Body
Question
What is a device-bound passkey?
Answer
A device-bound passkey is stored on the device and can only be used from the device where it was created. It cannot be synchronized to other devices and typically provides stronger device-specific security. When you sign in, the device (or security key) verifies your identity using a fingerprint, face recognition, or PIN. Types of Device-Bound Passkeys Available for UWindsor Accounts:
- Passkey in Microsoft Authenticator App (Recommended): A passkey in Microsoft Authenticator is a device-bound passkey stored securely in the Microsoft Authenticator app on your mobile device. It uses cryptographic authentication and verifies your identity using your phone’s fingerprint, face recognition, or device PIN. When signing in, you may be prompted to scan a QR code or approve the sign-in through Authenticator, allowing you to securely access University resources without using a text message code or traditional push notification. The passkey remains protected on your phone and is not stored on the computer you are signing in from. Learn how to set up a passkey in Microsoft Authenticator.
- Passkey in Other Authenticator Apps: A passkey in other third-party authenticator app is a cryptographic credential stored securely within a supported authentication app on your mobile device. It verifies your identity using your phone’s fingerprint, face recognition, or device PIN and provides a secure, passwordless sign-in experience. When signing in, you may be prompted to scan a QR code or approve the sign-in through the authenticator app, allowing you to securely access University resources without using a text message code or traditional push notification. The passkey remains protected on your mobile device and is not stored on the computer you are signing in from. Examples of authenticator apps that may support passkeys include Google Password Manager, 1Password, Bitwarden, Dashlane, and other FIDO2-compatible authentication applications.
- Windows Hello for Business: Windows Hello for Business is Microsoft's enterprise authentication solution that uses biometrics (face or fingerprint), a PIN, or both, backed by cryptographic keys stored on the device, to provide passwordless access to corporate resources. If you have a university-owned or research-funded, primary user Windows OS (PC) device, this method is automatically set up for you.
- FIDO2 Security Key: A FIDO Security Key is a physical hardware device (USB) that stores cryptographic credentials and is used to authenticate users through a simple action such as touching or inserting the key. FIDO2 Keys can be purchased through the University at Security Key | Information Technology Services. Alternatively, for a list of vendors with known-compatible FIDO2 keys, see: Azure Active Directory passwordless sign-in - Microsoft Entra | Microsoft Learn.