If no passkey was ever set up, the current iPhone cannot use one until it is registered first. The QR code is generated from the Microsoft account security setup page or, for work or school accounts, from the Security info page.
For a personal Microsoft account:
- Sign in to the Microsoft account Security tab at
https://account.microsoft.com/security.
- Select Manage how I sign in.
- Select Add a new way to sign in or verify.
- Choose Use an app.
- If Authenticator is already installed on the iPhone, select Set up a different Authenticator app and then Next to reveal the QR code.
- Open Microsoft Authenticator on the iPhone, tap the + icon, choose Personal account, and tap Scan a QR Code.
- If the camera cannot be used, select I can't scan the bar code on the PC and then Enter code manually in the mobile app.
For a work or school account:
- On another device such as a laptop, open a browser and sign in with MFA to Security info at
https://mysignins.microsoft.com/security-info.
- Select + Add sign-in method and choose Passkey in Microsoft Authenticator.
- If prompted, complete MFA and continue.
- On iPhone, enable Authenticator as a passkey provider:
- iOS 18: Settings > General > Autofill & Passwords
- iOS 17: Settings > Passwords > Password Options
- Turn on AutoFill Passwords and Passkeys and make sure Authenticator is selected under Autofill From.
- Continue the setup in Authenticator to create the passkey.
If the sign-in screen is asking for a passkey but none exists yet, use another available sign-in method first, then add Authenticator or create the passkey from the account security page.
If the QR code for mobile sign-in does not appear on Windows, check these requirements:
- Bluetooth must be enabled on both devices.
- Both devices must be in range and connected to the internet.
- Some organizations block Bluetooth-based cross-device authentication.
If this is a work account and the only prompt available is for the old Authenticator or a passkey that was never created, the organization’s IT admin or helpdesk may need to reset the MFA methods so Authenticator can be set up again on the new iPhone.