Massachusetts State Seal An official website of the Commonwealth of Massachusetts Here's how you know

Official websites use .mass.gov

A .mass.gov website belongs to an official government organization in Massachusetts.

Secure websites use HTTPS

A lock icon or https:// means you've safely connected to the official website. Share sensitive information only on official, secure websites.

Set up multifactor authentication (MFA) and secure sign-in methods

The Commonwealth uses multifactor authentication (MFA) and passwordless sign-in methods to help protect your account and Commonwealth information.

Microsoft is moving toward more secure, phishing-resistant sign-in methods, including passkeys and Windows Hello for Business.

Passkeys became available on September 1, 2026. If you currently use text messages (SMS) or phone calls (voice) to verify your identity, you may be prompted to set up a passkey when you sign in.

Beginning February 1, 2027, Microsoft-provided text message and phone call authentication will no longer work. If you rely on either method, you must set up an approved replacement sign-in method before that date to avoid interruptions when signing in.

Choose the sign-in method that applies to you

Passkey in Microsoft Authenticator
Use this option if you use Microsoft Authenticator on your phone or trusted device. 

A passkey lets you securely verify your identity using your device's fingerprint, face recognition, or PIN.

Windows Hello for Business (WHfB)
Use Windows Hello for Business to securely sign in using your Commonwealth Windows computer.

Windows Hello for Business is set up separately on each computer you use. If you use more than one computer, you’ll need to set it up on each device.

You can sign in using a Windows Hello for Business PIN. Fingerprint or facial recognition may also be available on supported devices, but you don’t need to use them.

FIDO2 Security Key
Use this option if your agency has instructed you to use a physical security key. 

A FIDO2 security key is a physical device that connects to your computer using USB or works wirelessly using NFC. The security key is protected by its own PIN.

If you currently use text messages or phone calls

If you receive a text message (SMS) or phone call to verify your identity when signing in, you need to set up a replacement sign-in method before February 1, 2027.

Beginning February 1, 2027, Microsoft-provided text message and phone call authentication will no longer work. We recommend setting up your new method early so you have time to become familiar with it.

Frequently Asked Questions (FAQs)

Why is MFA changing?

Text messages and phone calls are more vulnerable to phishing and account compromise than newer authentication methods. Passkeys and other passwordless methods provide stronger protection by using more secure ways to verify your identity

They can also make signing in easier.  Depending on the method and device you use, you can verify your identity using a device PIN, fingerprint, Face ID, or security key — without needing to enter a password or verification code. 

Are Passkeys the same as Microsoft Authenticator app authorization?

No. A passkey is an authentication credential, while Microsoft Authenticator is an app that supports authentication methods for your account.

Passkeys are passwordless and phishing-resistant. Microsoft Authenticator can support passkeys as well as other authentication methods.

How do they connect?

When you set up a passkey using Microsoft Authenticator, the app securely stores the passkey and makes it available when you need to sign in.

When prompted to sign in with your passkey, you confirm your identity on your device — for example, using Face ID, a fingerprint, or your device PIN — and Microsoft Authenticator uses the passkey to authenticate you.

The easiest way to think about it: Microsoft Authenticator holds the passkey; the passkey is the credential used to sign you in.

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback