Body


Setting Up Passkeys
| Microsoft is now requiring passkeys for all accounts. Passkeys replace passwords with a faster, more secure sign-in your face, fingerprint, or PIN. This guide walks you through getting set up. |
In This Article
What Is a Passkey?
A passkey is a modern, password-free way to sign in. Instead of typing a password, you verify your identity using something already on your device, your fingerprint, face scan, or PIN. Passkeys are more secure than passwords because they cannot be stolen in a data breach or used on a fake login page.
Where your passkey can live:
- Microsoft Authenticator app (iPhone or Android) recommended for most people
- Windows Hello face, fingerprint, or PIN on a Windows 10/11 PC
- iCloud Keychain syncs automatically across your Apple devices
- Google Password Manager syncs across Android/Chrome devices
Passkeys vs. Passwords
| Feature |
Password |
Passkey |
| Can be phished or stolen? |
Yes |
No |
| Can be forgotten? |
Often |
Never |
| Works without typing? |
No |
Yes |
| MFA built in? |
No |
Yes, automatically |
| Risk if there's a data breach? |
High |
None |
Setting Up Your Passkey
You only need to do this once. After setup, you can sign in with a tap and a biometric instead of typing your password.
Before you begin, you will need:
| Requirement |
Details |
| Microsoft Authenticator app |
Install on your iPhone (iOS 17+) or Android phone |
| Your JCC account |
Your jccmi.edu email and current password |
| MFA already configured |
You must be able to complete a sign-in verification at least once |
| Phone screen lock |
Face ID, fingerprint, or PIN must be enabled on your phone |
Option A: Set Up via the Authenticator App (Recommended)
Step 1: Install Microsoft Authenticator
Download Microsoft Authenticator from the App Store (iPhone) or Google Play (Android). If you already use it for MFA, skip to Step 2.
Step 2: Add Your JCC Account
- Open Microsoft Authenticator.
- Tap + or Add account, then choose Work or school account.
- Sign in with your jccmi.edu email and password, then complete the verification when prompted.
Step 3: Create the Passkey
- Tap your account name inside the Authenticator app.
- Tap Create a passkey.
- Complete the sign-in verification when prompted. (Required the first time only.)
- If prompted, set up a screen lock (PIN, fingerprint, or Face ID) on your phone.
Step 4: Enable Authenticator as Your Passkey Provider
This step tells your phone to use Microsoft Authenticator when you sign in with a passkey. Follow the instructions for your phone type below.
On iPhone (iOS 18):
- Go to Settings > General > AutoFill & Passwords.
- Make sure AutoFill Passwords and Passkeys is turned ON.
- Under "Autofill From," select Microsoft Authenticator.
On iPhone (iOS 17):
- Go to Settings > Passwords > Password Options.
- Turn on AutoFill Passwords.
- Under "Allow Filling From," select Microsoft Authenticator.
On Android:
- Go to Settings > Passwords & accounts (exact name may vary by phone brand).
- Tap Additional providers or Passkeys.
- Select Microsoft Authenticator.
Step 5: You're Done!
Return to the Authenticator app and tap Done. Your passkey is registered. The next time you sign in to Microsoft 365, JCC email, or Teams, you'll be prompted to use your passkey instead of your password.
| ⚠️ Android 14 users: If you cannot select Authenticator as your passkey provider, contact the JC Solution Center for assistance, your device may need an update. |
Option B: Set Up via a Web Browser
Use this method if you prefer to start from a computer browser, or if the Authenticator app prompts are not appearing on your phone.
- On your computer, open a browser and go to: https://mysignins.microsoft.com/security-info
- Sign in with your jccmi.edu account and complete verification when prompted.
- Click + Add sign-in method.
- Select Passkey in Microsoft Authenticator (or Passkey).
- Follow the on-screen instructions — you will be asked to scan a QR code with your phone.
- Open Microsoft Authenticator on your phone and complete Steps 2–4 from Option A above.
- Return to the browser, click Next, then Done.
| 💡 Tip: When using Option B, make sure Bluetooth is turned on on both your phone and your computer before scanning the QR code. |
Signing In with Your Passkey
On your own device:
- Go to any Microsoft sign-in page (Outlook, Teams, Microsoft 365).
- Enter your jccmi.edu email and click Next.
- When prompted, approve with your fingerprint, Face ID, or PIN.
- You're signed in; no password needed.
On a shared or lab computer (using your phone):
- At the sign-in page, click Sign-in options or Use passkey from another device.
- A QR code will appear on screen. Open Microsoft Authenticator on your phone and scan it.
- Approve the sign-in with your fingerprint or Face ID on your phone.
- You're signed in on the shared computer, no credentials left behind. (Bluetooth must be on.)
| 🔒 Security note: Your passkey cannot be phished. Even if you visit a fake login page, your passkey will not work there — it is cryptographically bound to the real Microsoft domain only. |
Troubleshooting
| Problem |
What to try |
| Passkey option doesn't appear in Security Info |
Contact the JC Solution Center; your account may need to be added to the passkey rollout. |
| QR code scan doesn't work during setup |
Make sure Bluetooth is enabled on both your phone and computer, and that both are connected to the internet. |
| Android: can't select Authenticator as passkey provider |
This is a known issue on Android 14. Contact the JC Solution Center; your device may need an OS update. |
| Passkey prompt stopped appearing when signing in |
Go back to Step 4 of the setup guide and confirm Microsoft Authenticator is selected as your passkey provider in your phone's settings. |
| "Error" or "passkey not found" when signing in |
Go to Security Info, remove the old passkey entry, and re-register a new passkey following the steps above. |
| Passkey stopped working after your email address changed |
Passkeys are tied to your account email. Re-register your passkey at Security Info after any email/username change. |
| You lost or replaced your phone |
Sign in with your password + verification code, then go to Security Info to register a passkey on your new device. |
Frequently Asked Questions
What if I lose my phone?
You can still sign in using your password and verification code. Once you have a new phone, install Microsoft Authenticator, sign in to your JC account, and register a new passkey from Security Info.
Can I register passkeys on more than one device?
Yes. You can set up a passkey on multiple devices, your phone, your laptop, or a tablet. Each one shows up separately in Security Info and can be removed at any time.
Does this replace the MFA verification I already do?
Yes, passkeys combine the password and the MFA step into one fast action. You still use the Microsoft Authenticator app, just in a new way. You do not need to remove your existing MFA setup.
Is my fingerprint or face scan sent to Microsoft?
No. Your biometric data never leaves your device. The fingerprint or face scan is processed locally to unlock your passkey. Microsoft only receives a cryptographic proof of your identity; your biometrics are never transmitted or stored on Microsoft's servers.
What if I share a computer in a lab or classroom?
Use the cross-device sign-in option: at the Microsoft login page, click Sign-in options > Use passkey from another device, then scan the QR code with your phone. You'll be signed in securely without leaving any credentials on the shared machine.
Do I still need a password at all?
Your password remains as a backup option, but once your passkey is set up you will rarely need it. Microsoft's long-term goal is to remove passwords entirely.
Need Help?