Body
Your Massasoit account gives you access to your email, Canvas, Microsoft services like Office 365, OneDrive, Teams, and more. You can sign into it quickly and securely with a passkey stored in the Microsoft Authenticator app on your phone.
This guide covers everything from your very first sign-in and passkey setup to signing in every day. It applies to students, faculty, and staff at Massasoit.
Jump to the part you need:
- How signing in works
- What is multi-factor authentication (MFA)?
- What is a passkey?
- Why passkeys are safer
- Do I still need a password?
- Recognizing a real sign-in request
- Before you start
- Sign in for the first time
- Get your first-time sign-in information
- Complete your first sign-in
- Set up Microsoft Authenticator
- Create your passkey
- Sign in with your passkey
- On your phone
- On a computer
- Troubleshooting
- Get help
1. How signing in works
Massasoit accounts are secured with Multi-Factor Authentication. What that means is that you'll need to set up and use something beyond just a password to access your account. The easiest and most secure multi-factor sign-in method is a passkey.
1.1 What is multi-factor authentication (MFA)?
MFA means proving who you are with at least two different kinds of evidence, called factors:
- Something you know, such as a password or PIN
- Something you have, such as your phone
- Something you are, such as your face or fingerprint
The important word is different. A password plus a security question is two steps, but both are something you know, so together they only count as one factor. Real MFA means that someone who steals one factor still can't get into your account without the other.
A debit card works the same way. To withdraw cash, you need the card (something you have) and its PIN (something you know). A thief who only has one of them gets nothing.
Massasoit requires MFA for all sign-ins while off-campus. When you're on-campus and connected to the secure network, MFA won't be required for most sign-ins.
1.2 What is a passkey?
A passkey is a secure sign-in credential stored on a device, such as in the Microsoft Authenticator app on your phone. You can think of it like a physical lock and key: when you create a passkey, your device holds the key, and your Massasoit account holds the one lock it fits. Before your device will use the key, you unlock it with your face, fingerprint, or PIN.
For our online sign-ins at Massasoit, such as accessing the Portal, email, or Canvas, using a passkey effectively replaces a password.
That one step of using a passkey covers two factors at once:
- Your device (something you have). The passkey lives only on that device and can't be copied off it.
- Your face, fingerprint, or device PIN (something you are or know). The passkey won't work until you unlock it. Your fingerprint, face, and PIN stay on your device and are never sent to Massasoit or Microsoft.
So even though signing in with a passkey is a single step, it is full multi-factor authentication: if someone wanted to get into your account, they'd need to physically have your device and be able to unlock it. It's also quicker and easier; you don't need to enter a password or verification code when you use it.
1.3 Why passkeys are safer
Scammers build fake websites that look exactly like official sign-in pages. If you type a password or a text-message code into one of these pages, the scammer can use it to get into your account. Beyond that, passwords are codes you need to remember, and they only get harder to remember over time as websites and services raise their requirements, make you reset your password more and more often, and don't let you use previous ones. Passwords often get written down or saved in a file somewhere on your computer, drastically reducing the security they're meant to provide.
A passkey only works on the real sign-in page it was created for. A fake page can't use it, and there's no code for anyone to steal. That makes passkeys much safer than passwords and verification codes, even though they take less effort.
For these reasons, Microsoft and other organizations call passkeys as a phishing-resistant sign-in method.
1.4 Do I still need a password?
Yes. Your passkey is how you sign into the MyMassasoit Portal and other online services like Office 365 and Canvas. You'll still use your password for other things:
- The Massasoit Secure WiFi network on-campus
- Signing into on-campus computers such as in labs or offices
- Other assorted sign-ins, usually on-campus
Keep your password, and never share it with anyone - including Massasoit faculty and staff, even in ITS!
1.5 Recognizing a real sign-in request
Scammers sometimes imitate Microsoft's sign-in screens. A real request to sign in or create a passkey:
- Typically appears right after you start signing in yourself, on a page you went to on purpose. It never arrives through an email link.
- Shows a Microsoft address in the address bar, such as login.microsoftonline.com.
- Never asks you to share a code with anyone or use a code shared by someone else. Massasoit ITS will never ask for your password, a sign-in code, or to scan a QR code someone else sends to you.
Not sure? Close the page, go to the MyMassasoit Portal yourself, and sign in again. To be sure, you can always access the Portal by navigating to the main Massasoit website (massasoit.edu) and clicking MyMassasoit Portal at the top of the page (in a 3-line menu if it doesn't show at the top). If the prompt appears there, it's real.
Back to top
2. Before you start
You'll need:
- Your Massasoit sign-in information
- If it's your first time signing in, section 3 has you covered.
- A smartphone
- A screen lock on that phone: Face ID, fingerprint, or a PIN/passcode
- About 10 minutes for first-time setup. After that, signing in takes a few seconds.
Don't have a compatible smartphone? The ITS Help Desk is here to help. Contact us to discuss other options.
Back to top
3. Sign in for the first time
If you've already signed into your Massasoit account and set up Microsoft Authenticator, skip to section 5.
3.1 Get your first-time sign-in information
Your email address and a first-time temporary password are emailed to your personal email address. For students, this email comes from Student Central. Faculty and staff are emailed from ITS through our ticketing system, TeamDynamix.
Be sure to check your spam, junk, or other folders for the email.
If you don't see the email with your first-time sign-in information, please contact the ITS Help Desk.
3.2 Complete your first sign-in
- Navigate to the MyMassasoit Portal.
- Enter your Massasoit email address and select Next.
- Enter your temporary password and select Sign in.
- You'll see a screen that says More information required. Select Next. This starts your security setup.
- Follow the prompts to download and install the Microsoft Authenticator app. Section 4 below walks through how to install and use the authenticator step-by-step.
- You'll be asked to create a new password. Fill out the fields on the screen to enter your current (temporary) password, then a new one, and then confirm the new one.
- Massasoit's password requirements:
- Minimum of 15 characters
- Must be different from a previous password
- Cannot contain your personal information, such as your name or date of birth
Back to top
4. Set up Microsoft Authenticator
To install the app and add your Massasoit account, follow these steps:
- On your phone, open the App Store (iPhone) or Play Store (Android).
- Search for Microsoft Authenticator. Check that the publisher is Microsoft Corporation, then install it.
- Open the app. If it asks to allow notifications, choose Allow. This is how sign-in requests reach you.
- Add your Massasoit account:
- If you're in the middle of your first sign-in (section 3): follow the on-screen instructions on your computer. When it shows a QR code, tap + in the Authenticator app, choose Work or school account, then Scan QR code. Point your phone at the screen to scan the QR code, then click Next on the computer.
- Otherwise: in the app, tap +, choose Work or school account, then Sign in, and sign in with your Massasoit email address.
- Your Massasoit account should now appear in the app's account list.
Back to top
5. Create your passkey
Once you've signed into your Massasoit account, have a password you created, and you've set up an MFA method such as the Authenticator app, you're ready to create a passkey.
There are a few ways to create a passkey - you may be prompted to create one during sign-in, or you can create one in your account settings or the Authenticator app. These will all produce the same result, but for the smoothest and easiest experience, we recommend creating a passkey using the Microsoft Authenticator app. You only need to do this once per phone.
Before following these steps, make sure you've set up the Microsoft Authenticator app on your phone using the steps in section 4.
Creating a passkey in the Authenticator app
- Open Microsoft Authenticator on your phone.
- Tap your Massasoit account.
- Tap Create passkey.
- Sign in if asked, then unlock with your face, fingerprint, or PIN.
- If prompted, tap Settings and set up a screen lock.
- If prompted, tap Settings and allow Authenticator to autofill (iPhone) or use passkeys (Android).
- Once you've tapped Settings, you'll be redirected to your phone's settings app. Make sure that Authenticator is enabled on this screen. Once it's set to enabled, you can navigate back to the Authenticator app.
- This step may vary based on the make and model of your device.
- After you return to the Authenticator, tap Done to confirm the setting.
- You can now see Passkey added as a sign-in method for your account. Tap Done to finish.
For Microsoft's official step-by-step instructions including screenshots and separate iOS and Android walkthroughs, see their article here: Register passkeys in Authenticator on Android and iOS devices
Back to top
6. Sign in with your passkey
Once your passkey is set up, this is how you'll sign in every time. You don't need to enter your password.
6.1 On your phone
- Open the website or app you want to use (for example, the MyMassasoit Portal, Canvas or Outlook).
- Enter your Massasoit email address.
- The page will say Face, fingerprint, PIN, or security key and prompt you to use your passkey. Follow the prompt to use your saved passkey.
- Unlock with your face, fingerprint, or PIN. You're signed in.
6.2 On a computer
Note: Bluetooth is required while signing in on a computer. Ensure that Bluetooth is enabled on both your phone and the computer you're signing in on.
- Navigate to the website you want to use and enter your Massasoit email address to sign in.
- If you see a password prompt, select Other ways to sign in, then Face, fingerprint, PIN or security key.
- If asked where your passkey is or to choose which one, select iPhone, iPad, or Android device. A QR code will appear.
- Open your phone's Camera app and point it at the QR code. Tap the link that appears (it should say Use passkey or Sign in with passkey).
- Unlock with your face, fingerprint, or PIN.
- Your computer finishes signing you in.
Once a passkey is set up on your account, Massasoit logins should offer it first, so you won't usually need to select Other ways to sign in.
On a shared or campus computer: Always sign out when you're done. Your passkey stays on your phone, not the computer, so the next person can't use it.
Back to top
7. Troubleshooting
- The QR code won't scan, or scanning does nothing.
- While setting up the Authenticator app during first-time sign-in: Use the Authenticator app's scanner, not your phone's built-in Camera app.
- While signing in and using a passkey: Use your phone's built-in Camera app, not the Authenticator app's scanner.
- Make sure the whole code is visible and your screen brightness is up.
- It says it can't connect to my phone or doesn't give the option for a passkey during sign-in.
- Bluetooth must be enabled on your phone and the computer for a passkey to work. Keep your phone within a few feet of the computer.
- I don't see "Create passkey" in the Authenticator app.
- Update the app from the App Store or Play Store, and check that your phone is running iOS 17 or later, or Android 14 or later.
- I got a new phone.
- Your passkey doesn't move to a new phone automatically. Before you reset or trade in your old phone, install Authenticator on the new one and create a new passkey using section 5. If you've already given up the old phone, contact the ITS Help Desk.
- I lost my phone or it was stolen.
Back to top
8. Get help
The ITS Help Desk is here to help with any step in this guide or any other questions you might have!
-
Walk-in: the Fine Arts building on the Brockton campus, room FA456
-
Phone: 508-588-9100 extension 1139
-
Email: helpdesk@massasoit.mass.edu
-
Business hours: Monday-Friday 8am-5pm
Back to top