Data Bank

Passkey

What is a Passkey? Why Should We Use It?

Protecting our institutional information assets and user accounts, reducing the risk of unauthorized access, and making our digital working environment more secure are important elements of information security.

A Passkey is a modern authentication method that allows users to sign in to their accounts without entering a password by using secure authentication methods available on their devices. When using a passkey, instead of entering a password, users can verify their identity using methods such as fingerprint recognition, facial recognition, a device PIN, or a security key. This helps reduce risks such as password theft, password guessing, and the compromise of account credentials through phishing attacks. Depending on the device and service being used, passkeys can be securely stored on a device or in a supported password manager. Passkeys may be used through Windows Hello, mobile devices, security keys, or supported password managers.

Benefits of Using a Passkey

  • Secure Passwordless Access: Access your account without entering your password by using your device's secure authentication method.
  • Protection Against Phishing: Passkeys help reduce password-based phishing risks, such as entering passwords on fake websites.
  • Easy to Use: Sign in quickly using familiar device security methods such as fingerprint recognition, facial recognition, or a PIN.
  • Device-Based Security: Authentication is performed through a trusted device where the passkey is stored.
  • Support Across Different Devices: Depending on the system, passkeys can be used with computers, smartphones, tablets, or physical security keys.
  • Improved Account Security: Reducing reliance on passwords provides an additional layer of protection against certain types of attacks targeting user accounts.

How to Create a Passkey Depending on the Microsoft account and the configuration permitted by the organization, a passkey can be created for the account. In general, the following steps can be followed to create a passkey:

  1. Sign in to the Security Info section of your Microsoft account.
  2. Select Add sign-in method.
  3. Select Passkey from the available authentication methods.
  4. Select where you want to save the passkey.
  5. Complete the authentication process requested by your device, such as fingerprint, facial recognition, or PIN verification.
  6. Once the process is completed, the passkey will be associated with your account.

The available passkey options may vary depending on the device, operating system, browser, and security policies applied by the organization.

Where Can a Passkey Be Stored?

Depending on the capabilities of the system being used, passkeys can be stored in different environments.

  • Windows Hello: Passkeys can be created on Windows computers using the device's built-in security features.
  • Mobile Devices: Passkeys can be used on supported iPhone, iPad, and Android devices.
  • Password Managers: Passkeys can be stored in supported password and credential managers.
  • Physical Security Keys: Supported physical security keys can also be used to store and use passkeys.

The available storage options may vary depending on the device and service being used.

Signing In with a Passkey

Once you have created a passkey, you can use it to sign in to applications and websites that support passkey authentication. During the sign-in process:

  1. Enter your user account information.
  2. Select Sign in with a passkey.
  3. Use the authentication method requested by your device.
  4. Complete the fingerprint, facial recognition, or PIN verification.
  5. Once authentication is successfully completed, you will be signed in to your account.

In some cases, you may need to authenticate using a QR code between the computer and the mobile device where your passkey is stored.

Microsoft Support Pages

What Should You Do If Your Device Is Lost?

If a computer, smartphone, tablet, or security key containing or providing access to a passkey is lost or stolen, the incident should be reported to the relevant IT/Information Security team without delay. Particularly when a device provides access to an institutional account, the necessary security checks should be performed and the relevant authentication methods should be removed or disabled if required. Regularly Review Your Passkeys Users are encouraged to periodically review the passkeys registered to their accounts. Passkeys associated with devices that are no longer in use, as well as outdated authentication methods, should be removed when necessary to maintain account security. When acquiring a new device or retiring an old device, it is important to review the authentication methods registered to the relevant accounts. Remember! Account security is not limited to using a password. Using strong authentication methods, keeping devices secure, and being cautious about suspicious sign-in requests all contribute to protecting institutional information security. By using passkeys, you can make the sign-in process easier while improving protection against password-based attacks. If you notice any suspicious activity involving your institutional account or experience difficulties creating or using a passkey, please contact your organization's Department of Information Technology/Information Security team.

  Information Security and Data Protection Considerations

In accordance with our organization's ISO/IEC 27001 Information Security Management System and applicable data protection requirements;

  • Use strong and secure authentication methods for institutional accounts whenever possible.
  • Keep screen lock and security features enabled on devices where passkeys are stored.
  • Never share device security information such as fingerprints, facial recognition data, or PINs with other people.
  • Do not create or store institutional account passkeys on shared or untrusted devices.
  • Immediately notify the relevant IT/Information Security team if a computer, mobile device, or security key used to access an institutional account is lost or stolen.
  • Regularly review the passkeys registered to your account and remove those associated with devices that are no longer in use when necessary.
  • Pay attention to suspicious sign-in notifications or unexpected authentication requests.
  • Do not click suspicious links received through email, SMS, or other communication channels.
  • Be cautious of messages requesting passwords, PINs, verification codes, or other security information.

Using passkeys can significantly contribute to account security; however, device security and user awareness remain essential components of information security.