Please Note

Before beginning the process, please download the Microsoft Authenticator app to your phone from an official app store such as Google Play or the Apple App Store. You will need the app for step 7 of the process below.
A video walkthrough is available on the Microsoft website.

 
  1. Go to https://mysignins.microsoft.com/ 
  2. Sign in using your CCAC Email Address and click Next
  3. Enter your password and click Sign in
  4. Select Security Info

  1. Click Add sign-in method

  1. Select your method (it is recommended that you select Microsoft Authenticator and one other method from the list). Do Not Select Hardware Token unless you have a personal hardware token available

  1. Follow the prompts of your selected method. If you choose one of your selections as Microsoft Authenticator, please continue if you need assistance with the process. This process should be completed on a computer
  2. Open the app and click Add account or the + icon on the top-right of the app

  1. Choose Work or school account

  1. Choose Next

  1. You will see a QR code. Scan the QR code.  Click Next
    • You may need to allow the app to have access to your phone’s camera 

  1. On your phone, select Scan QR Code
    • Your account should now appear on Microsoft’s Authenticator app’s home screen

  1. On your computer screen, you will be asked to “try it out." Choose Next

  • The app will generate a number on your computer screen, and it will ask you to enter the number on your phone

  • Select Yes
    • On your computer, you may have to click the Next button after the Yes turns blue. 
      Otherwise, you will get a message showing the notification was approved. Then choose Next
  1. When you complete the steps correctly, the following screen will appear – click Done




 

If you would like to setup an additional authentication method

Starting from step 6 above, you can follow these alternate instructions. Having an alternate authentication method can help prevent you from being locked out of your account if something happens to your primary login method. 

Phone

 

  1. In the pop-up on the computer, enter in the phone number that you would want to get a text message to and click Next.
  2. You will then be prompted to enter in the code sent to you by text message. Enter the code you recieved in a text and click Next.
  3. You will get a message saying Verification complete, and have succesfully added your phone number as a method to recieve MFA prompts. Click Done.
 
 

Email

This cannot be your CCAC email

Please make sure to use a non-CCAC email address that you expect to have constant access to. The Microsoft website has up-to-date instructions for this process if you are unsure of any of the steps listed. 

 

 

  1. In the pop-up, enter your email address into the text field, then click Next
  2. Enter the numeric code that was emailed to you and then click Next
  3. You will get a pop-up that says ‘Email was succesfully registered’ and the email address will now show on the list of sign-in methods. 
 
 

YubiKey Passkey

What is a Passkey?

Passkeys allow you to sign in to Microsoft services using a hardware security key such as a YubiKey. This enhances security and simplifies login. To learn more about Yubikeys specifically, you can go to Yubico's website

 

Prerequisites before you begin

  • You must have a supported YubiKey.
  • You must be allowed to register security keys by your organization’s admin.
  • You must be using a supported browser:
    • Microsoft Edge
    • Google Chrome
 

1. Go to Your Microsoft Account Page

  1. Open a browser and go to:
    https://myaccount.microsoft.com/
  2. Sign in with your Microsoft/Work account.
  3. Click on the Security Info tab.

2. Add a New Authentication Method

  1. Click + Add sign-in method.
  2. In the dropdown menu, select Security key.
  3. Choose USB device (for a physical YubiKey you plug in)
  4.  Click Add.

3. Begin Security Key Setup

You’ll be prompted with a Microsoft setup wizard:

  1. Select USB (for YubiKey).
  2. When asked, insert your YubiKey into your computer’s USB port.
  3. If prompted by Windows Security or your browser, tap the YubiKey’s circle contact to verify presence.

4. Create a PIN for Your YubiKey

If this is the first time using passkey/FIDO2 features on your YubiKey:

  1. You'll be asked to create a PIN.
  2. Enter a secure PIN and confirm.

This PIN is required for future authentication events.

 

5. Name Your YubiKey

  1. After verification, you will return to Microsoft’s setup.
  2. Give your YubiKey a friendly name like:
    • “YubiKey 5 – Work Laptop”
    • “USB Passkey”
  3. Click Done.

6. Confirm the Passkey is Registered

On the Security info page:

  • You should now see Security key listed as a sign-in method.
  • Optional: Click Security key to test or remove it.

How to Sign-in with Your YubiKey Passkey

When signing into Microsoft apps:

  1. Choose Sign in with a security key.
  2. Insert your YubiKey.
  3. Enter the PIN (if required).
  4. Tap the gold contact on the YubiKey.

You’re in.

 
 

 

 

Changing the default sign-in method

Set your default method to what works best for you

If you have set multiple sign-in methods you may want to change which option it defaults to in order to keep your day flowing quickly. The Microsoft website has more information on the different types of authentication methods and how they function, so you can set the default that works best for yourself.

 
  1. From the Microsoft security info page (Step 4 above), click the Change option
  2. In the pop-up use the dropdown menu to select your desired default method
  3. Click confirm
  4. You will get a green pop-up that says “Your default sign-in method was updated” and the default sign-in method shows will change to your selected method. 
 
 

 

0