Overview
This article provides step-by-step instructions for creating a device-bound Microsoft MFA passkey in the Microsoft Authenticator app. These instructions apply to both iOS and Android devices.
Important Information
What Is a Device-Bound Passkey?
Passkeys created in the Microsoft Authenticator app are device-bound, meaning the passkey is stored only on the device where it was created.
If the device is lost, damaged, or replaced, the passkey will not transfer to a new device and must be recreated. If this occurs, please contact the Help Desk for assistance.
Authenticator Passkeys vs. Authenticator Push Notifications
Using a passkey in Microsoft Authenticator is different from approving a Microsoft Authenticator push notification.
A passkey:
- Allows passwordless sign-in
- Uses your device's Face ID, fingerprint, PIN, or other secure unlock method
- Verifies your identity using cryptographic credentials stored on the device
Multiple Passkeys Are Supported
You can register multiple passkeys for your NEOMED account.
For example, you may have:
- A device-bound passkey in Microsoft Authenticator
- A synchronized passkey stored in Apple Passwords (iCloud Keychain)
- A synchronized passkey stored in Google Password Manager
Android Devices
Microsoft Authenticator must be enabled as a passkey provider to create a passkey within the app.
Depending on your Android version and device manufacturer, you may be prompted to enable Microsoft Authenticator as:
- A preferred credential provider, or
- An additional credential provider
during the enrollment process.
Path 1: You Do Not Currently Use Microsoft Authenticator with Your NEOMED Account
Step 1: Install Microsoft Authenticator
- Download and install Microsoft Authenticator from your device's app store.
Step 2: Add Your Account
- Open the Microsoft Authenticator app.
- Select Add work or school account.

Step 3: Sign In
- Sign in using your NEOMED account credentials.

Step 4: Secure Your Account
- On the Let's secure your account screen, select Continue.

- Complete your device's unlock method when prompted:
- Face ID
- Fingerprint
- PIN
- Passcode
Android Note: If Microsoft Authenticator is not already enabled as a passkey provider, you may be prompted to enable it during enrollment. The experience may vary by Android version and device manufacturer.
Step 5: Register the Device
- On the Register your device screen, select Register.

Step 6: Complete Device Security Registration
- On the Help us keep your device secure screen, select Register.
- Complete your device unlock method again when prompted.
Step 7: Finish Enrollment
- Select Done.

Your NEOMED account is now added to Microsoft Authenticator, and a device-bound passkey has been created.
Path 2: You Already Use Microsoft Authenticator with Your NEOMED Account
Step 1: Open Microsoft Authenticator
- Open the Microsoft Authenticator app on your smartphone.
Step 2: Select Your NEOMED Account
- Tap your NEOMED account.
Step 3: Create a Passkey
- Select Create a passkey.

Note: If Microsoft Authenticator has not previously been granted permission to use your device's biometric authentication or PIN, you will be prompted to allow access.
Step 4: Verify Your Identity
- Complete the device unlock method when prompted:
- Face ID
- Fingerprint
- PIN
- Passcode
Android Note: If Microsoft Authenticator is not enabled as a passkey provider, you may be prompted to configure it during enrollment. The exact screens may vary based on your Android device and operating system version.
Step 5: Complete Setup
- Select Done.

Your device-bound passkey has now been successfully created.
Verify the Passkey
To confirm the passkey was created:
- Open the Microsoft Authenticator app.
- Select your NEOMED account.
- Select Passkey.
The passkey details should be displayed, confirming that enrollment was successful.
Need Help?
If you experience issues enrolling or using a passkey, contact the NEOMED IT Help Desk.
- Submit a ticket through the IT Service Portal (see Services above)
- Email: help@neomed.edu
- Phone: 330-325-6911