Account Access - Passkeys
Microsoft is retiring SMS and voice verification for Microsoft 365 accounts. If you currently verify your sign-in with a text message or phone call, you must move to a supported authentication method before February 1, 2027.
For most SIUE users, Microsoft Authenticator is the recommended starting point. It works on nearly any smartphone and does not require Bluetooth. Passkeys need Bluetooth for cross-device sign-in, which does not work on most public machines such as labs, kiosks, and podiums.
After you have Microsoft Authenticator configured, you may also add a passkey. Passkeys provide a faster sign-in experience and use your device's built-in security features, such as a fingerprint, facial recognition, device PIN, or security key. They are becoming the standard approach to account security and help future-proof your sign-in experience as passwords, SMS verification, and other legacy methods are phased out.
What Is a Passkey?
A passkey is a modern sign-in method that lets you access your SIUE Microsoft account without entering a password. Instead of typing a password and entering a code, you verify your identity using the same method you use to unlock your device:
- Facial recognition or fingerprint scans
- A secure device PIN
- A physical security key
Passkeys are designed to be more secure and resistant to phishing attacks than traditional passwords.
Why Use Passkeys?
Major technology providers, including Microsoft, are moving toward phishing-resistant authentication methods and away from less secure methods such as SMS text messages and voice calls. SMS and voice methods are vulnerable to interception, SIM-swapping, and phishing.
Passkeys are phishing resistant. Authenticator is the easiest choice for most users because it works on any device; passkeys add passwordless convenience on devices that support them.
Passkeys tie the credential to the application, so they cannot be captured through fake sign-in pages. Sign-in is faster, does not require waiting for a text or entering a code, and removes the risks tied to weak, reused, or compromised passwords.
Important Dates
Microsoft is retiring SMS text message and voice call verification for Microsoft 365 accounts. Here is what to expect:
- September 1, 2026: Users who still sign in with a text message or phone call will be prompted to register a passkey at every sign-in. You can dismiss the prompt for now, but it will appear again at your next sign-in.
- February 1, 2027: SMS and voice call verification will stop working. A passkey, Microsoft Authenticator, or another supported method will be required to sign in.
To avoid disruption, set up Microsoft Authenticator or register a passkey before September 1, 2026.
If a phone number was your only alternate method for self-service password reset, the retirement affects your ability to reset your password on your own. See E-ID - Changing your E-ID password for what to do.
What Should I Do?
Set up Microsoft Authenticator, or register a passkey on at least one capable device, before September 1, 2026.
You do not need to remove your existing sign-in methods right away. ITS recommends keeping at least one additional method on your account while you transition. If you lose access to your phone or passkey device, an alternate method can help you regain access without visiting the Help Desk.
Recommended setup: Install Microsoft Authenticator on your phone as your primary method. If your device supports passkeys, add a passkey as an additional sign-in method for passwordless sign-in. This gives you a backup if one device is lost, broken, or unavailable.
Where Are Passkeys Stored?
Passkeys are generated and stored on your devices or in secure credential systems. Depending on your setup, they may be stored in:
- Microsoft Authenticator app (on iOS or Android)
- Windows Hello (on a Windows PC)
- Apple iCloud Keychain (on Mac, iPhone, or iPad)
- Google Password Manager (on Android or Chrome)
Passkeys on your phone sync through iCloud Keychain or Google Password Manager, so a new phone of the same type picks up your passkey automatically. Passkeys on Windows do not sync; they stay on that computer. See Account Access - Passkeys: Requirements and FAQ for the full list of supported browsers, operating systems, and devices.
Guides
Select a topic below to find the guide you need.
Setup & Usage
- Microsoft Authenticator - Set Up and Use — install the app, add your SIUE account, approve sign-in requests, and use verification codes. Works on any device.
- Account Access - Setting Up and Signing In with a Passkey — set up a passkey on your iPhone, Android device, or Windows PC, and sign in with it. Includes the migration timeline for text message and phone call retirement.
Device Management
- Managing Passkeys: New and Multiple Devices — register passkeys on more than one device as a backup, and replace or upgrade a phone that has passkeys.
Support & Recovery
- Troubleshooting Passkey Errors — fix common passkey issues, including sign-in problems, QR code errors, and browser compatibility.
- Account Recovery: Lost All Sign-In Methods — regain access when you have lost your phone, passkey, and any other way to verify your identity.
Reference
- Account Access - Passkeys: Requirements and FAQ — compare authentication methods, see supported devices and browsers, and find answers to common questions.
Need Additional Support?
If you have any questions or need further assistance, please contact the ITS Help Desk:
- Call: (618) 650-5500
- Email: help@siue.edu
- Visit: Lovejoy Library Room 0005 during regular business hours.
This guide aims to provide useful information, but as technology changes, interfaces or steps might vary. Please use the Comment button to let us know if anything differs from your experience. Your feedback helps us keep this information accurate. Thank you!
