Sign In Without a Password (Passkeys & Secure Connect)

 

Who this is for / when to use it

Use this if you want to sign in using your Cornell credentials without typing your password every time — with your fingerprint, face, or a device PIN instead. Cornell calls this “Secure Connect”, and it works by putting a passkey on your device. It's available to active faculty and staff (students aren't eligible yet).

This applies whether you're on your JCB-managed computer or a personal device. It's a good option if you're tired of password prompts and want a faster, more secure sign-in.

What passwordless sign-in gets you

  • One-touch login to most Cornell websites — a fingerprint, face scan, or device PIN instead of your NetID password.
  • Stronger security: a passkey can't be phished or reused the way a typed password can.
  • It works with the Beyond Identity app, which is the passkey tool you'll see prompts from once it's set up.

Good to know before you start:

  • Each device you want to use needs its own passkey — setting it up on your laptop doesn't cover your phone.
  • You'll sign in with biometrics (Touch ID or Windows Hello) where available, or your device password or PIN if it isn't.
  • Not everything is passwordless yet. Most Cornell web logins work with your passkey, but VPN and Microsoft/Office Online sign-ins still ask for your password and Duo. That's expected.

How to set it up

Cornell's “Secure Connect” pages walk you through enrollment for your specific device. Start here:

  • Secure Connect at IT@Cornell — the starting point. Sign in with your NetID to see the step-by-step instructions for a Cornell-managed device or a personal device, and to add or move a passkey between devices.

Whether it's a managed or personal device, the process is the same: confirm your device can do biometrics, sign in to enroll a passkey, then choose “Always Sign In with Passkey” the first time your browser offers it. If you need to set up the fingerprint or face reader first, see Set Up Biometrics on Your Device.

On your JCB-managed computer: if you hit a permissions wall or the biometric reader isn't available during setup, contact JCB IT for assistance.

Common problems

  • It keeps asking for my computer password instead of my fingerprint. This means the device can't reach a usable biometric reader — common when a laptop runs docked/lid-closed with an external keyboard that has no fingerprint reader, or on a device with no Touch ID / Windows Hello hardware or no enrolled fingerprint. Using the device password is a valid fallback; to use biometrics, enroll a fingerprint/face or use the built-in laptop keyboard.
  • My passkey doesn't work in this browser. Passkeys are tied to the browser (and browser profile) you set them up in. Switch to the profile you enrolled with, and on a new browser check “Always Sign In with Passkey” the first time. If needed, open the browser in a private/incognito window to fall back to NetID + password + Duo.
  • I'm a student and can't set it up. Secure Connect passkeys are currently faculty/staff only.
  • VPN or Office Online still wants my password. That's expected — those still use password + Duo, not your passkey.

If that didn't work

Cornell's Secure Connect Help page covers the less common error messages (“biometrics prompt canceled,” “timed out,” “authentication error,” and others) with step-by-step fixes.

Still stuck?

If passwordless sign-in still isn't working on your JCB machine, contact JCB IT and we'll help. You can also browse Cornell's full guidance at it.cornell.edu/secure-connect.

Still need help? Contact the Cornell SC Johnson College of Business Helpdesk at itrequests@business.cornell.edu.

[edited via Jane by rtm25 on 2026-09-09 17:10 UTC]

Was this helpful?
0 reviews