What is a passkey?

Summary

Passkeys provide a more secure, phishing-resistant way to verify your identity when signing in. Instead of entering a code or approving a notification, a passkey uses cryptographic security and confirms your identity using a trusted device, such as your phone, computer, or security key, along with a fingerprint, facial recognition, or PIN. Because the passkey is tied to the legitimate website and cannot be intercepted or reused by attackers, it helps protect your account from phishing attacks, p

Body

Question

What is a passkey?

Answer

A passkey provides a more secure, phishing-resistant way to verify your identity when signing in. Instead of entering a code or approving a notification, a passkey uses cryptographic security and confirms your identity using a trusted device, such as your phone, computer, or security key, along with a fingerprint, facial recognition, or PIN. Because the passkey is tied to the legitimate website and cannot be intercepted or reused by attackers, it helps protect your account from phishing attacks, password theft, and fraudulent sign-in requests while providing a simpler and faster sign-in experience.

NOTE: Passkeys became the default Microsoft Entra authentication on September 1, 2026.

There are two different categories of passkeys:

  1. device‑bound passkey (including those stored locally in Microsoft Authenticator or on a security key) is tied to a single device or authenticator instance and does not sync, meaning it must be re‑registered on each new device.
  2. In contrast, a synced passkey for a Microsoft work or school account is a phishing‑resistant sign‑in credential (based on FIDO2) that is securely saved in a cloud‑backed credential manager—such as iCloud Keychain, or Google Password Manager—and automatically syncs across your devices, so you can use it even if you change or lose a device.

Both use biometrics or a PIN to prove your identity and are resistant to phishing, but synced passkeys prioritize convenience and portability across devices (most suitable for regular users), while device‑bound passkeys provide tighter control by keeping the credential confined to one device (recommended for high-profile users and administrators with access to sensitive data). 

The following phishing‑resistant passkey-based MFA methods are currently supported for your Microsoft work/school account (UWin Account):

Passkeys are becoming the new standard for secure authentication as they provide a faster, easier, and more secure way to access your university account while helping protect against phishing and other cyber threats.

New users have to set up MS Authenticator push notifications before they can add their device-bound passkey or any other type of passkey.

View this chart to help decide which passkey is best for you:

Learn more about passkeys and other multi-factor authentication topics.

Details

Details

Article ID: 151707
Created
Thu 2/19/26 12:42 PM
Modified
Mon 9/21/26 3:43 PM

Related Articles

Related Articles (7)

The different authentication options available in the My Profile under “My Security Info” page exist to let users prove their identity using multiple methods, which strengthens account security and provides flexibility during sign‑in or account recovery. Instead of relying only on a password—which can be stolen or guessed—these options (such as the Microsoft Authenticator app or passkeys) add extra verification factors so that access requires something you know, have, or are.
Microsoft Authenticator is a free mobile app from Microsoft for iPhone, iPad, and Android devices that helps protect your UWin Account (Microsoft work/school account). Passwords alone are no longer enough to keep accounts secure. Microsoft Authenticator adds an extra layer of protection that helps prevent unauthorized access, even if someone else knows your password.
A device‑bound passkey stored locally in Microsoft Authenticator app on your mobile device is tied to a single device or authenticator instance and does not sync, meaning it must be re‑registered on each new device. It uses biometrics or a PIN to prove your identity and is resistant to phishing while providing tighter control than synced passkey by keeping the credential confined to one device.
Passkeys are the most secure method of authentication. There are two different types of passkeys: a synced passkey (automatically syncs across your devices) and a device‑bound passkey (tied to a single device). This article focuses on synced passkeys.
IT Services utilizes the Outlook Junk Email Filter to block delivery of unwanted emails to your inbox. This article explains how to check and set junk mail settings. It also explains how to report spam and suspected phishing messages.
Multi-Factor Authentication (MFA) combines two or more independent credentials - what you know (your password) with something you have (mobile phone) in order to create a second layer of security for your UWin Account. Even if someone knows your password, they will be prevented from accessing your account when it is protected by MFA.
Phishing scams are fake e-mails trying to trick users into actions on behalf of the scanner. This article shows how to recognize phishing messages, how to avoid them and what to do when you discover one.