Set up Microsoft passkey for multifactor authentication

Table of Contents

Overview of Passkeys

Passkeys are a secure way to sign in to websites and apps. Instead of a password, a passkey uses your device to confirm it's really you with either a PIN, fingerprint, or face recognition. To improve account security, the university is moving from traditional multifactor authentication (MFA) to passkey using the Microsoft Authenticator app.

All University of Arkansas faculty, staff, and students will be required to set up a passkey by December 1st, 2026.

Before You Start

Before you set up passkey, there are requirements you must complete or confirm with your devices first.

  • Microsoft Authenticator App:
  • Windows Hello: If you use a university managed Windows computer for work, you must set up Windows Hello before creating your passkey.
    • Note: If you are a student or use a personal device, we recommend you set up Windows Hello but it is not required. You may continue with the steps in the Setting Up Passkey section.
  • Mobile Device Requirements:
    • Android running 14 and later
    • iOS running 17 and later
  • Bluetooth Requirements:
    • Make sure Bluetooth is turned on for both your computer and mobile device.

If your mobile device does not meet these requirements, or you have a reason for not using the Microsoft Authenticator app for passkey on your personal mobile device, you may request a YubiKey to use as your primary MFA method.

Setting Up Passkey

IMPORTANT: There are three parts to setting up passkey. Please complete all of the steps in each part to successfully set up your passkey.
1. Create the passkey
2. Confirm the passkey
3. Enroll in the "MFA with Passkey in Microsoft Authenticator" group.


Part 1: Create the Passkey

  1. Open the Microsoft Authenticator app on your mobile device.Microsoft Authenticator app logo
  2. Select your University of Arkansas account.

    Authenticator with account indicated.
     
  3. Select Create a passkey.

    Tap Create a Passkey in Microsoft Authenticator
     
  4. Choose Sign In on the Let’s create your passkey screen.
    Note: You may be prompted to sign-in with your existing multifactor setup at this step.
  5. Unlock your mobile device however you normally do. If your device does not have a screen lock, you'll be asked to set one up before continuing.
  6. When the passkey is created, you'll see a Passkey Created screen. Select Done.
  7. In your phone Settings, enable Authenticator for passkey use.
    • If using iOS: Go to Settings, General, Autofill & Passwords, and ensure that AutoFill Passwords and Passkeys is turned on.
    • If using Android: Go to Settings, Passwords, Accounts, Under the Additional providers section, make sure Authenticator is enabled. 

Your passkey has now been created. Please continue to Part 2: Verify Passkey.
Note: If you have any issues at this step, go to the Security Info page and select "Sign out everywhere" at the bottom. Then, continue with the instructions.

Part 2: Confirm Passkey

Before enrolling in the required group, you must make sure that the passkey was actually created. This is important to keep you from getting locked out. 
  1.  Go to the My Account page and sign in with your new passkey. 

  2. Under My Account, select the Security Info tab. This will show you a list of the sign-in methods that you have set up. Make sure your passkey was created by looking for: "Passkey (Device Bound) Microsoft Authenticator". If you do not see this option, the passkey was not created correctly. Return to Part One to create the passkey again. 

Part 3: Enroll in the "MFA with Passkey in Microsoft Authenticator" Group

ATTENTION: Do not complete this part if you are a student who uses Walton Virtual Labs, or you will be unable to log in. 
  1. After confirming that the passkey is in your list, select My Access in the left navigation pane.

  2. Under My Access in the left navigation, Select Access Packages.

    left navigation with Access packages indicated
     
  3. Select View All.

    Access packages page with View all indicated.

     
  4. Choose Request in the "MFA with Passkey in Microsoft Authenticator" row.

    Request link is indicated
     
  5. Select Continue when the window opens.

    MFA with Passkey in Microsoft Authenticator - Requesting for Myself
     
  6. Before enrolling in this group, answer the questions in the Additional Questions window:
    1. Select Yes or No to answer, "Have you registered a Microsoft passkey in Microsoft Authenticator or registered a YubiKey?"
    2. Select Yes or No to answer, "For Windows users, have you set up Windows Hello for Business?"
    3. You can leave the Business Justification field blank.
    4. Click the Submit Request button. 

      Additional questions window

A green message in the upper-left corner confirms your request was submitted. This will not take long to process.

Your request to add MFA with Passkey in Microsoft Authenticator is being processed.

What's Next

You will receive an email to your UARK email account from Microsoft Security with the subject line, "You now have access to MFA with Passkey in Microsoft Authenticator" to let you know that you have successfully enrolled in the required security group. Both parts are complete, and you are ready to use your passkey to access university resources. 

Depending on whether you’re signing in to your assigned work computer, a shared computer or device, or your mobile phone where the passkey is stored, the sign in experience will vary. Please visit the Sign in with Microsoft Passkey article for more information about using passkey in your daily work on campus. 

Need Help?

Need more information? Check the Related Articles sections on this page (on the side) for additional resources that might help

67% helpful - 3 reviews
Print Article

Related Articles (7)

This article is for faculty, staff, and student employees wanting to know more about passkey and why it is being implemented at the university as a multi-factor authentication method.
The purpose of this policy is to provide guidelines for MFA connections to the University of Arkansas network and information systems on and off campus.
This article is for faculty, staff, student employees, and students that have frequently asked questions about using passkey.
The university creates a UARK account for each new student and each new employee. To set up your account, you must set a password and set up MFA.
Set up a new secondary/non-primary UARK account
Multi-factor authentication (MFA) is required for all student, faculty, and staff UARK accounts. After activating your UARK account, register for MFA.
Your UARK account allows you to securely access university services, including email, campus Wi-Fi, Blackboard, Workday, and more.

Related Services / Offerings (1)