Using passkeys to sign into your LSE account

Passkeys replace passwords as a more secure way to login to your LSE account. This article explains what passkeys are, the reasons for using them and the rollout of passkeys for LSE accounts.

passkey-red-transparent-cropped

What is a passkey?

A passkey is a replacement for your password. Instead of typing a username and password to sign in, you login with a cryptographic ‘key’ that is stored on your device (e.g. your phone) and validated with your fingerprint, face scan, or a PIN.

 

Why switch to passkeys?

Traditional MFA (multi-factor authentication) that validates a username and password with approval via an app or code has become vulnerable to sophisticated phishing attacks where:

  1. a fake sign-in page captures your password and immediately uses it on the real site
  2. the real site sends you a genuine MFA notification, which you approve because it looks legitimate
  3. the attacker is now signed in as you and may go on to create additional MFA methods in your account that they can continue to use

Phishing resistant MFA using passkeys addresses this vulnerability in the following ways:

  • there is no password for an attacker to capture
  • the passkey is registered and bound to the site that it was set up for. It will not work on a fake site

Passkey sign-in methods

Passkeys for LSE logins can be stored in different ways that provide varying levels of security and convenience.
Apps that can store passkeys include:  

  • Microsoft Authenticator (which most LSE staff and students already use for MFA)
  • Apple iCloud Keychain (on iPhones and MacBooks)
  • Google Password Manager (on Android phones)
  • Password management tools like Bitwarden and 1Password can also store passkeys. 

Passkeys can also be stored on USB hardware devices, most commonly “Yubikeys”.

Staff with LSE-managed Windows laptops will soon be able to use Windows Hello to login to their LSE Microsoft account without needing to enter their password.  

The simplest option to set up and store a passkey is to use a phone app like Microsoft Authenticator, Apple Passwords or Google Password Manager.

 

Passkey enforcement

From 1 September 2026, when logging on to an LSE account, users without a passkey will occasionally be prompted by Microsoft to set one up. The prompt will guide users through the steps to set up a passkey. Users can skip the prompt and continue to use their existing MFA methods to validate a login using their password, but will be prompted again at future logins.

From 1 February 2027 the sms and phone methods for validating a login will be withdrawn by Microsoft and will no longer work. Users who regularly use sms or phone validation will be prompted to set up a passkey before 1 February 2027.

During 2026 LSE users can login with a passkey or with their email, password and MFA. To improve the security of LSE accounts, passkey only logins will be enforced for most users in future, most likely at some point in 2027.

 

Setting up a passkey

Instructions for setting up a passkey in various apps are in the following guides: 

Setting up a passkey when prompted by Microsoft

Setting up a passkey in Microsoft Authenticator

Setting up a passkey in Apple Passwords iCloud Keychain

Setting up a passkey in Google Password Manager

 

Logging in with a passkey

Sign-in using a passkey on your phone