Managing Android devices using Microsoft Intune
For a new Android work profile that is asking for a passkey that is not available, the most common cause is that the existing passkey is tied to a different profile or device and is no longer valid for the new setup.
Use these steps:
- Verify where the existing work passkey is stored
- If the passkey for the work account was originally created using the camera or an authenticator app in the Personal profile, it will not be available in the Work profile.
- In that case, a new passkey must be created specifically in the Work profile.
- Recreate the passkey in the correct profile
- On the Android device, switch to the Work profile.
- Sign in to the work or school account security info page at
https://mysignins.microsoft.com/security-infofrom the Work profile browser. - Choose Add sign-in method and select Passkey or Passkey in Microsoft Authenticator.
- Follow the on-screen instructions on that device to complete passkey creation.
- If the passkey is reported as invalid or not found
- If any message appears like “This passkey can no longer be used,” or the passkey is not found, it likely has been deleted or invalidated (for example, due to device change or local authenticator changes).
- Delete any non-working passkeys from the account security info page and from the authenticator app on the device.
- Set up a new passkey from the Work profile as above.
- If signing in from Windows or another device
- When prompted to sign in with a passkey and the local passkey is not available, choose Sign-in options → Face, Fingerprint, PIN, or Security Key, then select the passkey that corresponds to the new Android Work profile device, or choose the option to use iPhone, iPad or Android device and follow the QR flow.
- Ensure device and platform support
- Confirm that the Android version on the new device is Android 9 or newer (and Android 14 or newer if using Passkeys in Microsoft Authenticator for work/school accounts).
If the organization has disabled passkeys for work accounts, an Intune/Entra ID admin must enable passkey support before a new passkey can be created.
References: