What is a Passkey?

Think of a passkey as a secure digital key stored on your device. Instead of entering a password, you simply use your smartphone to scan a passkey QR code or authenticate with a physical security key, such as a FIDO2 key. It's faster, easier to use, and significantly more resistant to phishing and credential theft than traditional passwords.

Set Up Microsoft Authenticator

Please follow the instructions from Microsoft Authenticator Setup Guide

FAQs

Instead of sending a password over the Internet, your device generates a pair of keys: a private key and a public key.

  • The private key is stored securely on your device.
  • The public key is registered with the website or application.

When you want to sign to the website or application, your device has to prove that it has the private key. After you unlock your private key, your device digitally signs a challenge from the website or application. The website or application verifies the signature using the public key and grants you access.

Yes, passkeys are considered a form of multi-factor authentication. When you use a passkey, you must use a device that stores the passkey (something you have) and unlock it with biographic information or a PIN (something you are, or something you know).

Yes, passkeys are phishing resistant. When they are created, passkeys are associated with the specific domain that the website or app are registered with. A passkey created for netflix.com can only be used with netflix.com. While a user can be tricked into landing on a similar looking website, they can't present their passkey to the malicious website. Their device won't allow it.

Yes, you can use passkeys across multiple devices. Synced passkeys allow you to use your passkey anywhere the provider is. On Windows you can use Microsoft Password Manager or a third-party provider to save and use passkeys created on other devices.  

In addition, you can use cross device authentication: a passkey might be stored on one device, and you can use it for sign-in on another device through a QR code that is generated on the device where you want to sign in. During this process, a proximity check takes place to ensure that the passkey is only being used for authentication on a device that's nearby. With this technology, you can rest assured that your passkey can't be used by a remote attacker to gain access from far away.

If you get a new phone or reinstall the Microsoft Authenticator app, you will need to re-activate the app. You can enroll your new device yourself through the device management portal.

To add a new device, you must first sign in using an MFA method that is already configured on your account. This is why we strongly recommend having at least two MFA methods set up, for example, the Authenticator app plus a phone call or SMS. Having multiple methods makes account recovery much easier if you lose access to one device.

If the device you are replacing was your only MFA method and you no longer have access to it, please contact the IT Help Desk for assistance.

New Help Desk Ticket


Need More Help?

Contact our Help Desk if you have any questions about this process!