- Home
- Take Action
- Education & Guides
- Passkeys
- Password Management
- Phishing
- Physical Security
- Theft of Computer Equipment
-
Policies & Procedures
- Account Access and Recovery
- Alabama Breach Notification Act of 2018
- Admin Systems Security Access Authorization Process
- Copyright Information
- E-mail Policy
- Information Technology Usage Policy
- International Travel Requirements
- World Wide Web Policy
- Technology Policies
- Technology Standardization Guidelines
- Additional Resources
- IT Security Award
Passkeys
What is a passkey?
A passkey is a digital credential created for a specific account on a website or application. Instead of remembering and typing a password, you approve access through a compatible device or hardware security key.
Your fingerprint, face, or PIN unlocks the credential locally. These are not the passkey itself, and your biometric information is not shared with the website.
How does it work?
When you create a passkey for your TROY account it generates two mathematically related keys:
- Public key: Registered with Microsoft
- Private key: Protected by your credential manager or security key and never sent to the website.
During sign-in, you approve the request, your device uses the private key to sign it. The website verifies that signature using the public key and grants access without receiving a password or your private key.
Why are passkeys safer?
Passkeys are tied to the legitimate service. If you visit a fraudulent website that imitates the real login page, your browser will not offer that service’s passkey to the fake site.
Each account also has its own credential, eliminating password reuse for passkey sign-ins. Stealing the public key from a service’s database does not give an attacker the private key needed to authenticate.
Are passkeys a form of multifactor authentication?
Passkeys protect your TROY account by combining your device or security key with your PIN. Fingerprint, or face providing multifactor authentication in one sign-in.
Add a passkey to your Troy University account
On your university computer, visit mysignins.microsoft.com and sign in using your @troy.edu account. Complete the requested verification, select My Account then select Security info, and click Add sign-in method.
Option 1: Microsoft Authenticator on your phone
On either Windows or Mac, select Passkey in Microsoft Authenticator, then Next. Follow the instructions to complete registration on your phone.
Option 2: Another device or security key
Windows: Select Passkey, then Next. Select where to save your passkey such as phone, tablet or hardware security key. Follow the prompts for your selected option.
Mac: Select Passkey, then Next. Follow the macOS prompts and complete registration.
Keep your devices and applications updated. Where passkeys are unavailable, continue using strong, unique passwords and enable multifactor authentication.
Remember: Passkeys strengthen account protection but staying alert to scams and protecting your devices remain essential.