Said It Here

Fixing security token enrollment errors for non-technical users

Asking standard employees to manually navigate certificate tools, templates, and provisioning slots turns simple token setups into 30-minute helpdesk calls. Additionally, strict configurations cause sign-ins to fail with error messages stating that the passkey does not meet the criteria set by the admin.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Purchasing expensive commercial Certificate Management Systems
  2. 2
    Writing custom internal enrollment tools
  3. 3
    Check Conditional Access policy configuration for MFA
  4. 4
    Verify device requirements like PIN or Face ID settings

In their words

Unedited, most upvoted first, each linked to the thread it came from.

Asking standard employees to navigate certmgr.msc, pick the right AD CS template, and properly provision Slot 9A usually results in a 30-minute helpdesk call.source ↗

Legal2k · r/sysadmin · 14 upvotes

I am getting a “Your sign in was successful but this passkey does not meet the criteria set by your admin” error message.source ↗

evil-scholar · r/sysadmin · 2 upvotes

Where this came up

People with this problem also raised