Registering and Managing Passkeys with Microsoft Authenticator

Set Up a Passkey with Microsoft Authenticator

This guide walks Hillsborough College students, faculty, and staff through setting up a passkey in the Microsoft Authenticator app on your phone.

Official reference: For Microsoft's own step-by-step instructions (kept current by Microsoft), see Register passkeys in Authenticator on Android and iOS devices.

What is a passkey?

A passkey is a secure, hard-to-phish way to prove it's really you when you sign in.

At Hillsborough College, a passkey does not replace your password. You'll still sign in with your NetID and password, then use your passkey on your phone (with your fingerprint, face, or screen PIN) to finish verifying your identity. It takes the place of older methods like text-message codes and standard app notifications.

Why it's more secure:

  • Harder to phish. A passkey only works on the real Microsoft sign-in page, so a fake "login" site can't trick you into handing it over.
  • Faster. Just use your phone's fingerprint, face, or PIN. No codes to type and no waiting for a notification.
  • Safer. The key stays locked on your phone and is never shared, so it can't be stolen in a data breach or guessed.

Before you start

You'll set your passkey up directly in the Microsoft Authenticator app on your phone. For security, Hillsborough College requires passkeys to be created and stored on your phone itself, so the computer-to-phone (QR code) setup method isn't available. The steps below are all you need.

On your phone, you'll need:

  • An iPhone or iPad running iOS 17 or later, or an Android phone running Android 14 or later (if you run Android 14 and hit problems, Android 15 is recommended).
  • A screen lock turned on (PIN, pattern, password, Face ID, Touch ID, or fingerprint).
  • The Microsoft Authenticator app installed and updated to the latest version (from the Apple App Store or Google Play Store).
  • An internet connection.

Step 1: Clean up old sign-in methods (optional but recommended)

Removing leftover or duplicate Authenticator entries first helps avoid conflicts.

⚠️ Important: Do not delete your last working sign-in method. If you remove the only method you have, you can lock yourself out of your account. Keep at least one working method until your new passkey is set up and confirmed.

  1. On a computer or tablet, go to https://mysignins.microsoft.com/security-info.
  2. Sign in with your NetID and complete your usual verification.
  3. In the left menu, click Security info.
  4. Look for duplicate or obsolete entries named "Microsoft Authenticator."
  5. Click Delete next to any you no longer use. When in doubt, leave it in place and contact the Helpdesk.

[Screenshot: Security info page with the Delete option]


Step 2: Create your passkey

On iPhone / iPad (iOS 17 or later)

  1. Open the Microsoft Authenticator app.
  2. If your Hillsborough College account isn't in the app yet, tap Add account (or the + button), choose Work or school account, and sign in with your NetID and password.
  3. Tap your Hillsborough College account, then tap Create a passkey.
  4. Sign in and complete your usual verification if prompted.
  5. If you don't have a screen lock yet, tap Settings to set one up.
  6. Tap Settings to turn on Authenticator as your passkey provider. This opens your iPhone settings:
    • iOS 18 and later: Settings > General > AutoFill & Passwords
    • iOS 17: Settings > Passwords > Password Options
  7. Turn AutoFill Passwords and Passkeys ON, then under "AutoFill From," select Authenticator so a checkmark appears.
  8. Return to Authenticator and tap Done. You'll see a success screen. Tap Done again to finish.

 

On Android (Android 14 or later)

  1. Open the Microsoft Authenticator app.
  2. If your Hillsborough College account isn't in the app yet, tap Add account (or the + button), choose Work or school account, and sign in with your NetID and password.
  3. Tap your Hillsborough College account, then tap Create a passkey.
  4. Sign in and complete your usual verification if prompted.
  5. If you don't have a screen lock yet, tap Settings to set one up.
  6. Tap Settings to turn on Authenticator as a passkey provider. In your Android settings, open Passwords & accounts.
  7. Under Additional providers, turn Authenticator ON.
  8. Return to Authenticator and tap Done. You'll see your new passkey added. Tap Done again to finish.

 

 


Signing in with your passkey

Once your passkey is set up, here's what signing in looks like. You'll still enter your NetID and password first, then verify with your passkey instead of a text code or notification.

On the same phone

  1. Enter your NetID and password as usual.
  2. When you're asked to verify, choose the passkey option.
  3. Confirm with your fingerprint, face, or screen PIN. You're in.

On a computer (using your phone)

  1. On the computer, enter your NetID and password.
  2. When you're asked to verify, a QR code appears on the screen.
  3. On your phone, open the regular camera app and scan the QR code.
    • On iPhone, use the built-in Camera app, not the scanner inside Authenticator. The Authenticator camera can't scan this sign-in code.
  4. Your phone and computer connect over Bluetooth, so make sure Bluetooth and internet are on for both.
  5. Confirm with your fingerprint, face, or PIN on your phone. You're now signed in on the computer.

Tip: If no QR code appears, or the phone and computer won't connect, it's almost always Bluetooth being off on one of them. Turn it on for both and try again.

 

[Screenshot: Cross-device sign-in QR prompt]

[Screenshot: Cross-device sign-in QR prompt]


First time using Microsoft Authenticator?

If you don't have the app set up for your Hillsborough College account yet, do this first:

  1. On your computer, sign in to https://mysignins.microsoft.com/security-info.
  2. Click + Add sign-in method and choose Authenticator app.
  3. Download the app on your phone, then click Next.
  4. Open the app, choose Work or school account if prompted, and click Next on your computer.
  5. Scan the QR code on your screen with your phone's camera, then click Next.
  6. Complete the verification prompt on your phone, then click Done.

Once that's done, come back to Step 2 above to add your passkey.


Troubleshooting & FAQs

I don't see a "Create a passkey" option. Make sure the Authenticator app is updated to the latest version, then reopen it. If it's still missing, your account may not be enabled for passkeys yet. Contact the OIT Helpdesk.

Setup failed or timed out. What should I do? Creating a passkey runs a quick security check with Apple or Google in the background, which occasionally times out. Wait a minute and try again. If it keeps failing, close and reopen the app, confirm it's updated, and retry.

I got an error saying "the passkey already exists." What now? This happens when a passkey saved on your phone didn't finish registering on the server. Delete the local copy and try again:

  1. Open Authenticator, tap your Hillsborough College account, and tap Settings.
  2. Tap Delete passkey.
  3. Go back to https://mysignins.microsoft.com/security-info and start over.

How do I remove a passkey (for example, if I'm replacing my phone)?

  1. In Authenticator, tap your account, then Settings > Delete passkey.
  2. Then go to https://mysignins.microsoft.com/security-info and click Delete next to that passkey to remove it from your account. (On Android this is often removed automatically, but check to be sure.)

My phone runs Android 14 but I can't pick Authenticator as a passkey provider. Menus vary by phone brand. Try searching "Passkey" in your phone's Settings, check your phone maker's help guide for where to turn on additional passkey providers, and if possible update to Android 15 for smoother support.

Can I use Safari? The passkey itself is created in the app, so Safari isn't part of the process. If you ever need the Security info page on a computer, use Chrome or Edge, which are more reliable than Safari for that page.


Need help?

For Microsoft's own current instructions, see Register passkeys in Authenticator on Android and iOS devices.