If you don't own a smartphone, your phone does not meet the minimum requirements for the Microsoft Authenticator app, or you'd prefer not to use your phone for multi-factor authentication (MFA), you still have several supported options. This article walks through each one so you can pick what works best for you.
Detailed Information
Before You Start: Check Your Phone
If you have a smartphone but aren't sure it's compatible, check its requirements before assuming you need an alternative option.
- iPhone/iPad requires iOS 17.0 or later
- Android requires version 14 or later
If your phone still doesn't meet the requirements after updating, or you don't have a phone at all, see the options below.
Option 1: Passkeys
A passkey is a phishing-resistant sign-in method that replaces a password and an MFA code with a single step. There are two kinds.
Device-Bound Passkey (No Phone Required)
A device-bound passkey is stored on one specific device only. It is not synced anywhere else.
Syncable Passkey (No Phone Required)
A syncable passkey is stored in a password manager and synced across your signed-in devices.
Option 2: Hardware Security Keys
A hardware security key is a small physical device that plugs into a USB port or taps via NFC. It works without a phone, without an app, and without a network connection, and it's one of the most phishing-resistant options available.
How It Works
Insert the key into a USB-A or USB-C port, or tap it against your phone or laptop's NFC reader, then touch the key's metal contact when prompted.
Recommended Models
- YubiKey 5 NFC (USB-A and NFC)
- YubiKey 5C NFC (USB-C and NFC)
- YubiKey 5Ci (USB-C and Lightning, for those who also want to use it with an iPhone)
- Security Key NFC / Security Key C NFC (a lower-cost, FIDO2-only option, if you don't need the extra protocols the YubiKey 5 series supports)
Students
Students who need a hardware security key must purchase one on their own. YubiKeys can be purchased directly from Yubico (External Link) or other online retailers, such as Amazon (External Link) or Best Buy (External Link).
Employees
Faculty and staff can request a hardware security key through IT. See Getting a Hardware Security Key (YubiKey).
Once You Have a Key
See Add MFA Sign-in Method: Hardware Security Key (FIDO2) to register your key.
Option 3: Third-Party Authenticator App
WARNING: OATH-TOTP codes are not phishing-resistant. Unlike a passkey or hardware security key, a TOTP code can be captured and reused if you are tricked into entering it on a fake sign-in page. Use this option only if a passkey or hardware security key is not available to you.
If you have a computer but no smartphone, or a phone that doesn't meet the Microsoft Authenticator app's requirements, Microsoft Entra ID accepts verification codes from third-party apps that support the OATH TOTP standard, the same standard used to generate 6-digit rotating codes.
Requirements
- The app must generate OATH-TOTP codes (6-digit codes that refresh every 30 to 60 seconds).
- Microsoft Entra ID does not support OATH-HOTP (counter-based codes).
Examples of Compatible Apps
- Google Authenticator
- Twilio Authy
- 1Password (with its built-in authenticator field)
- Bitwarden (with its built-in authenticator field)
- Any other app that supports standard TOTP codes
Comparison
| Option |
Requires a phone |
Requires an app |
Phishing-resistant? |
| Device-bound passkey (Windows Hello / Touch ID / hardware key) |
No |
No |
✅ Yes |
| Syncable passkey (iCloud Keychain / password manager) |
No |
No (built into OS, browser, or password manager) |
✅ Yes |
| Hardware security key |
No |
No |
✅ Yes |
| Third-party authenticator app (TOTP) |
No (works on a computer, if the app has a desktop version) |
Yes |
❌ No—use only if no other option is available |
Environment
- Applies to all University of Maine System (UMS) accounts
- Windows, macOS, and any device with NFC or USB support
- Does not require a smartphone