Set up the Okta Verify app to sign in to services protected by your HMS account using biometrics like Face ID, fingerprint, or PIN. Install on each device you use to access Harvard and HMS services (phone, computer, iPad).
If you already have Okta Verify set up on your devices and need to enable passwordless sign-in, skip to Enable Okta FastPass.
Table of Contents
Set up Okta Verify on your mobile device
We recommend setting up Okta Verify on your mobile device before setting it up on your computer.
Install Okta Verify
If you do not have Okta Verify installed, download and install it:
- Mobile devices:
- iOS and iPadOS: Apple App Store
- Android: Google Play Store
Note – If you encounter a
We could not complete your purchase.error message, you must first update your operating system (OS) to a supported version. After updating your operating system, try downloading and installing Okta Verify again.
Configure Okta Verify on mobile devices
- Open the Okta Verify app.
- Follow the prompts to Get Started.
- When prompted for Ways to verify, select Add account.
- For Account Type, select Organization.
- When prompted to Add Account from Another Device, select Skip.
- When prompted, Do You Have Your QR Code?, select No, Sign In Instead.
Connect your HMS account
- When prompted to Enter Your Organization's Sign-In URL, enter:
- URL (HMS account): login.hms.harvard.edu
- URL (HMS account): login.hms.harvard.edu
- Select Next.
- When prompted with Harvard Medical School Sign In, enter your HMS account ID (typically in the format
ABC123).Note – If you do not know your HMS account ID, you can find it on the HMS IT Service Portal. Select your profile avatar from the menu, then select Profile. Your ID is displayed on your User Profile, in the About section under HMS ID.
- When prompted, enter your HMS account password.
- Select Verify.
- When prompted to Verify with Universal Duo, select Verify.
- Approve the Duo push notification sent to your device.
- When prompted to Enable Face ID or Passcode Confirmation, select Enable.
- When prompted again, select Allow.
- When the app displays Account Added, select Done.
Connect your HarvardKey account
- When prompted to Enter Your Organization's Sign-In URL, enter:
- URL (HarvardKey): login.harvard.edu
- Select Next.
- When prompted with HarvardKey Sign In, enter your HarvardKey account name (typically in the format
firstname_lastname@hms.harvard.edu). - When prompted, enter your HarvardKey account password.
- Select Verify.
- When prompted to Verify with Universal Duo, select Verify.
- Approve the Duo push notification sent to your device.
- When prompted to Enable Face ID or Passcode Confirmation, select Enable.
Enable push notifications
- When prompted to Allow Push Notifications?, select Allow.
- When prompted again about push notifications, select Allow.
Okta Verify is set up on your mobile device. Next, set up Okta Verify on your computer.
Set up Okta Verify on your computer
Follow these instructions to install and configure Okta Verify on your Windows or macOS computer.
Install Okta Verify
All Harvard-managed computers have the Okta Verify application. If you cannot find it or are working on a personal computer, download and install it:
- Windows: Download Okta Verify for Windows and install it.
- macOS: On a Harvard-managed Mac, open the HMS Self Service for Macintosh app. Search for Okta Verify and install it. On a personal device, download Okta Verify for macOS in the App Store and install it.
Note – If you encounter a
We could not complete your purchase.error message, you must first update your operating system (OS) to a supported version. After updating your operating system, try downloading and installing Okta Verify again.
Configure Okta Verify
- Open the Okta Verify app on your computer.
- Follow the prompts to Get Started.
- When prompted for a New account, enter:
- HMS account URL: login.hms.harvard.edu
- HarvardKey URL: login.harvard.edu
- Select Next.
- When the sign-in page opens, enter your HMS account ID or your HarvardKey account ID (typically in the format
ABC123).Note – If you do not know your HMS account ID, you can find it on the HMS IT Service Portal. Select your profile avatar from the menu, then select Profile. Your ID is displayed on your User Profile, in the About section under HMS ID.
- Select Next.
- When prompted to Verify it's you with a security method, select Password. Enter your HarvardKey or HMS account password. Do not select "Okta Verify: Use Okta FastPass" at this step.
- When prompted again to Verify it's you with a security method, select Okta Verify: Get a push notification or Okta Verify: Enter a code. Do not select "Okta Verify: Use Okta FastPass" at this step.
- Approve the push notification on your mobile device using the Okta Verify app.
- When prompted for Windows Hello, Touch ID, or password confirmation, select Enable.
When Okta Verify confirms Account added, your account appears in the Okta Verify app.
Alternative: Add from a mobile device
If you have already set up Okta Verify on your mobile device, you can add your account to your computer from your phone:
Note – Bluetooth must be enabled on both your phone and your computer for this method to work.
- Open Okta Verify on your computer and select Get Started.
- Select Add Account from Another Device.
- On your phone, open Okta Verify and select the organization profile:
- HMS: login.hms.harvard.edu
- HarvardKey: login.harvard.edu
- Select Add Account to Another Device.
- Enter the 8-digit code from your phone into the computer app.
- Enable Touch ID, Windows Hello, or PIN authentication when prompted.
Enable Okta FastPass for passwordless sign-in
Okta FastPass is a feature within the Okta Verify app that replaces the password-and-push-notification step when you sign in. FastPass uses a secure key stored on your device combined with biometrics (Face ID, fingerprint, or Windows Hello) or a PIN to verify your identity. Because authentication is tied to your specific device, it cannot be intercepted or replayed.
FastPass is available for both HMS account and HarvardKey sign-in. Complete the steps below on each computer you use to access Harvard and HMS services.
Before you enable FastPass
Confirm the following on the device where you want passwordless sign-in:
- Okta Verify is installed and up to date.
- Your HMS account (login.hms.harvard.edu) is added in Okta Verify.
- Your HarvardKey account (login.harvard.edu) is added in Okta Verify.
If any of these are missing, complete the mobile device setup and computer setup sections first.
Enable FastPass on your mobile device
- Ensure your mobile device has appropriate features enabled to use FastPass.
- Android: Set up a screen lock.
- iOS: Turn on Lock Screen.
- Open the Okta Verify app.
- Tap your account, which appears as your Harvard email address.
- In the Account Details screen, under Security toggle on:
- Android: Screen lock confirmation or Face ID. If this is already toggled on, no further steps are needed for this account on your mobile device.
- iOS: Face ID or Passcode Confirmation. If this is already toggled on, no further steps are needed for this account on your mobile device.
- Verify your identity when prompted.
- The next time you access HarvardKey-protected resources on this device, select "Okta Verify > Use Okta FastPass" to sign in with your fingerprint, face, or PIN.
- Future sign-in attempts default to the last used method.
Enable FastPass on your computer
If you have not already done so, set up Okta Verify on your computer. FastPass requires a biometric method or device PIN on your computer. Set up one of the following verification methods if you have not already.
Verification methods for Windows
Follow the instructions to configure Windows Hello, ensuring that the PIN, facial recognition, or fingerprint recognition are enabled. Then:
- Open the Okta Verify app.
- Select your HarvardKey or HMS account.
- Select the toggle to turn Windows Hello confirmation on and follow the instructions. If this is already toggled on, no further steps are needed for this account on your Windows computer.
- If you are asked to verify your identity:
- Do not select Okta FastPass. Instead, use your HarvardKey or HMS password, an Okta Verify code, or an Okta Verify push notification.
- If you selected Okta Verify code or Okta Verify push notification, use your mobile device to complete this step.
- Multiple verifications may be required.
- The next time you access HarvardKey-protected resources on this device, select "Okta Verify > Use Okta FastPass" to sign in with your fingerprint, face, or PIN.
- Future sign-in attempts default to the last used method.
- Repeat the steps for the account not selected in step 2.
Verification methods for macOS
Mac users have two options for verification: fingerprint recognition or their computer’s password. If using the computer’s password, no additional setup steps are required. To use fingerprint recognition, configure Touch ID on Mac. Then:
- Open the Okta Verify app.
- Select your HarvardKey or HMS account.
- Find the Face ID or Passcode Confirmation and turn the toggle switch to On. If this is already toggled on, no further steps are needed for this account on your Mac.
- Select Enable in the prompt.
- Verify your identity using the available methods, when prompted.
- Do not select Okta FastPass. Instead, use your HarvardKey or HMS password, an Okta Verify code, or an Okta Verify push notification.
- If you selected Okta Verify code or Okta Verify push notification, use your mobile device to complete this step.
- Multiple verifications may be required.
- The next time you access HarvardKey-protected resources on this device, select "Okta Verify > Use Okta FastPass" to sign in with your fingerprint or password.
- Future sign-in attempts default to the last used method.
- Repeat the steps for the account not selected in step 2.
Verify device readiness
After you enable FastPass for HarvardKey, confirm that your device is ready for passwordless authentication:
- Open the device passwordless readiness check.
- If your device is correctly set up, the message Success! This device is using passwordless! appears.
- If the check does not pass, follow the on-screen prompts to enable biometrics or a PIN.
- Confirm that both login.harvard.edu and login.hms.harvard.edu are added in Okta Verify.
Note – For additional troubleshooting steps, see the device readiness troubleshooting article on the Harvard IT Service Portal.
Sign in with FastPass
After you complete the setup steps above, FastPass handles authentication when you sign in to a service protected by your HMS or HarvardKey account:
- Navigate to the sign-in page for the service you want to access.
- Okta Verify may authenticate you automatically in the background. If it does, you are signed in with no further action.
- If automatic authentication does not occur, select Sign in with Okta FastPass on the sign-in page.
- Confirm your identity with Touch ID, Face ID, Windows Hello, or your PIN when prompted.
Okta FastPass becomes the default sign-in method for your device. You do not need to enter your password.
Set up HarvardKey passkeys for shared computers
- Follow these instructions to turn on Bluetooth on your phone and computer:
- Go to the Okta account settings at login.harvard.edu.
- Sign in with your HarvardKey credentials.
- Select Manage security methods.
- Next to Security Key or Biometric Authenticator, select Set up or Set up another.
- When Okta prompts you, authenticate with the security method you last used.
- On the Set up security methods prompt, select Set up under Security Key or Biometric Authenticator.
- Save the passkey to your phone.