New Identity Security Alert: Microsoft has rolled out a critical update affecting how FIDO2 Security Keys (like YubiKeys) interact with Microsoft Entra ID. To combat sophisticated phishing and key-theft attacks, users are now being forced to set up a PIN during sign-in, creating a mandatory two-factor verification step.
This change impacts all organizations using passwordless authentication methods to secure their cloud environments.
What is Changing? (The Mandatory PIN Rule)
Previously, the requirement for a PIN on FIDO2 keys was optional or dependent on specific WebAuthn flags. However, Microsoft is now enforcing strict User Verification (UV) protocols.
- The New Rule: If an Identity Provider (IDP) requests User Verification set to “Preferred,” Microsoft will now force the setup of a PIN if the key is capable but lacks one.
- The Trigger: This aligns with WebAuthn specifications where “User Verification” proves user presence via PIN or Biometrics.
Technical Analysis: Affected Windows Updates
According to the latest documentation, this deployment was completed following the November 11, 2025 security updates. Administrators must check their Windows builds for the following patch versions to ensure compliance.

Affected OS Builds & KB Versions
We have compiled the technical data regarding the specific updates that trigger this behavior:
| Update ID | Release Date | OS Builds Affected |
|---|---|---|
| KB5065789 | Sept 29, 2025 | 26200.6725, 26100.6725 |
| KB5068861 | Nov 11, 2025 | 26200.7171, 26100.7171 |
Technical Breakdown: The requirement impacts authentication flows where the User Verification (UV) level is set to “Preferred.” Previously, PIN setup only happened during registration. Now, these updates extend that check to the authentication flow itself.
CyberUpdates365 Analysis: Why This Matters
Our Take: This is a strategic move by Microsoft to prevent “Key Theft” attacks. If a threat actor physically steals a user’s security key (Something they have), they could potentially access the account if no PIN (Something they know) is required.
The Impact: While this significantly hardens the security posture, IT admins should expect increased helpdesk tickets. Users who are used to simply “plugging and tapping” their keys may think their device is malfunctioning when suddenly asked for a PIN.
Action Plan for Security Teams
If your organization uses Entra ID, follow these steps immediately:
1. Audit User Keys
Identify users currently authenticating without a PIN. Most modern keys (YubiKey 5 Series) support PINs by default but may not have one configured.
2. Proactive Communication
Send an internal security alert: “Due to a Microsoft security update, you may be prompted to create a PIN for your security key next time you sign in. This is a normal security enhancement.”
Disclaimer: This report is based on the latest authentication updates from Microsoft Entra ID. The analysis provided by CyberUpdates365 is for educational purposes to help IT teams prepare for security changes.




