Passkey to be mandatory in Microsoft Authenticator — proceed as follows
Due to changes made by Microsoft, in future you will need a passkey in your Microsoft Authenticator app in order to sign in. The passkey will be mandatory from the 1st February 2027.
Create an authentication key now
Create an authentication key by following the illustrated instructions on the IT Services website. (The instructions will open in a new tab)
By when must the authentication key be created?
- Create an authentication key as soon as possible, but no later than 31 January 2027.
- Once the deadline has passed, Microsoft will no longer allow you to sign in until you have created an authentication key.
The "Let's keep your account secure" notification when signing in
- Microsoft suggests creating an authentication key when you sign in.
- Select "Next" if you want to create an authentication key.
- Select "Not now" if you are not yet able to create an authentication key.
- The notifications will disappear once you have created an authentication key.
- From 1 February 2027 onwards, you will no longer be able to sign in until you have created an authentication key.
What are the benefits of an authentication key?
An authentication key is an even more effective way to protect yourself against phishing.
Will the old authentication methods be discontinued?
- Authentication using a two-digit code in Microsoft Authenticator will remain unchanged.
- The one-time password (TOTP) will remain unchanged.
- Authentication by SMS message will be discontinued on 1 February 2027.
- When signing in, you can choose your preferred authentication method, although the authentication key is the primary option.
Is the email message sent by Microsoft genuine?
Make sure that the link ends with ".onmicrosoft.com"
Microsoft has sent its users, including members of the Metropolia community, email messages about enabling the authentication key. If you click the link in the message, you will be taken to an address ending in .onmicrosoft.com. Before clicking the link, check the address. Attackers seeking to steal information could send an identical-looking message in which the link leads instead to a phishing site designed to harvest your information.
Microsoft has also sent members of the Metropolia community email messages concerning the review of access rights, with subject lines such as "Action required: Review group access". These messages will be communicated about separately in the near future.
Other reliable domains in messages sent by Microsoft include, for example, office365.com, microsoftonline.com and microsoft.com. Always ensure that the message is genuine before clicking a link.
You can find illustrated instructions for identifying phishing messages on the IT Services website.
Best regards,
Helpdesk
In case of any inquiries related to this announcement or other IT matters at Metropolia, please contact the Helpdesk as follows:
Phone service: +358 9 7424 6777
Service requests: hd.metropolia.fi / helpdesk [at] metropolia.fi (helpdesk[at]metropolia[dot]fi)
Frequently Asked Questions: itservices.metropolia.fi/FAQ
Ask Mikko Anything (AMA): mikko.metropolia.fi