Turn on passwordless sign-in
This is the in-app switch that lets you approve sign-ins with a tap instead of typing a password. About 7 in 10 of you already have it on — if you can already sign in by approving a notification on your phone, you're set: skip straight to Stage 2. If not, here's how. Good news either way — setting up a phone passkey in Stage 2 turns this on for you automatically, so you won't have to circle back.
- On your phone, open the App Store (iPhone) or Google Play (Android).
- Search for Microsoft Authenticator (publisher: Microsoft Corporation) and install it.
- Open the app and accept the privacy prompts. Don't add an account yet — the next step does that.
- On a computer, go to your Security info page:
- Sign in with your Ascent email and password (and approve MFA if prompted).
- Select + Add sign-in method → Microsoft Authenticator → Add.
- When the QR code appears, open Authenticator on your phone → + → Work or school account → Scan QR code, and scan it.
- Approve the test notification to confirm the link.
- In Microsoft Authenticator, tap your Ascent account.
- Tap Set up phone sign-in (may read "Enable phone sign-in" / "Set up passwordless").
- Follow the prompts. You may be asked to verify with MFA and to set a device lock if you don't have one.
Create a passkey
A passkey is a phishing-resistant credential locked to your device and unlocked by your face, fingerprint, or PIN. Ascent allows two kinds: a passkey in Microsoft Authenticator (your phone) and Windows Hello (your work PC). Pick the device you want to set up — you can do both.
- Make sure you finished Stage 1 (Authenticator installed + your Ascent account added).
- Make sure your iPhone has a screen lock set up (Face ID, Touch ID, or a passcode).
- Turn Authenticator on as a passkey provider:
iOS 18: Settings → General → AutoFill & Passwords
iOS 17: Settings → Passwords → Password Options
Turn on AutoFill Passwords and Passkeys, then enable Authenticator under "Autofill from". - Open Authenticator → tap your Ascent account → Create a passkey.
- Complete MFA when prompted, then follow the on-screen steps to finish.
- Done — you'll see Passkey listed under your account in Authenticator (and on your Security info page).
- Make sure you finished Stage 1 (Authenticator installed + Ascent account added).
- Make sure your phone has a screen lock (fingerprint, face, or PIN).
- Set Authenticator as a passkey provider:
Settings → Passwords, passkeys & accounts → choose Authenticator as a provider. (Exact path varies by phone maker.)
- Open Authenticator → tap your Ascent account → Create a passkey.
- Complete MFA when prompted, then follow the on-screen steps.
- Done — Passkey now appears under your account and on your Security info page.
- Open Settings → Accounts → Sign-in options.
- Set up a PIN (Windows Hello), and add Fingerprint or Facial recognition if your device supports it.
- If Windows prompts you to set this up at sign-in, you can just follow that prompt instead.
- On your PC, open your Security info page (link at the top of Stage 1).
- Select + Add sign-in method → Passkey.
- When asked where to save the passkey, choose This device / Windows Hello.
- Verify with your PIN or biometric to finish.
Follow the iPhone or Android steps above to create a passkey in Microsoft Authenticator. You only do this once.
- Keep Bluetooth on and your phone nearby.
- At the Mac sign-in screen, choose Sign in with a passkey (or "Other ways to sign in" → passkey).
- Pick the option to use a phone. A prompt appears on your phone.
- Approve it with your face / fingerprint / PIN. You're in.
Now use it the right way
Creating the passkey is only half the job. You get true phishing-resistant sign-in only when you choose your passkey at login — not when you type a password and approve a push. Here's the one move to remember.
At the Microsoft sign-in screen, choose Sign-in options (or Other ways to sign in) → Face, fingerprint, PIN, or security key.
- Open the app or site you're signing in to (for example, office.com), or start from the Windows lock screen.
- If you aren't offered your passkey automatically, select Sign-in options — or, after typing your name, Other ways to sign in.
- Choose Face, fingerprint, PIN, or security key.
- Using Windows Hello (your PC): verify with your face, fingerprint, or PIN. You're in.
- Using your phone's passkey: pick iPhone, iPad, or Android device, scan the QR code with your phone's camera, then approve with your face / fingerprint / PIN. Keep Bluetooth on and the phone nearby.
A password plus a "tap to approve" push can still be stolen — a convincing fake login page can capture your password and trick you into approving the attacker's sign-in. A passkey is cryptographically tied to the real Microsoft sign-in address. Present it to a lookalike site and it simply won't work, because the site isn't who it claims to be. There's no code to read out, no prompt to approve by mistake, and nothing for an attacker to reuse. That binding to the genuine site is what "phishing-resistant" means — and it's why choosing the passkey at sign-in matters, not just having one.
Stuck on a step?
The Service Desk can issue a Temporary Access Pass, reset a method, or walk you through it live.
Contact the Service Desk