Question
What methods are available for Multi-Factor Authentication (MFA)?
Answer
The University of Windsor supports several Multi-Factor Authentication (MFA) methods to meet different user needs. For most students, faculty, staff, and sessional instructors, a device-bound or synced passkey is recommended because it provides strong, phishing-resistant protection and securely stores credentials on your device. You can choose from the secondary authentication methods listed below. We recommend enabling more than one method in your Microsoft work / school account profile so you can Sign in another way if your default method is unavailable.
Device-Bound Passkey
A device-bound passkey is stored on the device and can only be used from the device where it was created. It cannot be synchronized to other devices and typically provides stronger device-specific security. When you sign in, the device (or security key) verifies your identity using a fingerprint, face recognition, or PIN. Types of Device-Bound Passkeys Available for UWindsor Accounts:
- Passkey in Microsoft Authenticator App (Recommended): A passkey in Microsoft Authenticator is a device-bound passkey stored securely in the Microsoft Authenticator app on your mobile device. It uses cryptographic authentication and verifies your identity using your phone’s fingerprint, face recognition, or device PIN. When signing in, you may be prompted to scan a QR code or approve the sign-in through Authenticator, allowing you to securely access University resources without using a text message code or traditional push notification. The passkey remains protected on your phone and is not stored on the computer you are signing in from. Learn how to set up a passkey in Microsoft Authenticator.
- Passkey in Other Authenticator Apps: A passkey in other third-party authenticator app is a cryptographic credential stored securely within a supported authentication app on your mobile device. It verifies your identity using your phone’s fingerprint, face recognition, or device PIN and provides a secure, passwordless sign-in experience. When signing in, you may be prompted to scan a QR code or approve the sign-in through the authenticator app, allowing you to securely access University resources without using a text message code or traditional push notification. The passkey remains protected on your mobile device and is not stored on the computer you are signing in from. Examples of authenticator apps that may support passkeys include Google Password Manager, 1Password, Bitwarden, Dashlane, and other FIDO2-compatible authentication applications.
- Windows Hello for Business: Windows Hello for Business is Microsoft's enterprise authentication solution that uses biometrics (face or fingerprint), a PIN, or both, backed by cryptographic keys stored on the device, to provide passwordless access to corporate resources. If you have a university-owned or research-funded, primary user Windows OS (PC) device, this method is automatically set up for you.
- FIDO2 Security Key: A FIDO Security Key is a physical hardware device (USB) that stores cryptographic credentials and is used to authenticate users through a simple action such as touching or inserting the key. FIDO2 Keys can be purchased through the University at Security Key | Information Technology Services. Alternatively, for a list of vendors with known-compatible FIDO2 keys, see: Azure Active Directory passwordless sign-in - Microsoft Entra | Microsoft Learn.
Synced Passkey
Synced passkeys are securely stored in a cloud-based password manager and synchronized across a user's trusted devices. Unlike device-bound passkeys, synced passkeys can be used from multiple devices within the same ecosystem, making them convenient for users who regularly work across computers, tablets, and smartphones. For example, if you create a passkey on your phone, you may also be able to use it on your tablet or computer because the passkey is securely shared between those devices through your device's cloud account.
Types of Synced Passkeys include:
- Apple iCloud Keychain: An iCloud Keychain passkey is a synced passkey securely stored in a user's iCloud Keychain and synchronized across their trusted Apple devices. This allows users to sign in without a password using a passkey available on their iPhone, iPad, or Mac. Because the passkey is synced through iCloud, it can be accessed on multiple devices while remaining protected by Apple's security and encryption technologies.
- Google Password Manager: A Google Password Manager passkey is a synced passkey that is securely stored in a user's Google Account and synchronized across signed-in devices. This allows users to sign in without a password using passkeys available on Android devices and supported Chrome browsers. Because the passkey is synced through Google Password Manager, users can access it from multiple devices while benefiting from strong security protections built into their Google Account.
- Microsoft Passkey Synchronization: A Microsoft-synced passkey is securely stored in a user's Microsoft account and synchronized across supported devices and Microsoft services. This enables users to sign in without a password using a passkey that is available wherever they are signed in with their Microsoft account. Because the passkey is synchronized through Microsoft's cloud services, users can access it across multiple devices while maintaining a secure and convenient sign-in experience.
Learn how to set up a synced passkey.
Other Authentication Methods in the Microsoft Authenticator App
- Microsoft Authenticator Push Notification: A push notification is sent to the Microsoft Authenticator app installed on your mobile device when accessing MFA protected services and apps on non-trusted computers. You will view the notification and select Approve to complete verification. If your phone is not connected to wi-fi or does not use mobile data, you will be prompted to enter a verification code (i.e. second credential) when accessing MFA protected services and apps on non-trusted computers, right after entering their password. The Microsoft Authenticator app is available for iOS and Android platforms and can be downloaded from Apple and Google app stores.
- Microsoft Authenticator Time-based One-time Passwords (TOTP): A time-based one-time password (TOTP) is a temporary verification code generated in the Microsoft Authenticator app on your mobile device. When prompted for MFA, open the app, select your University of Windsor account, and enter the current six-digit code to complete verification. This method can be used even when your phone does not have Wi-Fi or mobile data, but the Microsoft Authenticator app must already be set up on your device.
Note: In the fall of 2026, text message (SMS) to your mobile phone method will gradually phase out and will be discontinued by January 31, 2027.
Passkeys are becoming the new standard for secure authentication as they provide a faster, easier, and more secure way to access your university account while helping protect against phishing and other cyber threats.
New users have to set-up MS Authenticator push notification first before they can add their device-bound passkey or any other type of a passkey.
View this chart to help decide which passkey is best for you:
