Account Access - Passkeys: Requirements and FAQ

Find out whether you must use a passkey, how passkeys compare to Microsoft Authenticator, which devices and browsers are supported, and answers to common questions.

Authentication Options at SIUE

Microsoft is retiring SMS text message and voice call verification for Microsoft 365 accounts, including SIUE. If your only backup sign-in method is a text message or phone call, you will be prompted to register a new method when you sign in. To ensure your sign-in keeps working, you can replace them with Microsoft Authenticator, a passkey, or a hardware security key.

Microsoft Authenticator is the recommended method for most users and works as the primary sign-in method for your SIUE account. After you enter your password, you approve a push notification on your phone or enter a verification code from the app. It can also store a passkey for passwordless sign-in. Authenticator works on any device with the app installed, does not require Bluetooth, and keeps working on public and shared computers. Many users already have it installed. For setup see Microsoft Authenticator - Set Up and Use.

Passkeys are the natural next step if you use a capable personal device. They let you sign in without a password using a fingerprint, facial recognition, device PIN, or security key. Public machines: Passkeys require Bluetooth for cross-device sign-in, which does not work on most public machines such as labs, kiosks, and podiums. Microsoft Authenticator works on any device, so use it if you sign in from shared or public computers.

Hardware security keys (FIDO2, such as a YubiKey) are portable and work on any device with a USB port or NFC reader. They are a good choice if you prefer not to use a personal phone.

If a phone number was your only alternate method for self-service password reset, the retirement also affects your ability to reset your password on your own. See E-ID - Changing your E-ID password for what to do before the retirement takes effect.

FAQ: Which Authentication Method Should I Use?

Do I have to use a passkey?

No. Microsoft Authenticator is the recommended way to sign in to your SIUE Microsoft account. You can add a passkey as an additional sign-in method on most modern personal devices, or choose a hardware security key if you prefer not to use a personal phone. If you cannot use any of these methods, contact the ITS Help Desk.

How do Microsoft Authenticator and passkeys compare?

The Microsoft Authenticator app supports two distinct sign-in modes. Understanding the difference helps you choose the right one.

  • Push Notification (Standard MFA): You enter your SIUE password first, then approve a push notification on your phone (often by matching a two-digit number). Your password is still required.
  • Passkey (Stored in Authenticator): You skip the password entirely. Select the passkey sign-in option, authenticate with a biometric check (Face ID, Touch ID, or fingerprint), and the passkey proves your identity without transmitting a password.

Microsoft Authenticator is the recommended method because it works on any device, including public and shared computers. Passkeys are phishing resistant and faster, but they require a capable personal device and Bluetooth for cross-device sign-in. See Passkeys for an overview of your options and Account Access - Setting Up and Signing In with a Passkey for setup steps.

What is a hardware security key?

A hardware security key (FIDO2, such as a YubiKey) is a small physical device you plug into a USB port or tap against a phone's NFC reader. The passkey lives on the key itself, so it works on any device with a USB port or NFC reader and is not tied to a phone. It is a common choice if you prefer not to use a personal device for authentication.

Hardware security keys cannot be used for password reset. Keep a second registered method such as Microsoft Authenticator, or contact the Help Desk to reset your password.

What if I cannot use any of these methods?

Contact the ITS Help Desk before February 1, 2027. ITS can review your situation, including accessibility needs, and identify the method that works best for you.

 To the top

FAQ: Devices and Scenarios

What if I do not own a smartphone?

If you have a supported Windows PC, you can use a passkey through Windows Hello. A passkey on your PC only signs you in to Microsoft services like email, Blackboard, and Cougarnet. It does not change how you sign in to the computer itself.

If your device does not support passkeys, contact the ITS Help Desk for alternatives.

What if my device does not support passkeys?

Passkeys require a recent operating system (a recent version of iOS or Android, or a supported version of Windows or macOS). If your device is older, you can still use Microsoft Authenticator for sign-in approvals and verification codes. Authenticator works on older devices that cannot create or store passkeys.

If you are not sure whether your device is supported, check the compatibility tables below or contact the ITS Help Desk.

Can I use a passkey on my computer?

Yes. Windows PCs support passkeys through Windows Hello. You can use a PIN, fingerprint, or facial recognition to unlock a passkey for signing in to websites and services.

Note: At SIUE, Windows Hello for Business is disabled. You will still sign in to your Windows PC with your normal username and password. A passkey on your PC is used only for signing in to Microsoft services, not for signing in to the computer itself. See Account Access - Setting Up and Signing In with a Passkey for setup instructions.

What happens if I get a new phone?

If you saved your passkey in the Microsoft Authenticator app, it should be available when you sign in to Authenticator on a new phone with the same Microsoft account. If it is not, you can register a new passkey using the setup guide for your device.

If your old phone is lost or being replaced, follow the steps to remove the old passkey and register your new device in Managing Passkeys: New and Multiple Devices.

What if I prefer not to use a personal phone?

If you do not want to use a personal mobile device for account authentication, contact the ITS Help Desk to ask about options such as a hardware security key.

A hardware security key (FIDO2) is portable and works with any device that has a USB port or NFC reader. It is not tied to a phone, so it is a common choice if you prefer not to use a personal device. Hardware security keys cannot be used for password reset. Keep a second registered method such as Microsoft Authenticator, or contact the Help Desk to reset your password.

What if mobile devices are not permitted?

If your workplace does not allow mobile devices, a hardware security key is the most practical option. It works on any computer with a USB port or NFC reader and does not require a phone. Contact the ITS Help Desk to ask whether a hardware security key is right for you.

What accessibility options are available?

Microsoft Authenticator works with screen readers and has options for users with physical accessibility needs. Windows Hello passkeys can use a PIN, fingerprint, or facial recognition. Hardware security keys can use a PIN or fingerprint. Some users find these easier than typing a password.

If standard options do not fit your needs, contact the ITS Help Desk. ITS can review your situation and identify the method that works best for you.

What if I am traveling or do not have cellular service?

Passkeys typically do not require a text message or phone call to complete the sign-in process. As long as you have access to your registered device and can complete the local authentication step (fingerprint, face, or PIN), you do not need a text message or phone call. You still need internet access (Wi-Fi or cellular) and your registered device.

 To the top

FAQ: Passkeys and Security

What is a passkey?

A passkey is a modern sign-in method that allows you to access your SIUE Microsoft account using a fingerprint, facial recognition, device PIN, or security key instead of entering a password. See Passkeys for a full explanation of how passkeys work and why SIUE is moving to them.

Do passkeys replace my password?

For day-to-day sign-ins to Microsoft services such as Blackboard, email, and Cougarnet, a passkey allows you to sign in without entering your password. However, you will still need your password to sign in to campus computers. Passkeys do not change how you sign in to your Windows PC.

Your password may also be required for account recovery, initial setup, or certain legacy authentication processes.

Are passkeys more secure than SMS text messages or phone calls?

Yes. Passkeys are designed to resist phishing attacks and cannot be captured through fake sign-in pages in the same way passwords or one-time verification codes can be.

Will passkeys work with all SIUE services?

Passkeys are designed to work with services that support modern authentication, including Microsoft 365, Blackboard, and Cougarnet.

Should I remove my existing authentication methods after creating a passkey?

ITS recommends keeping additional authentication methods available while transitioning to passkeys. Maintaining alternative sign-in methods can simplify account recovery if your primary device becomes unavailable.

Can I have more than one passkey?

Yes. Microsoft allows users to register multiple sign-in methods. ITS recommends registering passkeys on more than one device so you always have a backup way to sign in. See Managing Passkeys: New and Multiple Devices for guidance.

 To the top

Compatibility

The tables below are reference material for passkey support. Microsoft Authenticator itself works on any device with the app installed, regardless of the details below.

Requirements vary by platform and device. If you are unsure whether your device or browser supports passkeys, contact the ITS Help Desk.

Browser Support

Most modern browsers support passkeys. The table below shows which browsers support registering and signing in with a passkey on SIUE Microsoft services.

Browser Support Table
Browser Same-Device Sign-In Cross-Device Sign-In Notes
Microsoft Edge Yes Yes Microsoft recommended browser on Windows.
Google Chrome Yes Yes Works on Windows, macOS, Android.
Safari Yes Yes Best experience on macOS and iOS. Requires macOS 13.5+ or iOS 16+.
Firefox Partial Partial Limited support. Avoid for passkey registration or sign-in.

Operating System Support

OS Support Table
Operating System Passkey Support Minimum Version Notes
iOS Yes iOS 16 Passkeys stored in iCloud Keychain. Syncs to other Apple devices signed in to the same Apple ID.
iPadOS Yes iPadOS 16 Same as iOS. Passkeys stored in iCloud Keychain.
macOS Yes macOS 13.5 (Ventura) Passkeys stored in iCloud Keychain when using Safari or Chrome.
Android Yes Android 14 Passkeys stored in Google Password Manager. Syncs to other Android devices signed in to the same Google account.
Windows Yes Windows 10 (22H2) or Windows 11 Passkeys stored locally with Windows Hello. Does not sync to other devices.

Device Support

Device Support Table
Device Type Passkey Support How Passkeys Are Stored Syncs To Other Devices
iPhone Yes iCloud Keychain Yes (Apple devices, same Apple ID)
iPad Yes iCloud Keychain Yes (Apple devices, same Apple ID)
Mac Yes iCloud Keychain Yes (Apple devices, same Apple ID)
Android Phone Yes Google Password Manager Yes (Android devices, same Google account)
Android Tablet Yes Google Password Manager Yes (Android devices, same Google account)
Windows PC Yes Windows Hello (local) No
Hardware Security Key Yes On the key itself No (works on any device you plug it into)

Important Notes About Sync

  • Apple devices sync automatically. If you register a passkey on your iPhone and have iCloud Keychain enabled, the passkey is available on your iPad and Mac when signed in to the same Apple ID.
  • Android devices sync automatically. If you register a passkey on one Android device, it is available on your other Android devices signed in to the same Google account.
  • Windows does not sync. A passkey registered on one Windows PC stays on that PC. If you have multiple Windows computers, register a passkey on each one separately.
  • Cross-platform does not sync. A passkey stored on your iPhone does not appear on your Windows PC. Apple and Google password managers do not share passkeys with each other or with Windows.
  • Hardware security keys are portable. A FIDO2 security key (such as a YubiKey) works on any device with a USB port or NFC reader. The passkey lives on the key itself, not on the device.

Need Additional Support?

If you have any questions or need further assistance, please contact the ITS Help Desk:

This guide aims to provide useful information, but as technology changes, interfaces or steps might vary. Please use the Comment button to let us know if anything differs from your experience. Your feedback helps us keep this information accurate. Thank you!



Keywords:
passkey, passkeys, FAQ, frequently asked questions, requirements, exceptions, alternative, authentication, compatibility, browser, operating system, device, Microsoft Authenticator, push notification, MFA, password, security key, FIDO2, accessibility, smartphone, SMS, retirement 
Doc ID:
163170
Owned by:
Jeff P. in Southern Illinois University Edwardsville
Created:
2026-08-06
Updated:
2026-08-13
Sites:
Southern Illinois University Edwardsville