A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
I believe you are referring to a security key (hardware token), sometimes called a FIDO2 key, which is a passwordless authentication method available as a sign-in option in Windows that is used with a unique PIN or fingerprint for authentication instead of a username and password. Security keys are physical devices like USB drives, NFC devices (smartphone, tablet, gaming console, access card) or Bluetooths which must be unlocked with a PIN or fingerprint before it can be used to sign in to Windows, apps, websites and work or school accounts.
Since a security key is used in addition to a PIN or fingerprint they are a stronger verification method than a username and password. Security keys adhere to Fast IDentity Online (FIDO) standards, ensuring cross-platform compatibility and support across various websites and applications. Even if someone steals your security key, they will not be able to sign in without your PIN or fingerprint. You can have up to 10 keys registered with your account.
- How to sign in with or add a security key as a sign in method for your Microsoft account
- How to set up and register a security key (FIDO2) as a sign in verification method
- Passkeys vs Security Keys: Which One Offers Better Protection?
Passkeys (passwordless authentication) rely on public-key cryptography (keypair concept: a private key and a public key) in combination with Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in.
For more specific information about passkeys, please read All about PINs, Passkeys & Security Keys and Microsoft Authenticator Mobile APP (Post #23)