Passkeys: What they are and how to create them
Passkeys are a new authentication method to replace passwords
What are Passkeys?
To sign into accounts, traditionally you use:
- Password
- + Multifactor authentication (MFA) method, eg. text / authenticator app code or voice call
Passkeys are a more secure method of authenticating using:
- Device, eg. computer, mobile phone or USB security key
- + PIN code or Biometrics (fingerprint / face ID)
Warning: Microsoft is moving away from less secure authentication methods such as SMS and voice calls by February 2027. Passkeys provide a more secure and convenient way to sign in, protecting your account from phishing and password theft.
How to create Passkeys for your diocesan Microsoft Account
Tip: We recommend creating a minimum of 2 passkeys, one on your diocesan computer and a second on your diocesan or personal mobile phone.
- Create a Passkey on Windows with Windows Hello >
- Create a Passkey on a Mobile with the Microsoft Authenticator app >
- Create a Passkey on Mac with iCloud Keychain >
🪟Create a Microsoft 365 Passkey on a Windows Computer with Windows Hello
For diocesan Windows computers, you can setup PIN and facial / fingerprint recognition by going to:
- ⚙️Settings
- Accounts
- Sign-in options
Tip: A full guide on Windows Hello can be found here:
📱Create a Microsoft 365 Passkey on a Mobile with the Microsoft Authenticator app
Note: You may use a personal mobile if you do not have a diocesan mobile.
Ensure you have setup a PIN code and, optionally, facial and/or fingerprint recognition on your mobile in the device settings.- Personal mobiles: Download the Microsoft Authenticator app from the Apple App Store or Google Play Store
- For diocesan mobiles, this app is already installed. Go to step 3.
- Open the Microsoft Authenticator app
- If your diocesan account is already listed, go to step 5. Otherwise:
- Tap Add account or select the + plus icon top right
- Choose Work or school account
- Sign in with your diocesan credentials
- Select your diocesan account
- Select Create a passkey
- If you see Passkey rather than Create a passkey then a passkey has already been created for this account. Skip to step 8.
- Authenticate your account again to create a passkey
- Ensure the Microsoft Authenticator app can manage your passkeys on your device:
- For iPhone/iPad (iOS)
- Open Settings
- Go to Passwords > Password Options
- or General > Autofill & Passwords on older versions
- Turn on AutoFill Passwords and Passkeys.
- Select Microsoft Authenticator as the default provider.
- For Android
- Open Settings
- Go to Passwords & passkeys
- or Passwords & accounts
- or System > Autofill service
- Under Additional providers, ensure Microsoft Authenticator is enabled.
- For iPhone/iPad (iOS)
- When signing in on your mobile device, the Microsoft Authenticator app will popup and you will authenticate using a PIN code, fingerprint or facial recognition.
- When signing in on another device, you may see a QR code. Scan the QR code with your mobile's camera and follow the steps on the mobile to sign in.
Tip: A full guide on Microsoft Authenticator passkeys can be found here:
🍎Create a Microsoft 365 Passkey on a Mac Computer with iCloud Keychain
Note: This method will work only for diocesan Mac users and Associates.
Go to https://mysignins.microsoft.com/security-info >
- It is recommended you use the Microsoft Edge web browser
- Sign in with your diocesan credentials
- Select Add sign-in method
- Select Passkey
- Select Next x2
- If asked for a security key, select Save another way
- When asked where to store the passkey, choose iCloud Keychain / Passwords
- Turn on iCloud Keychain if asked
- Authenticate with Touch ID or your Mac password
- Give your passkey a name, eg. Diocesan Mac
Tip: A full guide for passkeys on Mac can be found here: