Passkeys are a quick and convenient way to complete Duo Two-Step verification: Verify your identity using your device’s built-in security, such as Face ID, Touch ID, Windows Hello, a fingerprint, PIN or pattern.
| Operating System | Minimum Browser Version |
|---|---|
| Windows 11 | Chrome 108+, Microsoft Edge 79+, or Firefox 66+ |
| macOS Ventura 13 or later | Safari 16+, Chrome 108+, or Firefox 122+ |
| iOS 16 or iPadOS 16 or later | Safari 16+, Chrome 95+, Microsoft Edge 95+, or Firefox 68+ |
| Android 11 or later | Chrome 95+, Firefox 68+ |
Passkeys may not be available in every sign-in experience. Some applications use embedded browsers that do not support the features required for passkeys. We strongly recommend enrolling Duo Mobile as a backup to ensure you can always complete Duo Two-Step verification.
1. Go to twostep.buffalo.edu and sign in with your UBITName and password
2. Select My Settings & Devices
3. Sign in to Duo Manager using your UB email address and password
4. Select Add a device
5. Select the option that uses your device’s built-in authentication. The name varies by device and may appear as Face ID / Touch ID, Windows Hello, fingerprint, PIN or another option
6. Follow the instructions on your screen to add the passkey. Verify your identity using your device’s screen lock when prompted
7. When the confirmation message appears, select Continue
8. The next time Duo asks you to verify your identity, your device may automatically offer the saved passkey. Select Use Passkey, then verify using your device
Passkeys are designed to be protected by the device or password manager in which they are stored. A device-bound passkey remains on one device, such as a computer, phone or physical security key. A synced passkey is encrypted and made available on the person's other devices through a password manager such as iCloud Keychain, Google Password Manager or Microsoft Password Manager. You can learn more about setting up and using synced passkeys with password managers including, but not limited to:
We strongly recommend keeping Duo Mobile or another Duo verification method in addition to a passkey.
Your passkey may be stored on another device or password manager, or your browser or operating system may not support passkeys. If your passkey is unavailable, use another enrolled Duo verification method.
This message usually means the current sign-in experience cannot use your enrolled passkey. A bypass code is not needed. Instead, use another enrolled Duo verification method, such as Duo Mobile, or add an additional verification method to your account.
Contact the UBIT Help Center.