Passkeys: What they are and how to create them
Passkeys are a new authentication method to replace passwords
What are Passkeys?
Traditionally, you sign in by providing both of the following:
- Password
- Multifactor authentication (MFA) such as a text, authenticator app code, or phone call
Passkeys are a more secure alternative. They replace both the password and MFA code with a sign-in credential stored on a trusted device, security key, or approved password manager, unlocked using a PIN, fingerprint, or facial recognition.
How to create Passkeys for your diocesan Microsoft Account
Tip: We recommend creating a minimum of 2 passkeys, one on your diocesan computer and a second on your diocesan or personal mobile phone.
- Create a Passkey on Windows with Windows Hello >
- Create a Passkey on a Mobile with the Microsoft Authenticator app >
- Create a Passkey on Mac with iCloud Keychain >
🪟Create a Microsoft 365 Passkey on a Windows Computer with Windows Hello
For diocesan Windows computers, you can setup PIN and facial / fingerprint recognition by going to:
- ⚙️Settings
- Accounts
- Sign-in options
Tip: A full guide on Windows Hello can be found here:
📱Create a Microsoft 365 Passkey on a Mobile with the Microsoft Authenticator app
Note: You may use a personal mobile if you do not have a diocesan mobile.
Passkeys in the Microsoft Authenticator app require a device running at least iOS 17 or Android 14.
Ensure you have setup a PIN code and, optionally, facial and/or fingerprint recognition on your mobile in the device settings.- Personal mobiles: Download the Microsoft Authenticator app from the Apple App Store or Google Play Store
- For diocesan mobiles, this app is already installed. Go to step 3.
- Open the Microsoft Authenticator app
- If your diocesan account is already listed, go to step 5. Otherwise:
- Tap Add account or select the + plus icon top right
- Choose Work or school account
- Sign in with your diocesan credentials
- Select your diocesan account
- Select Create a passkey
- If you see Passkey rather than Create a passkey then a passkey has already been created for this account. Skip to step 8.
- Authenticate your account again to create a passkey
- Ensure the Microsoft Authenticator app can manage your passkeys on your device:
- For iPhone/iPad (iOS)
- Open Settings
- Go to Passwords > Password Options
- or General > Autofill & Passwords on older versions
- Turn on AutoFill Passwords and Passkeys.
- Select Microsoft Authenticator as the default provider.
- For Android
- Open Settings
- Go to Passwords & passkeys
- or Passwords & accounts
- or System > Autofill service
- Under Additional providers, ensure Microsoft Authenticator is enabled.
- For iPhone/iPad (iOS)
- When signing in on your mobile device, the Microsoft Authenticator app will popup and you will authenticate using a PIN code, fingerprint or facial recognition.
- When signing in on another device, you may see a QR code. Scan the QR code with your mobile's camera and follow the steps on the mobile to sign in.
Tip: A full guide on Microsoft Authenticator passkeys can be found here:
🍎Create a Microsoft 365 Passkey on a Mac Computer with iCloud Keychain
Note: This method will work only for diocesan Mac users and Associates.
Go to https://mysignins.microsoft.com/security-info >
- It is recommended you use the Microsoft Edge web browser
- Sign in with your diocesan credentials
- Select Add sign-in method
- Select Passkey
- Select Next x2
- If asked for a security key, select Save another way
- When asked where to store the passkey, choose iCloud Keychain / Passwords
- Turn on iCloud Keychain if asked
- Authenticate with Touch ID or your Mac password
- Give your passkey a name, eg. Diocesan Mac
Tip: A full guide for passkeys on Mac can be found here: