If your YubiKey works on Mac but not Windows 11, the most common fix is enabling Passkey access in Windows Settings under Privacy and Security. This hidden setting blocks the Windows Security popup from appearing, even for U2F-based keys, making it look like the YubiKey is completely broken on Windows.
This cross-platform issue frustrates thousands of users every month. The YubiKey itself is almost never defective. Instead, Windows 11 handles FIDO2 and WebAuthN authentication differently than macOS, and certain settings, drivers, or conflicting software can prevent the key from being recognized.
I have helped dozens of users troubleshoot this exact scenario where a YubiKey works on Mac but not Windows 11. In nearly every case, the resolution came down to one of six fixes I will walk you through below. Let us start with the quickest solution and work toward more advanced diagnostics.
Table of Contents
Why Your YubiKey Works on Mac but Not Windows 11
When a YubiKey works on Mac but not Windows 11, the root cause is almost always on the Windows side, not the hardware. macOS handles FIDO2 and WebAuthN authentication at the browser level with minimal operating system interference. Windows 11, on the other hand, routes security key authentication through the Windows WebAuthN API, the Windows Security dialog, and CredentialUIBroker.exe.
This means Windows has multiple layers that can block your YubiKey. The most frequent culprit is a disabled Passkey access toggle in Windows Settings. When this setting is off, Windows blocks all passkey and security key operations system-wide, regardless of which browser or application you are using.
Other common causes include USB port or driver issues, conflicting software like Citrix Workspace or Duo Security, outdated YubiKey firmware, or a browser misconfiguration. The good news is that each of these has a straightforward fix once you identify which one applies to your situation.
Step 1: Check if Windows 11 Detects Your YubiKey
Before diving into settings, confirm whether Windows 11 sees your YubiKey at all. This quick diagnostic takes under two minutes and tells you whether the problem is hardware-related or software-related.
Press Win + X and select Device Manager. Look under the Security Devices or Universal Serial Bus devices section. When you plug in your YubiKey, you should see a new device appear within a few seconds. If nothing appears, try unplugging and reinserting the key.
Next, check the LED indicator on the YubiKey itself. When you plug it in, the LED should light up steadily or pulse gently. A completely dark LED means the key is not receiving power, which points to a USB port or cable issue rather than a Windows configuration problem.
You can also install the free Yubico Authenticator app from the Microsoft Store or Yubico’s website. Open it with your YubiKey inserted. If the app recognizes your key and displays its serial number and firmware version, the hardware connection is working fine. The issue is then at the operating system or browser level.
Step 2: Enable Passkey Access in Windows 11 Settings
This is the single most common fix for a YubiKey that works on Mac but not Windows 11. A Reddit user documented this exact resolution after months of frustration, and many others have confirmed it works. Windows 11 includes a Passkey access toggle that, when disabled, silently blocks all security key authentication.
The confusing part is that this setting can be turned off automatically after certain Windows updates or by organizational policies. You will not get any notification that it happened. Your YubiKey simply stops working across all browsers and applications.
Here is how to enable Passkey access step by step:
Step 1: Open Settings by pressing Win + I or clicking the Start menu and selecting the gear icon.
Step 2: Navigate to Privacy and security in the left sidebar.
Step 3: Look for Passkey access or Security key access in the security section. The exact label varies slightly depending on your Windows 11 version.
Step 4: Toggle it to On. If it is already on, try toggling it off, restarting your computer, and turning it back on. This forces Windows to reinitialize the WebAuthN subsystem.
Step 5: Restart your computer. This step is critical because the Windows Security dialog and CredentialUIBroker.exe process need to reload with the new setting.
After restarting, open your browser and try logging in with your YubiKey. The Windows Security popup should now appear, prompting you to tap your security key. If it does, your issue is resolved.
Tip: If you are on an enterprise-managed device and the Passkey access toggle is greyed out, your IT department may have disabled it through Group Policy. Contact your system administrator and ask them to check the Computer Configuration > Administrative Templates > Windows Components > Web Authentication** policy settings.
Step 3: Troubleshoot USB Connection and Ports
If Passkey access was already enabled and your YubiKey still does not work, the USB connection itself may be the problem. This is especially common with USB-C YubiKeys plugged into USB-C ports on newer Windows laptops, or with YubiKeys connected through USB hubs or docks.
Start by trying a different USB port. Ideally, test both a USB 2.0 port and a USB 3.0 port. Some Windows 11 systems have power management settings that selectively suspend USB devices, which can interrupt the WebAuthN handshake mid-authentication.
If you are using a USB hub, docking station, or USB-C adapter, remove it and plug the YubiKey directly into the computer. Hubs can introduce latency that causes the touch-to-authenticate window to time out before the key responds.
To disable USB selective suspend in Windows 11, go to Control Panel > Hardware and Sound > Power Options > Edit plan settings > Change advanced power settings. Expand USB settings and set USB selective suspend setting to Disabled.
For USB-C YubiKeys, also check whether your laptop has both USB 3.2 and Thunderbolt 4 ports. Try the YubiKey in each type. Some users report that their YubiKey only works reliably on specific port types on certain Windows 11 machines.
Step 4: Check for Software Conflicts
Certain third-party security and remote access software can intercept or block YubiKey authentication on Windows 11. The two most commonly reported culprits are Citrix Workspace and Duo Security.
Citrix Workspace installs virtual drivers that can redirect USB devices to remote sessions, even when you are working locally. This can prevent the YubiKey from communicating with your browser’s WebAuthN API. If you have Citrix installed, try temporarily uninstalling it and testing your YubiKey again.
Duo Security’s Windows Logon integration can also conflict with YubiKey authentication. If Duo is managing your Windows login, it may intercept security key requests before they reach the browser. Check your Duo configuration or temporarily disable the Duo Windows Logon client to test.
Other software that has been reported to cause conflicts includes VPN clients with built-in web filters, endpoint protection suites like CrowdStrike or SentinelOne, and remote desktop tools like TeamViewer or AnyDesk. The quickest way to identify a conflict is to perform a clean boot of Windows 11 and test the YubiKey.
To perform a clean boot, press Win + R, type msconfig, and press Enter. Under the Services tab, check Hide all Microsoft services, then click Disable all. Restart and test your YubiKey. If it works, re-enable services one by one until you find the culprit.
Step 5: Use YubiKey Manager for Diagnostics
YubiKey Manager is an official tool from Yubico that lets you inspect and configure your security key. It provides detailed information about which protocols are enabled on your YubiKey, the firmware version, and whether the FIDO2 application has any issues.
Download YubiKey Manager from the official Yubico website. It is free and available for Windows, Mac, and Linux. Install it, plug in your YubiKey, and open the application.
On the main screen, you should see your YubiKey’s serial number, firmware version, and form factor. If the app shows “Insert a YubiKey” even when the key is plugged in, you have a USB or driver problem, not a settings problem.
Click on the Applications tab and verify that FIDO2 and OTP are both enabled. If FIDO2 shows any error or is disabled, you have found your problem. Most YubiKey authentication on Windows 11 goes through the FIDO2 protocol via WebAuthN.
Check your firmware version as well. Yubico releases firmware updates periodically that improve Windows 11 compatibility. While YubiKey firmware cannot be updated directly by users, knowing your version helps Yubico support diagnose issues if you need to contact them.
Step 6: Reset FIDO2 Credentials on Your YubiKey
If none of the previous steps resolved the issue, resetting the FIDO2 application on your YubiKey can clear corrupted credentials that may be causing authentication failures. This is a more aggressive step, so use it as a last resort.
Warning: Resetting FIDO2 will permanently delete all FIDO2 credentials stored on your YubiKey. This includes passkeys, webauthn credentials, and FIDO2-based account registrations. You will need to re-register your YubiKey with every service afterward. OTP and U2F credentials are not affected by a FIDO2 reset.
To reset FIDO2 using YubiKey Manager, follow these steps:
Step 1: Open YubiKey Manager with your YubiKey inserted.
Step 2: Navigate to Applications > FIDO2.
Step 3: Click the Reset FIDO2 button.
Step 4: Remove and reinsert the YubiKey when prompted, then touch the golden contact within 10 seconds.
Step 5: Wait for confirmation that the reset is complete.
After resetting, go to each service where you previously registered your YubiKey and re-register it. Start with your Microsoft account, then your email provider, then any other services. Test on Windows 11 after each re-registration to confirm the key is now working.
WebAuthN Error Code Reference for Windows 11
If you want to dig deeper into why your YubiKey is failing, Windows Event Viewer contains detailed WebAuthN logs that can pinpoint the exact problem. These error codes are not documented well by Microsoft, but forum users have compiled the most common ones.
To access WebAuthN logs, open Event Viewer by pressing Win + X and selecting it. Navigate to Applications and Services Logs > Microsoft > Windows > WebAuthN > Operational. Look for error events with specific hex codes.
0x8001011B (Access is denied): This is the most common WebAuthN error when a YubiKey works on Mac but not Windows 11. It indicates that the calling process does not have permission to access the security key. The usual cause is the Passkey access toggle being disabled, as covered in Step 2. It can also occur when a Group Policy restricts security key usage or when another application has locked exclusive access to the YubiKey.
0x8000FFFF (Catastrophic failure): Despite the alarming name, this error typically indicates a transient communication failure between the browser and the YubiKey. It often resolves by unplugging and reinserting the key, trying a different USB port, or restarting Windows. If it persists, check for conflicting software or perform a FIDO2 reset.
Other codes you may encounter include 0x801901F6 (credential not found, meaning the YubiKey does not have the right credential for the requesting service) and 0x80070002 (file not found, which can indicate a missing or corrupted WebAuthN DLL in Windows).
Browser-Specific YubiKey Issues in Windows 11
Sometimes the YubiKey works fine in one browser but fails in another on the same Windows 11 machine. Each browser handles WebAuthN slightly differently, and knowing these differences helps narrow down the problem.
Microsoft Edge: Edge uses the native Windows WebAuthN API, which means it is most affected by the Passkey access setting and Windows Security dialog issues. If your YubiKey fails in Edge but works in other browsers, the Passkey access toggle is almost certainly the problem.
Google Chrome: Chrome on Windows 11 also routes WebAuthN through the Windows API by default. However, Chrome has its own passkey management that can sometimes interfere. Go to chrome://settings/passkeys and check if Chrome is trying to manage passkeys instead of delegating to Windows.
Mozilla Firefox: Firefox on Windows uses its own WebAuthn implementation rather than the native Windows API. If your YubiKey works in Firefox but not Edge or Chrome, that strongly suggests a Windows-level configuration issue rather than a hardware or browser problem.
Tip: Testing your YubiKey across all three browsers is one of the fastest diagnostic moves you can make. If it fails in all three, the problem is at the Windows level. If it fails in only one, look at that browser’s security and passkey settings.
FAQs
Does YubiKey work with Windows 11?
Yes, YubiKey works fully with Windows 11. All current YubiKey models (5 Series, Security Key Series) support FIDO2 and WebAuthN on Windows 11 for browser authentication, Microsoft account login, and enterprise single sign-on. When a YubiKey fails on Windows 11 but works on Mac, the issue is almost always a configuration problem like disabled Passkey access, not a compatibility issue.
Why is my computer not recognizing my YubiKey?
If your computer is not recognizing your YubiKey, check these things in order: try a different USB port, remove any USB hubs or adapters, check Device Manager for the security device, verify the LED lights up when inserted, and test the YubiKey in the Yubico Authenticator app. If the app sees the key but browsers do not, the problem is a Windows settings issue, not hardware.
How to reset a YubiKey in Windows 11?
To reset FIDO2 credentials on a YubiKey in Windows 11, open YubiKey Manager, go to Applications > FIDO2, and click Reset FIDO2. Remove and reinsert the YubiKey when prompted, then touch the gold contact within 10 seconds. This deletes all FIDO2 credentials so you will need to re-register the key with each service afterward. OTP and U2F credentials are preserved.
What to do if YubiKey is not working?
If your YubiKey is not working, start by testing it on another device to confirm the hardware is functional. Then check Passkey access in Windows Settings > Privacy and security, try different USB ports, look for conflicting software like Citrix or Duo, run YubiKey Manager diagnostics, and check Event Viewer for WebAuthN error codes. The Passkey access toggle is the single most common fix.
Why does my YubiKey work on Mac but not Windows 11?
When a YubiKey works on Mac but not Windows 11, the most common cause is that Passkey access is disabled in Windows Settings under Privacy and security. macOS handles WebAuthN at the browser level without this gatekeeper layer, so the same key works instantly. Windows 11 routes all security key authentication through its own API, which can be blocked by settings, conflicting software, or driver issues.
Conclusion
Fixing a situation where your YubiKey works on Mac but not Windows 11 comes down to methodical troubleshooting. Start with the Passkey access toggle in Windows Settings, as it is responsible for the majority of cases. Move through USB port testing, software conflict checks, YubiKey Manager diagnostics, and finally a FIDO2 reset if nothing else works.
The key insight is that this is almost never a hardware failure. If the YubiKey functions on your Mac, the physical device is working correctly. Windows 11 simply has more layers between the browser and the security key, and any of those layers can block authentication silently.
For ongoing issues, the WebAuthN error codes in Event Viewer will give you the most precise diagnostic information. The Reddit community at r/yubikey and Yubico’s official support documentation are excellent resources for unusual edge cases. If you are on an enterprise-managed machine, contact your IT department about Group Policy settings that may restrict security key authentication.