Using passkeys to authenticate

Passkeys replace passwords as a more secure way to login to your LSE account. This article explains what passkeys are, the reasons for using them and the rollout of passkeys for LSE accounts.

passkey-red-transparent-cropped

What is a passkey?

A passkey is a replacement for your password. Instead of typing a username and password to sign in, you login with a cryptographic ‘key’ that is stored on your device (e.g. your phone) and validated with your fingerprint, face scan, or a PIN.

 

Why switch to passkeys?

Traditional MFA that validates a username and password login with approval via an app or code has become vulnerable to sophisticated phishing attacks where:

  1. a fake sign-in page captures your password and immediately uses it on the real site
  2. the real site sends you a genuine MFA notification, which you approve because it looks legitimate
  3. the attacker is now signed in as you and may go on to create additional MFA methods in your account that they can continue to use

Phishing resistant MFA using passkeys addresses this vulnerability in the following ways:

  • there is no password for an attacker to capture
  • the passkey is registered and bound to the site that it was set up for. It will not work on a fake site

Passkey sign-in methods

Passkeys for LSE logins can be stored in different ways that provide varying levels of security and convenience.
Apps that can store passkeys include:  

  • Microsoft Authenticator (which most LSE staff and students already use for MFA)
  • Apple iCloud Keychain (on iPhones and MacBooks)
  • Google Password Manager (on Android phones)
  • Password management apps like Bitwarden and 1Password can also store passkeys. 

 Passkeys can also be stored on USB hardware devices, most commonly “Yubikeys”.

Staff with LSE-managed Windows laptops will soon be able to use Windows Hello to login to their LSE Microsoft account without needing to enter their password.  

The simplest option to set up and store a passkey is to use a phone app like Microsoft

Authenticator, Apple Keychain or Google Password Manager.

 

Passkey enforcement

From 1 September 2026, when logging on to an LSE account, users without a passkey will occasionally be prompted to set one up. The Microsoft prompt will guide users through the steps to set up a passkey. Users can skip this prompt and continue to use their existing MFA methods to validate a login using their password.

From 1 February 2027 the sms and phone methods for validating a login will be withdrawn and will no longer work. Users who regularly use sms or phone validation will be prompted to set up a passkey before 1 February 2027.

During 2026 LSE users without a passkey will be regularly prompted to set up passkey but they can continue to login with their email, password and MFA.

To improve the security of LSE accounts, passkey only logins will be enforced for most users in future, most likely at some point in 2027.

Setting up a passkey

Instructions for setting up a passkey in Microsoft Authenticator are in the following article: