ܽƵ

Passwordless Authentication

How to setup passwordless authentication.

Information Technology is sharing an additional method for authenticating to your ܽƵ Microsoft Account with MFA.

Passwordless authentication populates a 2-digit number in your browser to enter into the Microsoft Authenticator app. You only need to enter your email and the code so your password stays out of the authentication process. This method further increases security on your account and limits how cyber threats can infiltrate your account. The Authenticator app currently offers texted codes and push notifications, but Passwordless is the most efficient MFA setting for your authentication needs.

The Microsoft Authenticator app  must be setup on your mobile device for ܽƵ Microsoft MFA, and the App must be set as your default authentication method from your Microsoft Sign-Ins page.

If you have not installed the MFA Authenticator app, follow the instructions below with your ܽƵ email account. Do not download any other Authenticator Apps in the store other than the links from the article below.

If your current MFA primary method is a phone-call code, texted code, or method other than the Authenticator app, switch to the Microsoft Authenticator app by going to the following and update your default method to the app.

Once the Microsoft Authenticator app has been installed as your primary sign-in method, you can continue setting up Passwordless Authentication with the following instructions.

Device Registration and Setup for Passwordless Authentication

  1. Open the Microsoft Authenticator App on your iOS or Android mobile device
    Image of Authenticator app icon
  2. Click on your Fort Lewis College username@fortlewis.edu account
    Image of Microsoft Authenticator app
  3. Select the option: “Set up Phone Sign-in, sign in without a password"
    Image of Authenticator app phone sign-in option
  4. Follow the steps required
    1. Set screen lock (if not already setup)- You can choose to set a pin, biometric, or a password, which will be required to unlock your phone before opening your Authenticator app or approving any verification. You will need to authenticate using your current method to make changes.
    2. When screen locack has been setup click continue
      Image of phone sign-in screen lock
    3. The App will load your credentials for a few moments in a loading screen
      Image of Authenticator app loading screen
    4. Click Finish when prompted
      Image of Authenticator app account added
  5. You will receive the confirmation that your account has been added. Passwordless will be your default unless you choose to change back to another App method.

End User Experience

Sign-In to your ܽƵ Microsoft Account. This works great when logging in to the cloud OpenVPN or Workday. You will not be prompted with MFA when on campus connected to the network more than once every 90 days. You will be prompted when off campus and logging in to any Microsoft Application, OpenVPN, and Workday.

  1. On your next login, type your ܽƵ email address and click NEXT. You will not need to enter your password.
    Image of Microsoft Sign in prompt
  2. You will then be given a two-digit number from your web browser. Click the pop-up notification on your mobile device from Microsoft Authenticator app, enter the number, and click “Yes”. If you don’t want to use this sign in method, you can always select “Use your password instead”.
    Image of Microsoft Approve sign in dialogImage of Authenticator app Sign in
  3. Once confirmed you will be successfully logged into your ܽƵ Microsoft account

Note: If you ever receive a prompt on your mobile device that you did not initiate, treat with suspicion, and answer “No, It’s Not Me”, or Hide the message to let the prompt expire. If you don’t know why, just deny!

How to Remove Passwordless as App Verification Method

You can switch back to push notifications, texted codes, or other non-app authentication methods at any time.

  1. To switch to another App method, open the Authenticator App, select the Fort Lewis College account, and click Disable Phone Sign-In.
    Image of Authenticator app disable phone sign-in option
  2. You will be prompted to authenticate, and the app will take several moments to remove Passwordless, and then route you back to your account.
  3. You can then choose a different sign-in method within the app: push notifications or texted code.
  4. To switch to a method that does not use the app, navigate to the following , and update your default method to any other set up method. This page can also be accessed from any O365 application by clicking your initials icon at the top right of the screen, and View Account. Click My Sign-Ins.
Updated on Mon, 20 Mar 2023 by Bodine, James