Account - FIDO Security Key
Besides the Microsoft Authenticator app, you can sign in to Microsoft 365 using a FIDO2 security key (also called a passkey). This is a password-less, phishing-resistant option that gives you flexibility.
A FIDO2 key (such as a YubiKey) is a small hardware device that uses strong cryptography to verify your identity. During sign-in, you insert the key (USB) or tap it (NFC) and enter a quick verification like a PIN.
Instructions
If you don’t have a FIDO key, you can request one via the Hardware Procurement Request form.
Sign in at myaccount.microsoft.com.
Go to Security info > Add sign-in method.
Select Security key.
Choose key type: USB or NFC.
Follow prompts:
Insert/tap key
Set/confirm PIN
Touch key if required
Done! Your key is now registered.
Choose this method if you want:
A hardware-based sign-in option
A phishing-resistant way to access Microsoft 365
An alternative to phone-based authentication
Keep your key secure, like a badge or house key.
Never share your key or PIN.