Completing Passkey Prompt — Microsoft Authenticator


 

Setting Up Your Passkey Using Microsoft Authenticator

Follow the steps below to set up a passkey for your University of Guelph account with Microsoft Authenticator. 

Please note that there are some important requirements to use passkeys with the Microsoft Authenticator app on your mobile device:

 

This guide provides two separate methods for setting up Microsoft Authenticator with a passkey: 

Setup for users with Microsoft Authenticator as their primary MFA method
&
Setup for users who do not currently have Microsoft Authenticator installed

 

Setup for users with Microsoft Authenticator as their primary MFA method

Step 1 — Enable Microsoft Authenticator as the preferred passkey service

  1. For ANDROID
    1. Navigate to Settings > Security and privacy > More Security Settings > Passwords, passkeys and autofill
    2. If you have Microsoft Authenticator installed, you should see it listed among the other installed authenticator services on your phone. Besides the "Preferred service", you can select the gear icon, and then set "Microsoft Authenticator" as the preferred service
  2. For APPLE
    1. On iOS 18: Navigate to Settings > General > Autofill & Passwords OR on iOS 17: Navigate to Settings > Passwords > Password Options
    2. Turn on "AutoFill Passwords and Passkeys" and under "Autofill From", select Microsoft Authenticator.

Step 2 — Create Passkey on your Mobile Device

  1. Within the Microsoft Authenticator app, tap on your University of Guelph account. 

  2. Choose ‘Create a passkey’ and then the "Sign in" option when prompted to create your passkey, and follow the prompts to sign-in.

  3. You will then be prompted to use your screen lock to create a passkey (this may be a passphrase/PIN, pattern, fingerprint or face ID, depending on the method you have set on your phone)

  4. After completing the screen lock, you will receive a prompt saying "Passkey created", at which point you can select "Done"

Step 3 — Setup Passkey as Default Authentication Method

  1. Log into your U of G M365 account by visiting https://mysignins.microsoft.com/
  2. Choose the "Security info" option on the left navigation bar.
  3. From the ‘Security info’ page, look for ‘Default sign-in method' and click on the word ‘Change’. 

  4. You will be presented with a drop-down list of your configured MFA methods. Choose ‘App based authentication or hardware token - code’. 

  5. Your M365 account is now secured with passkey authentication. 

 

Important Note: It may take up to an hour for the changes above to fully take effect. On your next login, if you are not prompted to use your passkey, you will still be able to log in using your password and the six-digit one-time password code found in Microsoft Authenticator for your account.

 

 

 

Step 1 — Install Microsoft Authenticator

  1. Download the Microsoft Authenticator app from the App Store (iOS) or Google Play Store (Android).
  2. Install the app on your mobile device.

Step 2 — Enable Microsoft Authenticator as the preferred passkey service

  1. For ANDROID
    1. Navigate to Settings > Security and privacy > More Security Settings > Passwords, passkeys and autofill
    2. If you have Microsoft Authenticator installed, you should see it listed among the other installed authenticator services on your phone. Besides the "Preferred service" you can select the gear icon, and then set "Microsoft Authenticator" as the preferred service
  2. For APPLE
    1. On iOS 18: Navigate to Settings > General > Autofill & Passwords OR on iOS 17: Navigate to Settings > Passwords > Password Options
    2. Turn on "AutoFill Passwords and Passkeys" and under "Autofill From", select Microsoft Authenticator.

Step 3 — Add Your U of G Account

  1. Open the Microsoft Authenticator app.
  2. Tap the "+" icon to add a new account.
  3. Select "Work or school account" and then the "Sign in" option, and follow the prompts to add your U of G account.

Step 4 — Adding the Passkey

  1. After you've successfully added your U of G account, you should receive a prompt saying "Lets secure your account", allowing you to press "Continue"

     

  2. You will then be prompted to use your screen lock to create a passkey (this may be a passphrase/PIN, pattern, fingerprint or face ID, depending on the method you have set on your phone)

  3. After completing the screen lock, you will receive a prompt saying "Account added", at which point you can select "Done"

 

Step 5 — Setup Passkey as Default Authentication Method

  1. Log into your U of G M365 account by visiting https://mysignins.microsoft.com/
  2. Choose the "Security info" option on the left navigation bar.
  3. From the ‘Security info’ page, look for ‘Default sign-in method' and click on the word ‘Change’. 

  4. You will be presented with a drop-down list of your configured MFA methods. Choose ‘App based authentication or hardware token - code’. 

  5. Your M365 account is now secured with passkey authentication. 

 

Important Note: It may take up to an hour for the changes above to fully take effect. On your next login, if you are not prompted to use your passkey, you will still be able to log in using your password and the six-digit one-time password code found in Microsoft Authenticator for your account.

 


Your New and Improved Login Experience

Once the changes you have made to your account fully take effect, your login experience to U of G services will change. The next time you log in, after entering your U of G username (your central login ID @ uoguelph.ca or @guelphhumber.ca), you will be prompted to use your passkey instead of entering your password.  From the authentication page, ensure ‘iPhone, iPad, or Android device’ is selected and click ‘Next’.

Now, open the Microsoft Authenticator app on your mobile device and click the ‘Scan QR code’ button on the bottom right and scan the QR code on screen. Review the sign-in information presented to verify your account and the service you are logging into and click ‘Continue’.

 

 

 

Create your own Knowledge Base