TABLE OF CONTENTS


According to a recent Microsoft notification, all SMS and voice authentications will be retired permanently on February 1st, 2027. As part of our ongoing security improvements, Western Seminary will be phasing out SMS authentication with passkeys across Microsoft 365 and our Entra ID environment. This change aligns with Microsoft’s strategic direction — all newly created Microsoft accounts have been passwordless by default since May 2025, and Microsoft reports blocking over 7,000 password attacks per second, with more than 99% of identity attacks being password-based.
This email explains the two types of passkeys, the methods you can use to create them, and the step-by-step instructions for each. We also cover how to sign in on a device that doesn’t have your passkey using cross-device QR code authentication.

What Is a Passkey?

A passkey is a phishing-resistant credential built on the FIDO2 / WebAuthn standard. Instead of typing a password, you authenticate using biometrics (face or fingerprint), a device PIN, or a physical security key. Behind the scenes, a cryptographic key pair is used: the public key is registered with Microsoft Entra ID, and the private key stays securely on your device or synced provider. The private key is never shared, transmitted, or stored on Microsoft’s servers.
There are two categories of passkeys you can use:

Type 1: Device-Bound Passkeys

Device-bound passkeys store the private key on a single device only — it never leaves that device and cannot be synced elsewhere. This offers the highest level of security because the credential cannot be copied or intercepted in transit. If the device is lost, recovery requires a second registered authenticator.

Option A: Microsoft Authenticator App Passkey (Device-Bound)

The Microsoft Authenticator app stores a device-bound passkey directly on your phone (iOS 17+ or Android). This passkey cannot be synced — it lives only on that device.
How to set it up:
  1. Download Microsoft Authenticator from the App Store (iOS) or Google Play (Android).
  2. Open the app and sign in with your work or school account.
  3. Tap your account in the app, then navigate to Passkey registration.
  4. Follow the on-screen prompts — you’ll be asked to authenticate with Face ID, Touch ID, or your device PIN to create the passkey.
  5. The passkey is now stored on your phone. You can use it for same-device sign-in (opening Outlook in your phone’s browser, for example) or for cross-device sign-in (see the QR code section below).
Alternatively, you can register a passkey via aka.ms/mysecurityinfo. Sign in with your current credentials, click Add method → Passkey in Authenticator, and follow the prompts on your phone.


Option B: Windows Hello for Business (Device-Bound Platform Credential)

If you use an Entra-joined or Entra-registered Windows 10/11 PC, Windows Hello creates a device-bound passkey using your PC’s built-in hardware security module (TPM). You authenticate with facial recognition, fingerprint, or a Windows PIN — no password required.
How to set it up:
  1. On your Windows PC, go to Settings → Accounts → Sign-in options.
  2. Select Windows Hello Face, Fingerprint, or PIN.
  3. Follow the setup wizard. Your PC must be enrolled in Entra ID for this to serve as a passkey for organizational services.
  4. Once configured, when you sign in to Microsoft 365 or other Entra-integrated services from this PC, you’ll be prompted to authenticate with your chosen Windows Hello method.

Option C: FIDO2 Security Keys (Device-Bound)

physical FIDO2-certified security key (such as a YubiKey 5 Series) stores a device-bound passkey on the hardware key itself. The private key never leaves the physical device. This is ideal for users who cannot use a smartphone or prefer a tangible token.
How to set it up:
  1. Obtain a FIDO2-certified security key.
  2. Go to aka.ms/mysecurityinfo and sign in.
  3. Click Add method → select Security key.
  4. Insert the key into a USB port (or tap via NFC on supported devices).
  5. Follow the prompts to create a PIN for the key and touch the sensor when prompted to register.
  6. Once registered, you can use the security key to sign in by inserting/tapping it and entering the key’s PIN at the sign-in prompt.

Type 2: Synced Passkeys

Synced passkeys are stored in a cloud-synced passkey provider (such as Apple iCloud Keychain, Google Password Manager, or Proton Pass) and are automatically available across all your devices linked to that provider. This means if you create a passkey on your iPhone, it’s instantly usable on your Mac, iPad, or other Apple devices — and vice versa for Android/Chrome devices.
Microsoft recommends synced passkeys for all users due to their convenience and seamless cross-device availability.


Option D: Apple iCloud Keychain (Synced Passkey)

If you use an iPhone, iPad, or Mac, your passkey can be stored in iCloud Keychain and synced across all your Apple devices via Apple’s encrypted cloud sync.
How to set it up:
  1. Ensure iCloud Keychain is enabled on your Apple device: Settings → [Your Name] → iCloud → Passwords and Keychain (iOS) or System Settings → Apple ID → iCloud → Passwords and Keychain (macOS).
  2. Go to aka.ms/mysecurityinfo in Safari on your Apple device.
  3. Sign in with your current credentials and click Add method → Passkey.
  4. Safari will prompt you to save the passkey to iCloud Keychain — authenticate with Face ID or Touch ID.
  5. The passkey is now synced to all your Apple devices signed into the same Apple ID.
To sign in to Microsoft 365 from any Apple device afterwards, the browser will offer your saved passkey automatically — just authenticate with Face ID or Touch ID.


Option E: Google Password Manager (Synced Passkey)

If you use an Android device or Chrome browser, your passkey can be stored in Google Password Manager and synced across all devices signed into the same Google account.
How to set it up:
  1. Ensure you’re signed into your Google account in Chrome on your Android device or desktop.
  2. Go to aka.ms/mysecurityinfo in Chrome.
  3. Sign in and click Add method → Passkey.
  4. Chrome will prompt you to save the passkey to Google Password Manager — authenticate with your screen lock (biometric or PIN).
  5. The passkey is now synced to all devices signed into the same Google account via Chrome.

Option F: Third-Party Password Managers (Synced Passkey)

Supported third-party password managers — such as Proton Pass, 1Password, Dashlane, Bitwarden, and others that implement the passkey API — can also store and sync your passkeys.
How to set it up:
  1. Install your preferred password manager’s browser extension or mobile app.
  2. Ensure the password manager’s passkey feature is enabled (check the app’s settings).
  3. If using the mobile app, ensure your password manager is enabled for passkeys and autofill in your mobile device settings.
  4. If using a browser extension, ensure the password manager is unlocked
  5. Go to aka.ms/mysecurityinfo in your browser.
  6. Sign in and click Add method → Passkey.
  7. When prompted, select your password manager from the list of available passkey providers.
  8. Authenticate using your password manager’s unlock method (master password, biometric, or hardware key).
  9. The passkey is now stored and synced by your password manager across its supported devices.
Check with your password manager’s documentation to confirm passkey sync support for your specific plan and platform.

Cross-Device Authentication: Signing In with a QR Code

Sometimes you’ll need to sign in on a device that doesn’t have your passkey — for example, a shared workstation, a colleague’s laptop, or a new computer. In these cases, you can use cross-device authentication to approve the sign-in using your phone (where your passkey is stored) by scanning a QR code.
How It Works:
  1. Start by getting to a sign-in prompt on the device that doesn’t have your passkey.
  2. Before even entering your email address, click sign-in options. Select “Face, fingerprint, PIN or security key” (or similar wording)
  3. QR code appears on the computer screen.
  4. Open the camera app (or Microsoft Authenticator) on your phone and scan the QR code. (Your phone must be running iOS 17+ or a recent Android version.)
  5. If Bluetooth is enabled on both devices, a secure Bluetooth Low Energy (BLE) connection is established between your phone and the computer. This verifies physical proximity — ensuring you’re genuinely near the device you’re signing in to. (The devices do not need to be paired beforehand.)
  6. Make sure you do not have a VPN running on your mobile device, or it might not connect when you scan the QR code.
  7. Your phone will display a confirmation prompt. Unlock using Face ID, Touch ID, fingerprint, or PIN to authorize the sign-in.
  8. The private key on your phone signs the authentication challenge without the key ever leaving your device, and the signed assertion is relayed back to the computer — either via the BLE link or through Microsoft’s cloud service (if Bluetooth is unavailable).
  9. The computer receives the signed assertion and completes the sign-in. You’re now logged in.
Important Notes for Cross-Device Authentication
  • Bluetooth is recommended but not strictly required. If Bluetooth is off, the QR code alone can facilitate sign-in — the signed assertion is relayed through Microsoft’s cloud service rather than a direct BLE connection. However, enabling Bluetooth provides an additional layer of proximity-based security.
  • Both devices need internet access — the phone (to receive and respond to the challenge) and the computer (to submit the sign-in request).
  • The passkey never leaves your phone during this process. The QR code simply establishes a secure session between the two devices; the private key stays on your phone at all times.
  • This method works with Microsoft Authenticator passkeys, iCloud Keychain passkeys, Google Password Manager passkeys, and third-party passkeys (e.g. Proton Pass), as long as the passkey provider on your phone supports the cross-device flow.

Quick Setup Checklist
Step
Action
✅ 1
Choose your preferred passkey method from the options above
✅ 2
Go to aka.ms/mysecurityinfo to register your passkey
✅ 3
Set up a backup method (e.g., a second passkey on a different device/provider, or a security key)
✅ 4
Test signing in using your new passkey at office.com
✅ 5
Test cross-device QR code sign-in from a different device

Recommendation Summary
User Type
Recommended Passkey Method
Type
Standard users (Apple ecosystem)
iCloud Keychain passkey
Synced
Standard users (Google/Android)
Google Password Manager passkey
Synced
Standard users (mixed/cross-platform)
Third-party password manager passkey
Synced
Standard users (mixed/cross-platform)
Microsoft Authenticator passkey or FIDO2 security key
Device-bound
Windows PC users
Windows Hello for Business
Device-bound

Important Dates
Milestone
Date
Milestone
Passkey registration opens
September 1, 2026
Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in.
Passwords disabled for all accounts
February 1, 2027
Microsoft provided SMS and Voice fully retired in Microsoft Entra ID
All users must have ≥ 1 passkey + 1 backup method
After February 1, 2027
Users whose only available MFA method is SMS or voice will be required to register a passkey during sign-in to continue accessing their account. This prompt will be blocking. Users must register a passkey before they can continue to sign in to their account.
There is no opt out from this February 1 behavior. It will be enforced for all tenants.