MFA: Setting up Passkeys for Microsoft Authentication

Summary

This article explains several different ways to save Passkeys for logging into resources at USNH.  Passkeys are safer and more secure than passwords, and often easier to use as well! This article applies to all USNH account holders.

 

Types of Passkeys

A passkey lets you sign in without typing your password each time. It uses your device's built-in security, such as Face ID, fingerprint, screen lock, or device PIN. There are two primary types of passkeys – Synced Passkeys and Device-Bound Passkeys.

 

Synced Passkeys

The Apple Passwords app, Google Password Manager, and other password manager apps are examples of Synced Passkeys – the passkeys can exist in multiple places, wherever you can use that password manager.  

We recommend saving your passkey to: 

  • Apple Passwords (if you use iPhone)
  • Google Password Manager (if you use Android)

 

Device-Bound Passkeys

YubiKeys, Windows Hello, and Microsoft Authenticator are examples of Device-Bound passkeys – they can only exist on the device they were generated on.

 

Limitations

  • Passkeys work only on your device. If you sign in on a public computer or your friend’s computer, you will not be able to use your passkey. Some platforms will allow you to sync your passkey among your devices. For example, an iPhone and a Mac signed into the same Apple Account can share a passkey.
  • Passkeys do not work on certain applications. These include commonly used applications such as LockDown Browser and Microsoft Remote Desktop.
  • Some browsers do not accept passkeys set up in other browsers. For example if you set up a passkey on Google Chrome, you might not be able to use it on Firefox, even if you are on the same device.

To avoid these issues, you should add another authentication method in addition to your passkey. You can use your passkey on devices and services that support it, but then use your other method in other situations.

 

How-To

Before you Begin

Make sure you have: 

Do not create a passkey on: 

Your USNH full username, like jbd2519@usnh.edu

A public computer

Your current password

A shared family computer

Your current MFA method

A classroom or lab computer

A personal phone or computer that only you use

A friend's phone

 

Task for Apple devices only: Enable Passkey Syncing on iOS or macOS**

**Windows users with an Android device can skip this task.

Confirm your iCloud keychain is enabled if you want your passwords to sync across Apple devices.

Instructions for iPhone or iPad

Step 1 - Open Settings

Step 2 - Select your Name / Apple ID at the top

Step 3 - Tap iCloud

Step 4 - Tap Passwords or Passwords and Keychain 

Saved to iCloud page with Passwords app marked. Uploaded imageClick for full-size image

Step 5 - Confirm that the setting Sync this iPhone or Sync this iPad is enabled

 

Instructions for macOS computer

Step 1 - Open System Settings

Step 2 - Click your Apple Account

Step 3 - Click iCloud

Step 4 - Tap Passwords or See All > Passwords and Keychain 

Step 5 - Ensure that Sync this Mac is enabled

iCloud Passwords & Keychain settings with Sync this Mac marked. Uploaded imageClick for full-size image

 

Outcome

You have enabled passkey syncing on your iOS or macOS device.

 

Task: Create a new Passkey

You can register multiple passkeys for your USNH account.  Repeat this task as often as needed.

Instructions

Apple/Mac users - be sure to complete the task above first if you want to use synced passkeys across your iOS or macOS devices.

Step 1 - Open a web browser and visit https://myaccount.microsoft.com  

Step 2 - Expand My Account 

Step 3 - Select Security Info 

Step 4 - You will be prompted to sign in using MFA. If required, select or enter your username@usnh.edu (e.g. jbd2519@usnh.edu) and password. 

Step 5 - Once logged in, select Add sign-in method 

Step 6 - Select Passkey (not the "Passkey in Microsoft Authenticator" option)

Add sign-in passkey options.

 

Step 7 - Select Next and follow through the on-screen prompts. 

Step 8 -  Where you choose to save your passkey will affect whether it is a synced or device-bound passkey. The options you see depend on many factors such as what device you are using when creating the passkey, which browser on that device, and whether or not you use a password manager.  Some options you might see include:

  • This Windows device - to use Windows Hello, device-bound for that machine only.
  • iCloud Keychain - the default and most common option on macOS, synced if you have enabled iCloud sync as above.
  • iPhone, iPad, or Android device - save to a nearby mobile device via QR code/Bluetooth.
  • Use a phone, tablet, or security key - use another device or a hardware security key such as YubiKey.
  • Your browser profile - available in some browsers but not all.
    • Passkeys stored in a browser profile are usually device-bound, stored locally within THAT browser on THAT device.
    • To use this kind of passkey, you need to use the same browser on the same device when logging into your USNH resources.
  • A password manager (e.g., 1Password, Bitwarden, Google Password Manager) - if a third-party passkey manager browser extension is installed, synced where that manager is availabe.

 

Outcome

You have registered and saved a new passkey. Where you choose to save your passkey will affect whether it is a synced or device-bound passkey as described above.

 

Further Readings

MFA: Installing the Microsoft Authenticator App

MyAccount: Managing Account Verification Methods

MFA: Adding Backup Multi-Factor Authentication (MFA) Methods

MFA: Using Passwordless Sign In through Microsoft Authenticator 

MFA: Setting up YubiKey for Microsoft Authentication

Windows Hello: Configuring Windows Hello on Managed Windows Computers

 

Need additional help?

Visit the Technology Help Desk Support page to locate your local campus contact information or to submit an online technology support request.  For password issues you must call or visit the Help Desk in person.