It is a priority to keep your data safe and secure. Find out how secure passkeys are with our FAQs below.
Security and privacy questions
- Is my biometric data shared?
- What data is stored when I use a passkey?
- Can someone access my account if they have my device?
- Will MFA One-Time Password (OTP) using the Microsoft Authenticator app still be used?
- Will One Time Password (OTP) via email, phone call or SMS still be used?
- Why are my existing phone or SMS authentication methods removed once I have added a passkey?
No, your fingerprint or face identification data stays on your device only and is never shared with 51³Ô¹ÏÍø or Microsoft.
When you create a passkey, two pieces of information are created:
1. The private key:
- stays securely on your device (e.g. desktop, laptop, phone or hardware key).
- is protected by your device’s security (i.e. PIN, fingerprint, or face recognition).
- is never shared or sent anywhere.
2. The public key:
- is stored by the service (e.g. Microsoft 365) you are signing in to.
- cannot be used to access your account on its own.
If someone gets hold of your device, they can only unlock it using your face ID, fingerprint or PIN. (This is unlikely to happen unless you are under duress.
Please ensure your devices (which are not shared with others):
- use strong device security - set up your devices with a PIN or biometric (FaceID or Fingerprint). Speak to ICT Service Desk if you are unsure how to set this up.
- are kept for your use only and not shared with others.
Other shared evices do not have the ability to use device-bound authentication.
Yes, the Microsoft Authenticator app (get from or store) will still be used for Multi Factor Authentication (MFA) when a passkey is unavailable or cannot be used.
You may need to use MFA through the Microsoft Authenticator app, which will auto revert to number matching, if one or more of the following conditions apply:
- You have not yet set up a passkey.
- You are using a new or unregistered device.
- Your device does not support passkeys (see Passkey and device compatibility FAQs)
- You are signing in from a shared or restricted device.
- The application or service you want to log in to does not support passkeys.
- You have reached your passkey limit (more than 10 devices).
- There is a security check or unusual sign-in activity on your account.
No. To strengthen 51³Ô¹ÏÍø’s security, all existing users will be moved to passkeys or MFA via the Microsoft Authenticator app by the end of July 2026.
When a passkey is added to your account, it promotes the passkey to the primary (phishing-resistant) authentication method and removes phone or SMS One Time Pasword (OTP), as these are less secure authentication methods that can be easily phished.
More Passkey FAQs
Support and further guidance
- Contact the ICT Service Desk for general passkeys enquiries and support
- (ubikey/fido key).
- Report suspicious or unexpected behaviours to ICT Security.
- For anything related to our Passkey Champions network contact Ingrid Joannou
- Keep up with the latest cyber guidance on our Be Secure webpages.