MFA: What Is Phishing-Resistant MFA and How to Enroll?

Summary

Learn how passkeys provide stronger protection for your NEOMED account and how to get started.

Body

Overview

This article is intended for NEOMED faculty, staff, students, and affiliates who want to understand phishing-resistant multifactor authentication (MFA), passkeys, and the available sign-in and enrollment options for their NEOMED account.

What Is Phishing-Resistant MFA?

Phishing-resistant MFA uses sign-in methods that are designed to prevent an attacker from capturing or reusing your credentials on a fraudulent website. Traditional methods, including Microsoft Authenticator push notifications and number matching, provide strong protection but still rely on a password and are not considered phishing-resistant. Passkeys provide a stronger option because they verify both the user and the legitimate sign-in service without transmitting a reusable password.

What Is a Passkey?

A passkey is a passwordless, phishing-resistant credential associated with your device or security key that replaces your password. Unlike a password, a passkey cannot be typed into a fake sign-in page or easily reused by an attacker. Depending on the supported option, a passkey may be stored on a smartphone, tablet, computer, or physical FIDO2 security key.

After enrollment, you will no longer use your password to authenticate. Instead, you will verify your identity by using a PIN or biometrics (like Face ID or Touch ID) directly on your device, entering the code from your physical FIDO2 security key, or scanning a QR code with your phone and using your phone's unlock method to complete sign-in.

To learn more about passkeys, please see our Article - MFA: Understanding Passkeys.

NEOMED Authentication Method Comparison

Authentication Method

MFA

Passwordless

Phishing-Resistant

SMS/Text Code

Voice Call

Microsoft Authenticator Push Notification (including number matching)

Microsoft Authenticator One-Time Passcode (TOTP)

Microsoft Authenticator Passwordless Phone Sign-in

Microsoft Authenticator with Passkey

Apple Passwords Passkey (iOS devices)

Google Password Manager Passkey (Android devices)

FIDO2 Security Key (YubiKey, etc.)

Windows Hello

Windows Hello for Business

Platform SSO for macOS

How to Enroll a Passkey for your NEOMED Account

Specific instructions for enrolling and signing in with passkeys can be found in the following Article - MFA: Multifactor Authentication Help and Resources List. You can choose from a list of articles based on which device type you have available and want to use. Options include smartphones, tablets, computers, and FIDO2 security keys.

If you need help choosing an option, please see the following KB article: Article - MFA: How to Choose a MFA Method

Important Tips

  • Enroll more than one approved sign-in method when possible so you have a backup.
  • Do not approve a sign-in request you did not initiate.
  • Keep physical security keys in a secure location.
  • If you replace or lose a registered device, contact the NEOMED Help Desk for assistance updating your sign-in methods.

Details

Details

Article ID: 174653
Created
Wed 9/9/26 2:30 PM
Modified
Thu 9/10/26 3:35 PM