Follow the steps below to set up a passkey for your University of Guelph account with Microsoft Authenticator.
You will need the latest version of the Microsoft Authenticator app.
Your device needs to be running Android 14 or later for Android devices, or iOS 17 or later for Apple devices. If your device is out of date, you may refer back to the Passkey Guide for instructions on out-of-date devices.
For cross-device authentication, both the device with the passkey and the device you're logging into must have Bluetooth enabled, along with an active internet connection.
Microsoft recommends using Microsoft Edge (version 109 or newer), Safari (version 16 or newer), or Chrome (version 109 or newer) to ensure proper functionality.
See the Microsoft compatibility matrix for more information.
This guide provides two separate methods for setting up Microsoft Authenticator with a passkey:
Setup for users with Microsoft Authenticator as their primary MFA method
&
Setup for users who do not currently have Microsoft Authenticator installed
Within the Microsoft Authenticator app, tap on your University of Guelph account.
Choose ‘Create a passkey’ and then the "Sign in" option when prompted to create your passkey, and follow the prompts to sign-in.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy8yNTk0MC8zMjc4NS9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSg1MCkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg4MzYyNTkwfX19XX0_&Signature=OEROZCULhulB8iTpdKQDv4IklwW9yLrF81iQneeNxVXqdDINEwBgtfxevCzZSsRMvwfAnjQASHsNe0Fc8QmeANpV~8J6IuUy0LBHCmSutgBJ-HR4xKHNFHQ7GNTKlmfEPCeGwaTUD2cqhwXYTIo~THZLWam44m49mSFZKBNu6n-eQ-9Clbi6hFXZGirMDVSEBJZmRCsMuO4W9pl~ymoFaxMeXN-tSSJ5j8yRuWPFJFBJjb~fzAEPB6jGFEevqkuS~Wi9hjFwMVx0pabLd3TN-Zh2PCcHSTiNru29vYny9U~951tQiQCqy3RL4dW5BWpGpYYlJ8h~ZgEY1LbWLgcZlg__&Key-Pair-Id=K2TK3EG287XSFC)

You will then be prompted to use your screen lock to create a passkey (this may be a passphrase/PIN, pattern, fingerprint or face ID, depending on the method you have set on your phone)
After completing the screen lock, you will receive a prompt saying "Passkey created", at which point you can select "Done"

From the ‘Security info’ page, look for ‘Default sign-in method' and click on the word ‘Change’.

You will be presented with a drop-down list of your configured MFA methods. Choose ‘App based authentication or hardware token - code’.

Your M365 account is now secured with passkey authentication.
Important Note: It may take up to an hour for the changes above to fully take effect. On your next login, if you are not prompted to use your passkey, you will still be able to log in using your password and the six-digit one-time password code found in Microsoft Authenticator for your account.


After you've successfully added your U of G account, you should receive a prompt saying "Lets secure your account", allowing you to press "Continue"
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy8yNTk0MC8zMjc4NS9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSg0OCkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg4MzYyNTkwfX19XX0_&Signature=VFPvU~XPXRRt6CY3YEOZfygRK-hEGg1IPzaawECi3bMtPPm~WRCnNWsYitBKUHXGaIS2IU16nzG8NjfwOTXt4dpjkJK-Q9~JkoYNuUVtV8RihQ-eEUjH17k2XY9TFnK9y9D4pNCoVXpg6gBseAI1gZoMOUu6xAA8zgPPtGmK8cYQJ0ZH0~gGTCcmp5RGF7CTR8imPmPNl0Lj95NiLMRMPdbFrabzWi20puP3E79v4pMH64wMuOhJiiBtYaj1cwgHlyG9heYkynCdmit-aO5nk6z4myJGUe239kWmOELOxO3u4ETnGDaKGE-oaDwTOJiZ~AHpJreFdX4eDV3dxRR7Xg__&Key-Pair-Id=K2TK3EG287XSFC)
You will then be prompted to use your screen lock to create a passkey (this may be a passphrase/PIN, pattern, fingerprint or face ID, depending on the method you have set on your phone)
After completing the screen lock, you will receive a prompt saying "Account added", at which point you can select "Done"

From the ‘Security info’ page, look for ‘Default sign-in method' and click on the word ‘Change’.

You will be presented with a drop-down list of your configured MFA methods. Choose ‘App based authentication or hardware token - code’.

Your M365 account is now secured with passkey authentication.
Important Note: It may take up to an hour for the changes above to fully take effect. On your next login, if you are not prompted to use your passkey, you will still be able to log in using your password and the six-digit one-time password code found in Microsoft Authenticator for your account.


Once the changes you have made to your account fully take effect, your login experience to U of G services will change. The next time you log in, after entering your U of G username (your central login ID @ uoguelph.ca or @guelphhumber.ca), you will be prompted to use your passkey instead of entering your password. From the authentication page, ensure ‘iPhone, iPad, or Android device’ is selected and click ‘Next’.

Now, open the Microsoft Authenticator app on your mobile device and click the ‘Scan QR code’ button on the bottom right and scan the QR code on screen. Review the sign-in information presented to verify your account and the service you are logging into and click ‘Continue’.

