization.
- You are working in the only Global Administrator session and no recovery method exists.
- The proposed action would sign out or erase the only working session.
- The client wants to share passwords, one-time codes or PINs insecurely.
- A third party owns or controls the tenant and has not authorized the work.
- A compromise or fraud incident requires security response beyond routine support.
- Microsoft requires identity verification only the account owner can perform.
- The client asks you to bypass a security control.
- The client cannot understand or consent to the authentication change and no authorized representative is available.
Post-Repair Hardening and Documentation
- Test the new method in a private session.
- Confirm at least one separate recovery path.
- Document the credential’s device/provider and registration date.
- Confirm the phone and recovery information belong to the correct person.
- Confirm at least two appropriately secured admins for a business tenant.
- Remove stale methods only after replacement access is proven.
- Review active sessions when a device was lost or stolen.
- Explain what will happen when the phone or computer is replaced.
- Give the client a plain-language summary without recording secret values.
The thief knows the Windows PIN
This becomes significantly more serious if:
- The PIN was written on the laptop.
- The thief watched the client enter it.
- The client used the same PIN elsewhere.
- Windows logged in automatically.
- The computer had no password or lock screen.
- The device was already unlocked when stolen.
Potential exposure includes:
- Outlook email
- OneDrive files
- Browser-saved passwords
- Personal Microsoft account
- Business portals
- Accounting systems
- Existing Microsoft authentication tokens
- Remote-support software
- Password managers
- Client or customer information
At that point, this is bigger than passkey troubleshooting.
Outlook remains signed in on the stolen PC
Even if the thief cannot create a new sign-in, Outlook or another Microsoft app may have a valid cached token.
The client may need:
- Session revocation
- Device disabling
- Password reset
- Review of mailbox forwarding and inbox rules
- Review of delegated mailbox permissions
- Review of recent sign-ins
- Review of security information for newly added methods
- Review of account aliases
- Review of app consent and connected applications
The stolen PC was the only Global Administrator device
Potential nightmare:
- Admin passkey existed only in Windows Hello.
- No secondary administrator exists.
- Authenticator is not configured.
- SMS was the only other method and is no longer available.
- No physical security key exists.
- No emergency-access account was prepared.
- The client cannot create a Temporary Access Pass because nobody else can access the admin center.
This becomes Microsoft tenant-recovery territory, and recovery may require direct ownership verification.
BitLocker recovery becomes part of the new-PC conversation
The new computer may automatically enable device encryption or BitLocker when signed into a Microsoft account.
You will need to identify:
- Which account stores the new BitLocker recovery key
- Whether it is personal or business
- Whether the client can retrieve it
- Whether the old computer’s recovery key exists
- Whether the old drive can be recovered if the dead PC is later found or repaired
- Whether the stolen device was encrypted
A dead PC with an intact encrypted drive may still contain recoverable data—but only if the correct BitLocker recovery information is available.
The stolen PC is recovered later
Do not automatically put it back into service.
First consider:
- Was it tampered with?
- Was the drive removed?
- Were new programs installed?
- Were browser sessions accessed?
- Was malware added?
- Was the Windows PIN compromised?
- Were authentication methods changed?
- Should the device be professionally wiped and rebuilt?
- Have its old passkeys already been removed from the accounts?
Technician Intake and Preflight Checklist
Before Remote Access
- Obtain authorization from the account owner or authorized business representative.
- Ask whether any email or Microsoft app still works on any device.
- Ask whether the user can sign in at Microsoft 365 on the web—do not sign them out merely to test.
- Identify the phone model, mobile OS version and whether it has a screen lock.
- Ask whether the phone was recently replaced, restored, reset or repaired.
- Ask whether another Global Administrator exists.
- Ask whether GoDaddy, an MSP, former employee or family member manages Microsoft 365.
- Record the exact error and where it appeared.
- Confirm whether the client is using SMS, voice, Authenticator approval, Authenticator code, passkey, Windows Hello or security key.
- Confirm whether the client is physically present with every required device.
Evidence to Capture Before Changes
- Screenshot of the prompt and full error text.
- Account identifier shown in the prompt.
- Windows account type and username.
- Office activation account.
- Outlook email address and account type.
- Security Info methods, if accessible.
- Entra user authentication methods, if authorized admin access exists.
- Names of all administrator accounts.
- Working sessions and devices that must be preserved.
Technician Practice Lab
Practice in a test tenant. Never use a client’s only administrator as the experiment.
- SMS-only user enters registration campaign.
- Authenticator approval exists but no passkey exists.
- Passkey registration on supported iPhone.
- Passkey registration on supported Android.
- Cross-device QR registration with Bluetooth disabled, then enabled.
- Lost-phone recovery using a second administrator and TAP.
- Physical security-key registration and backup key.
- Local Windows account plus business Exchange account.
- Personal Windows account plus business Exchange account.
- Office Family activation plus Microsoft 365 Business mailbox.
- Same email string represented as personal and work identities.
- Outlook cached session while browser sign-in fails.
- Shared mailbox corrected from a shared-user-password workflow.
- Stale passkey removal after a new credential is verified.
The New-PC Call Checklist for Passkey
Before configuring anything, ask:
- Did the old PC die, disappear or get stolen?
- Is the old drive physically available?
- Was BitLocker or device encryption enabled?
- Does Outlook or email still work on another device?
- Which account previously signed into Windows?
- Which account paid for Office?
- Which account owns the Exchange mailbox?
- Is the client’s business email Microsoft 365, Outlook.com, POP or IMAP?
- Does the phone have Microsoft Authenticator?
- Does Authenticator contain an actual passkey?
- Is there another Microsoft 365 administrator?
- Was a Windows Hello passkey stored on the old PC?
- Is there a physical security key?
- Was OneDrive personal, business, both or neither?
- Did the old Outlook profile contain PST or local-only data?
- If stolen, have sessions and devices been reviewed or revoked?
- Who owns and controls the new Windows account?
- Where will the new BitLocker recovery key be stored?
- Which identity will activate Office?
- Which identity will receive the new passkey?
And your strongest safety line belongs at the top:
Do not erase, recycle, trade in, dispose of or attempt to reinstall Windows on the old computer or drive until the Microsoft identities, encryption status and possible local Outlook data have been documented.
Category: Outlook Support

