Overview
This article is intended for NEOMED faculty, staff, students, and affiliates who want to understand phishing-resistant multifactor authentication (MFA), passkeys, and the available sign-in and enrollment options for their NEOMED account.
What Is Phishing-Resistant MFA?
Phishing-resistant MFA uses sign-in methods that are designed to prevent an attacker from capturing or reusing your credentials on a fraudulent website. Traditional methods, including Microsoft Authenticator push notifications and number matching, provide strong protection but still rely on a password and are not considered phishing-resistant. Passkeys provide a stronger option because they verify both the user and the legitimate sign-in service without transmitting a reusable password.
What Is a Passkey?
A passkey is a passwordless, phishing-resistant credential associated with your device or security key that replaces your password. Unlike a password, a passkey cannot be typed into a fake sign-in page or easily reused by an attacker. Depending on the supported option, a passkey may be stored on a smartphone, tablet, computer, or physical FIDO2 security key.
After enrollment, you will no longer use your password to authenticate. Instead, you will verify your identity by using a PIN or biometrics (like Face ID or Touch ID) directly on your device, entering the code from your physical FIDO2 security key, or scanning a QR code with your phone and using your phone's unlock method to complete sign-in.
To learn more about passkeys, please see our Article - MFA: Understanding Passkeys.
|
NEOMED Authentication Method Comparison
|
|
Authentication Method
|
MFA
|
Passwordless
|
Phishing-Resistant
|
|
SMS/Text Code
|
✓
|
✗
|
✗
|
|
Voice Call
|
✓
|
✗
|
✗
|
|
Microsoft Authenticator Push Notification (including number matching)
|
✓
|
✗
|
✗
|
|
Microsoft Authenticator One-Time Passcode (TOTP)
|
✓
|
✗
|
✗
|
|
Microsoft Authenticator Passwordless Phone Sign-in
|
✓
|
✓
|
✗
|
|
Microsoft Authenticator with Passkey
|
✓
|
✓
|
✓
|
|
Apple Passwords Passkey (iOS devices)
|
✓
|
✓
|
✓
|
|
Google Password Manager Passkey (Android devices)
|
✓
|
✓
|
✓
|
|
FIDO2 Security Key (YubiKey, etc.)
|
✓
|
✓
|
✓
|
|
Windows Hello
|
✓
|
✓
|
✓
|
|
Windows Hello for Business
|
✓
|
✓
|
✓
|
|
Platform SSO for macOS
|
✓
|
✓
|
✓
|
How to Enroll a Passkey for your NEOMED Account
Specific instructions for enrolling and signing in with passkeys can be found in the following Article - MFA: Multifactor Authentication Help and Resources List. You can choose from a list of articles based on which device type you have available and want to use. Options include smartphones, tablets, computers, and FIDO2 security keys.
If you need help choosing an option, please see the following KB article: Article - MFA: How to Choose a MFA Method
Important Tips
- Enroll more than one approved sign-in method when possible so you have a backup.
- Do not approve a sign-in request you did not initiate.
- Keep physical security keys in a secure location.
- If you replace or lose a registered device, contact the NEOMED Help Desk for assistance updating your sign-in methods.