Microsoft Entra
Boise State uses Entra to provide multi-factor authentication (MFA), with passkeys becoming the default MFA method beginning September 1.
Passkeys provide a faster, more secure way to verify your identity using your device’s built-in security features.
To set up a passkey or add or update another authentication method, sign in to Microsoft Security info. Scroll down for more information and instructions.
Passkeys will be the new default for MFA
Beginning September 1, Microsoft will recommend passkeys as the preferred authentication method for Entra.
Passkeys are both more convenient and more secure. Once set up, you’ll use your passkey to sign in to Boise State applications instead of entering your password each time.
Expand the following sections for more information and setup instructions.
Learn more about passkeys
What is a passkey?
A passkey is a secure way to verify your identity using the same method you use to unlock your device, such as your fingerprint, face recognition, or device PIN. Once you set up a passkey, you can use it instead of entering your password and completing a separate MFA prompt.
Why use a passkey?
Passkeys make signing in:
- Faster: Authenticate with your face, fingerprint, or device PIN instead of entering a code or responding to a notification.
- Easier: There’s less to remember and fewer steps to complete when you sign in.
- More secure: Passkeys are resistant to phishing because they’re tied to your device and the website or service you’re signing in to. They can’t be tricked out of you through a fraudulent login page or unexpected MFA request.
You can continue to have other authentication methods, such as the Microsoft Authenticator app or a security key, registered as backup options.
How do I know if my device supports passkeys?
You don’t need to check your device before getting started. When you add a passkey in Microsoft Entra, the setup process will determine whether your device supports passkeys and guide you through the available options.
If your device can’t create a passkey on its own but can install the Microsoft Authenticator app, you can use Authenticator to create a passkey for your Boise State account. If your device doesn’t support either option, you can use another available MFA method.
Do I need to install an app to use a passkey?
No. You don’t need to install an app to use a passkey. Passkeys use security features already built into your device, such as a PIN, fingerprint, or facial recognition. You can set up a passkey through your Microsoft Security info using a supported device and browser.
Microsoft Authenticator is still available as an MFA option, but it isn’t required to set up or use a passkey. If your device can’t create a passkey on its own, you may be able to use the Authenticator app to create one instead.
Set up a passkey
Step 1: add a passkey to Microsoft Entra
- Go to Microsoft Security info and sign in with your Boise State account.
- Select + Add sign-in method.
- Select Passkey, then select Next.
- Follow the prompts to create and save your passkey. The options you see will depend on your device and browser. Your device may ask you to use a PIN, fingerprint, facial recognition, or another security method.
- Give your passkey a name that will help you identify the device, then select Next or Done to finish.
Tip: You can set up a passkey on more than one device, such as your computer and phone. Each passkey must be added separately in your Microsoft Entra security settings.
Step 2: sign in to your applications
The first time you sign in to each Boise State application, enter your Boise State password. After that, you’ll use your passkey instead of entering your password each time you access the application.
Set up multiple passkeys
Do you usually use your phone for MFA? Set up a passkey on more than one device, such as your computer and phone, so you have another way to access your account if your phone isn’t available.
If you get a new phone and don’t have another passkey set up:
- Don’t remove or erase your old phone until you’ve added a passkey for your new phone.
- Use your other registered device to sign in to Microsoft Security info and add the new passkey.
Other MFA options
Expand the following sections for more information and instructions.
Add the Microsoft Authenticator mobile app
Important: When setting up your Boise State account, start from Microsoft Security info and use the QR code provided there. Don’t try to sign in to your Boise State account directly from the Authenticator app during setup.
- Go to Microsoft Security info and sign in with your Boise State account.
- Select + Add sign-in method.
- Select Microsoft Authenticator, then select Next.
- If you haven’t already, install the Microsoft Authenticator app on your phone.
- In the Authenticator app, select + to add an account, then select Work or school account.
- Select Scan a QR code and use your phone to scan the QR code displayed on your computer.
- Follow the prompts to complete setup, then select Next and Done in Microsoft Security info.
Add a security key
If you are unable to register for Entra using a passkey or the Authenticator app, please contact the Help Desk to learn more about purchasing and registering with a security key.
The Boise State Bookstore sells YubiKey security keys with USB-A and USB-C connectors. Use the button below to view available options.
SMS authentication is going away
Microsoft and other major authentication providers are moving away from SMS text messages as a multi-factor authentication (MFA) method because stronger, more phishing-resistant options are available.
Boise State will no longer use SMS for MFA after February 1, 2027. If you currently use text messages to verify your identity, we recommend setting up a passkey or another available MFA method before SMS authentication is removed.
Passkeys are the recommended MFA method because they provide a faster, simpler, and more secure way to verify your identity. We also recommend setting up more than one authentication method so you have a backup if one isn’t available.
Security reminder
Never approve an authentication request unless you are actively signing in to Boise State services.
If you receive an unexpected push notification in the Authenticator app, select “No, it’s not me” to block the request.
Do not share authorization codes with anyone. Boise State will never ask for this information.
If you receive an authentication request you did not initiate, please contact the Help Desk immediately at (208) 426-4357.
Need assistance?
For more information, contact the Help Desk at (208) 426-4357, helpdesk@boisestate.edu, or ServiceNow.