Skip to content
English
  • There are no suggestions because the search field is empty.

Passkeys: What they are and how to create them

Passkeys are a new authentication method to replace passwords

What are Passkeys?

To sign into accounts, traditionally you use:

  1. Password
  2. + Multifactor authentication (MFA) method, eg. text / authenticator app code or voice call

Passkeys are a more secure method of authenticating using:

  1. Device, eg. computer, mobile phone or USB security key
  2. + PIN code or Biometrics (fingerprint / face ID)

Warning: Microsoft is moving away from less secure authentication methods such as SMS and voice calls by February 2027. Passkeys provide a more secure and convenient way to sign in, protecting your account from phishing and password theft.

 


How to create Passkeys for your diocesan Microsoft Account

Tip: We recommend creating a minimum of 2 passkeys, one on your diocesan computer and a second on your diocesan or personal mobile phone.


🪟Create a Microsoft 365 Passkey on a Windows Computer with Windows Hello

windows-11-start-pngFor diocesan Windows computers, you can setup PIN and facial / fingerprint recognition by going to:

  1. ⚙️Settings
  2. Accounts
  3. Sign-in options

Tip: A full guide on Windows Hello can be found here:



📱Create a Microsoft 365 Passkey on a Mobile with the Microsoft Authenticator app

Note: You may use a personal mobile if you do not have a diocesan mobile.

  1. msauth-1Ensure you have setup a PIN code and, optionally, facial and/or fingerprint recognition on your mobile in the device settings.
  2. Personal mobiles: Download the Microsoft Authenticator app from the Apple App Store or Google Play Store
    1. For diocesan mobiles, this app is already installed. Go to step 3.
  3. Open the Microsoft Authenticator app
  4. If your diocesan account is already listed, go to step 5. Otherwise:
    1. Tap Add account or select the + plus icon top right
    2. Choose Work or school account
    3. Sign in with your diocesan credentials
  5. Select your diocesan account
  6. Select Create a passkey
    1. If you see Passkey rather than Create a passkey then a passkey has already been created for this account. Skip to step 8.
  7. Authenticate your account again to create a passkey
  8. Ensure the Microsoft Authenticator app can manage your passkeys on your device:
    1. For iPhone/iPad (iOS)
      1. Open Settings
      2. Go to Passwords > Password Options
        1. or General > Autofill & Passwords on older versions
      3. Turn on AutoFill Passwords and Passkeys.
      4. Select Microsoft Authenticator as the default provider.
    2. For Android
      1. Open Settings
      2. Go to Passwords & passkeys
        1. or Passwords & accounts
        2. or System > Autofill service
      3. Under Additional providers, ensure Microsoft Authenticator is enabled.
  9. When signing in on your mobile device, the Microsoft Authenticator app will popup and you will authenticate using a PIN code, fingerprint or facial recognition.
  10. When signing in on another device, you may see a QR code. Scan the QR code with your mobile's camera and follow the steps on the mobile to sign in.

Tip: A full guide on Microsoft Authenticator passkeys can be found here:


🍎Create a Microsoft 365 Passkey on a Mac Computer with iCloud Keychain

Note: This method will work only for diocesan Mac users and Associates.

  1. apple-passwordsGo to https://mysignins.microsoft.com/security-info >
    1. It is recommended you use the Microsoft Edge web browser
  2. Sign in with your diocesan credentials
  3. Select Add sign-in method
  4. Select Passkey
  5. Select Next x2
  6. If asked for a security key, select Save another way
  7. When asked where to store the passkey, choose iCloud Keychain / Passwords
    1. Turn on iCloud Keychain if asked
  8. Authenticate with Touch ID or your Mac password
  9. Give your passkey a name, eg. Diocesan Mac

Tip: A full guide for passkeys on Mac can be found here: