This article is a guide on how to add a hardware security key as a form of Multi-Factor Authentication (MFA) for your Microsoft account.
Prerequisites
- Have login credentials to Microsoft Account with MFA enabled. If this is your first MFA, obtain a Temporary Access Pass (TAP) from your administrator.
- Have a FIDO2 hardware key or similar.
Instructions
The following instructions are made with the assumption this will be your account's first form of MFA. If your account already has another form of MFA, it may be used in place of a TAP.
Register the Security Key
1. Go to mysignins.microsoft.com. If prompted, login and provide MFA or the TAP.
2. Under Security Info, select Add sign-in method.
3. Select Security key as the sign-in method. Scroll down to select it if necessary.
4. You are now prompted to insert your security key to continue. If your key has biometrics, ensure the sensor is facing you for convenience.
5. Once inserted, your security key will be recognized. Enter a PIN to secure your hardware key. If prompted, touch the sensor on your security key. If prompted, provide a meaningful name for your security key.
6. Once complete, you will see the security key listed under sign-in methods.
Using the Security Key
When logging into a Microsoft web resource (Office365, Outlook email, etc.), you will be prompted for MFA.
1. Enter your username.
2. Enter your password.
3. You will be prompted to verify your identity. If you have multiple options available, select the one that says security key.
4. Insert your security key, enter your pin, and follow any on-screen prompts.
5. Once complete, you will be allowed access to the web resource.
Notes
- If possible, add the hardware key to a key chain or other personal possession you are unlikely to lose.