Body
Objective
How to set up a passkey in the Microsoft Authenticator App
Procedure
A passkey in Microsoft Authenticator lets you use your smartphone as a secure, phishing-resistant sign-in method instead of relying on passwords, text messages, or approval prompts. When you sign in, Microsoft Authenticator verifies your identity using your phone's built-in security features, such as fingerprint, facial recognition, or device PIN, and securely confirms the sign-in without exposing credentials that could be intercepted by attackers. Because the passkey is stored on your phone and is cryptographically tied to the legitimate sign-in service, it provides stronger protection against phishing attacks while making sign-in faster and easier.
To use a passkey stored in MS Authenticator app on either a University-owned or a personal smartphone or tablet used for work or school you will need to:
- ensure your mobile device is running Android 14 or newer, or iOS/iPad OS 17 or newer and has Bluetooth enabled
- install MS Authenticator app on your mobile device and link it to your University account, if not already installed and linked
- configure MS Authenticator as a service for passkeys
- generate the passkey for your UWin Account
You will need to be at your work computer and have your mobile device with you to set up this option. Your mobile device does not have to be enrolled in Intune.
Step 1: Install Microsoft Authenticator on your phone
If this app is not yet installed on your mobile device, follow instructions in this KB article: Microsoft Authenticator - Getting started
Step 2: Complete passkey setup on your phone
First, you have to update your mobile device OS settings to allow Microsoft Authenticator to use passkeys. Note that these instructions are for the latest versions of mobile OS and that older version may not fully support passkeys.
Android
- Open your device OS Settings and go to Passwords, passkeys & accounts
- Select the Work tab
- Turn on Authenticator as a passkey provider
Optional but recommended on University devices:
- Make Authenticator to be the Preferred service for passkeys
- Turn off any other options in Additional services, for example Google.
|
|
iPhone/iPad
- Open your device OS Settings
- Tap General
- Tap AutoFill & Passwords
- Turn ON: AutoFill Passwords and Passkeys
- Under AUTOFILL FROM, make sure Microsoft Authenticator is selected
- Tap Go to Authenticator and proceed with Microsoft Authenticator and follow the instructions to generate a passkey below
Optional but recommended on University devices:
- deselect iCloud Keychain to have only Authenticator used for work passkeys
|
Next, you have to generate a passkey for your UWin Account in your Microsoft Authenticator app.
- Tap the Authenticator app icon to launch it. If you are using personal Android device, see a note below.
- Tap your University of Windsor account entry to display its full profile
- Select Create a passkey
- Follow instructions on your screen.
Personal device running Android: Swipe up on your home screen and select Work tab to launch your University-managed version of Microsoft Authenticator app. If this is the first time you are using the work version of Microsoft Authenticator, tap Allow > Accept > Continue > Setup work or school account. Follow instructions on the screen to add your University of Windsor account. You will then be able to remove it from the personal version of Microsoft Authenticator app.
✅ Your phone is now registered as a passkey.