Body
Overview
This article is intended for NEOMED faculty, staff, students, and affiliates who want to understand passkeys before creating one for their NEOMED account.
What Is a Passkey?
A passkey is a secure, passwordless way to sign in to your NEOMED account. Instead of entering a password, you confirm your identity using a device PIN, fingerprint, facial recognition, or supported security key. Because a passkey is tied to a trusted device or credential manager and cannot be entered into a fraudulent sign-in page, it provides strong protection against phishing and credential theft.
How Passkey Sign-In Is Different
With a traditional sign-in, you would:
- Enter your NEOMED email.
- Enter your NEOMED password.
- Receive the requested multifactor authentication prompt.
- Enter/submit the multifactor authentication response.
- Then you are logged in.
With a passkey sign-in, you would:
- Enter your NEOMED email
- Select to sign in with a passkey.
- If prompted on a computer, scan the displayed QR code with the device that stores your passkey.
- Approve the request using Face ID, Touch ID, your device PIN, or a supported security key.
- Then you are logged in.
How Passkeys Are Stored
There are two ways to store a passkey:
- Device-bound passkey: The passkey remains on the device or physical security key where it was created. If that device is lost or replaced, you must create a new passkey as the passkey does not transfer devices.
- Synced passkey: The passkey is securely backed up by the device's built-in credential manager and can be available on your other trusted devices within the same platform ecosystem.
- Apple Passwords (iCloud Keychain) for iOS: If you choose to save the passkey in the Passwords app on your Apple device, all other Apple devices you own can access it.
- Google Password Manager for Android: If you choose to save the passkey in the Google Password Manager on your Android device, all other Android devices you own can access it.
|
Passkey Storage Options: Where Your Passkey Lives
|
|
Device-Bound: Stored only on the device or physical security key where it was created
|
| |
Passkey Option
|
Where It Is Stored
|
Storage Type
|
|
📱
|
Microsoft Authenticator Passkey
|
Stored in secure hardware on your phone, such as the iOS Secure Enclave or Android Keystore.
|
Device-bound
|
|
🔑
|
FIDO2 Security Key
|
Stored on an external security key, such as a Token2 or similar supported FIDO2 key.
|
Device-bound
|
|
💻
|
Windows Hello
|
Stored in the local Windows Hello container on your personal Windows computer.
|
Device-bound
|
|
🖥️
|
Windows Hello for Business
|
Stored as an enterprise-managed credential on your organization-managed Windows device.
|
Device-bound
|
|
Synced: Stored on the device and synchronized across trusted devices in the same platform ecosystem
|
| |
Passkey Option
|
Where It Is Stored
|
Storage Type
|
|
📲
|
Apple Passwords (iCloud Keychain)
|
Stored in Apple Passwords and synchronized across trusted Apple devices signed in to the same account.
|
Synced
|
|
📱
|
Google Password Manager
|
Stored in your Google Account and synchronized across trusted Android devices and Chrome.
|
Synced
|
Passkey Options Supported by NEOMED
NEOMED recommends the passkey options listed below. The NEOMED Help Desk can assist with general setup and troubleshooting for supported options. Other providers may function with your account but may not be officially supported by NEOMED. For an unsupported provider, contact that provider for assistance or switch to a NEOMED-supported option.
- Microsoft Authenticator passkey
- Apple Passwords / iCloud Keychain
- Google Password Manager
- Token2 FIDO2 security key
- Windows Hello
Related Articles
Use the following articles for additional guidance on selecting, creating, storing, and using passkeys with your NEOMED account.