Overview
You can find more FAQs on this Microsoft page.
Overview
A passkey is a modern way to sign in to websites and apps without using a traditional password. Instead of something you know (a password), a passkey uses cryptographic keys and often something you have (your device) plus something you are (Face ID, fingerprint, Windows Hello, etc.).
Passkeys are designed to be more secure, as well as easier to use than passwords. They are also more resistant to phishing & credential theft.
With Microsoft transitioning away from supporting SMS (text-based) and voice-based authentication, passkeys present a new alternative method for both logging into your account and completing MFA.
After you register a passkey, and set it as your default authentication method, the next time you log in, after entering your U of G username (your central login ID @uoguelph.ca or @guelphhumber.ca), you will be prompted to use your passkey instead of entering your password. This will typically involve scanning a QR code, and then scanning biometrics or entering a PIN on your phone, or plugging in a hardware security key to your computer and then scanning biometrics or entering a PIN.
The UofG has enabled the following authentication methods for storing and using Passkeys:
| Authentication/Sign-Method | Description | ||||
|
This is the recommended authentication method for use with passkeys. It is a free app that can be downloaded from the Apple Store or Google Play store (see our "Setting up Azure MFA - Autheticator App" page or the "Download and install the Microsoft Authenticator app" support page from Microsoft). The Authenticator App is supported on Android 8.0 and later, iOS 14 or later and Windows 10 mobile 14393.0 or later. WatchOS is no longer supported (January 2023). You can use other authenticator apps (Google, Authy, Duo etc) but the product we support is the Microsoft Authenticator App and other apps are best effort support.
When you try to login to an MFA protected service, after entering your username, you will get an prompt to scan a QR code with Authenticator, and after scanning biometrics or entering a PIN on your phone, you’ll automatically be logged in to the service you were trying to access.
If you have no internet connection on your phone, the app can still be used to give a one-time password code (a 6-digit number, similar to the code you would get when using SMS/text messages). |
||||
| Security keys or hardware tokens |
Note: Security keys require that you have an additional authentication/sign-in method already enabled on your account in order to add them to your account. If you are unable to add an additional authentication/sign-in method to your account, please contact the IT Help Centre for alternative setup methods.
These are little hardware devices or cards that you carry around with you. NOTE: The Fido Security key will not currently work for the login to Web Advisor (waiting on a fix by the vendor). They can look and function differently, depending on the token type:
CCS Information Security has approved the following additional hardware tokens: |
To manage your authentication methods in a web browser navigate to https://aka.ms/mysecurityinfo. If you are already logged into GryphMail via the Outlook web app, do the following:
This “Security info” page allows you to manage your Passkeys. If you already have at least one Passkey or MFA method registered to your account, you will be prompted to login using MFA.
To add a Passkey to your account, click on “Add sign-in method” and follow the prompts for your preferred passkey method.

.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy8yNTk0MC8zMjc4NS9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgzNSkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg4MzYyNTkxfX19XX0_&Signature=gRFNV7N9um4JfbPPrA8H4KQidglUUSe56nO5b747dgUkT8NxbzO5gM~TPX2cdrEb5Wn6473rCvP4qBjVg8ZcQAdoElK56AJMNUiUwRYbokItpdfgNjqtMxtcffhIL~Wks5AVxng65Va3KAI6BxuyI95SL1Seu-KWY4wbFnT0PNKxLVljfQ0QCubpvSsbHbNFEL7OA0w6MB8CD8jl8Pc~-dMLrr1-Dy6J1eWSqrh57x3xH2V3AXus-ERibM-4WxuhIfwng~Zt6LAaRMfSf4r9r-3Xf5Neh6-V~ls0HohesRaq07Qojtsg6peVwGqYFVIr20QelsS63Ihs3UWDncMedQ__&Key-Pair-Id=K2TK3EG287XSFC)
The security key option for passkey uses security keys, or hardware tokens, using the Fast Identity Online (FIDO2) passwordless authentication protocol. These can be purchased from many different businesses, including the Bookstore in the McNaughton Building on the University of Guelph campus. Prices can range anywhere from $8 to $100+, depending on what you are looking for.
CCS Information Security has approved the following additional hardware tokens:
Staff and faculty can speak with their department to see if they can provide a security or hardware token.
On the “Security info” section for your account (see the "How can I add an authentication/sign-in method for Passkey to my account?" question for instructions on how to get to the "Security info" section), click on “Change” next to the “Default sign-in method: ” option located above the list of authentication/sign-in methods registered on your account.

Troubleshooting and Security
As long as you have one available authentication/sign-in method available to you on your account, you can use that to remove any authentication/sign-in method that you no longer have access to. You can manage your authentication/sign-in methods on the "Security info" section of your account (see the "How can I add an authentication/sign-in method for MFA to my account?" question for instructions on how to get to this section).
If you do not have access to any of the authentication/sign-in methods registered on your account, please contact the IT Help Centre. As administrators of Microsoft 365, CCS can remove any authentication/sign-in methods from your account for you. Once all are removed, you can register new authentication/sign-in methods onto your account.
My security key is not working on my MacOS computer - what can I do?
If you cannot use your security key when signing into your account in Safari or Firefox, try signing into your account using Google Chrome instead. If you do not have Google Chrome installed, download and install Google Chrome and try signing in with your security key there.
Can passkeys control my phone or monitor me?
Passkeys are only used to verify your identity and ensure the security of your account. It will not be used for monitoring activity and does not provide the University access to your device. If you have questions about privacy related to Passkeys, please consult the resources below:
No — your password can still be compromised. We recommend you use a unique and strong password that does not contain any dictionary words, uses a variety of character sets, and does not contain your previous password. You still need to change your U of G Single Sign On (SSO) password when required. It is best practice to change your password at least once a year.