Secure your accounts with two-factor authentication and passwordless sign-in

Okta Verify is the app HMS and Harvard University use to confirm who you are when you sign in. One app holds both your HMS account and your HarvardKey, and you enroll each one separately. With Okta FastPass, you can sign in with your fingerprint, face, or a PIN instead of typing a password.

Set up Okta Verify

Eligibility

Anyone with an HMS account or a HarvardKey
HMS account HarvardKey

Most people at HMS have both an HMS account and a HarvardKey, and Okta Verify covers each of them. Some groups must use passwordless sign-in with FastPass, a feature within Okta Verify, rather than a password.

Security

Adds a second step, and can replace your password entirely
2FA FastPass

Two-factor authentication asks for your password plus a second confirmation, so your account stays protected even if someone learns it. Okta FastPass goes further and replaces the password: your device confirms your identity with Touch ID, Face ID, Windows Hello, or a device PIN. Because that confirmation is tied to the device in your hand, it cannot be reused elsewhere.

Your HMS account

Signs you in to HMS email, VPN, file shares, and research systems
Setup Devices

You sign in with your HMS account at login.hms.harvard.edu. Follow Set up Okta Verify for your HMS and HarvardKey account to enroll it.

To manage your enrolled devices or change how you confirm your identity, open your My Apps dashboard. Sign in there with your HMS account ID, a short code in the form abc123. You can find it on your profile page in the HMS Service Portal.

Your HarvardKey

A separate credential, enrolled on its own
Setup HUIT

You sign in with your HarvardKey at login.harvard.edu. It is separate from your HMS account, and enrolling one does not enroll the other, so set up both.

Harvard University Information Technology (HUIT) owns HarvardKey, writes its instructions, and supports it. Follow Set up Okta identity verification for new HarvardKey users to enroll it, and contact the HUIT Service Desk at 617-496-9001 for help with HarvardKey itself.

Add another device

Enroll every device you use for HMS or Harvard work
Transfer Support

Set up Okta Verify on each computer, phone, and tablet you use. On a device that does not hold your account, you cannot sign in.

If an account is already in Okta Verify on one device, you can move it to another yourself: Turn on Bluetooth on both devices, then follow Set up Okta Verify on an additional device. Okta has renamed the two buttons the transfer uses. Select Export Account on the device that already holds the account, then Import Account on the device you are adding. 

If no device holds the account, you cannot complete this setup yourself. Contact the HMS IT Service Desk at 617-432-2000 or itservicedesk@hms.harvard.edu for help.

Confirm your setup

Check that both accounts are enrolled
Devices Check

Open Okta Verify and look for two accounts: one for login.hms.harvard.edu and one for login.harvard.edu. If either is missing, enroll it.

To confirm passwordless sign-in is working on a device, follow Check whether passwordless sign-in is set up on your device.

Set up Okta Verify

Enroll both accounts, step by step, on a phone and on a computer.

HUIT’s guide for a first HarvardKey enrollment.

Move an account to another computer, phone, or tablet.

Confirm and troubleshoot

Confirm passwordless sign-in is enabled, one device at a time.

Fix a sign-in prompt that reappears each time you dismiss it.

HUIT’s recovery steps when HarvardKey will not verify.