Skip to content
Current/ Help Center

Authenticator apps and passkeys

5 min read · Updated Sep 11, 2026

The emailed code is the second factor everyone starts with. An authenticator app or a passkey replaces it: nothing to wait for in your inbox, nothing to retype, and no dependency on mail being delivered. Both live under Settings → Sign-in security, both are yours alone, and an admin can reset them but can never see them.

Set up an authenticator app

Any TOTP app works: Microsoft Authenticator, Google Authenticator, 1Password, Bitwarden, Authy. If your company already standardises on one, use that one.

  1. 1
    Open Settings → Sign-in security
    It lists the factors on your account and says so if your workspace requires an app or a passkey.
  2. 2
    Choose Add authenticator app
    Current shows a QR code, and the same secret as text for a desktop password manager that can't scan a screen.
  3. 3
    Scan it, then type the 6 digits
    Your app starts generating a code every 30 seconds. Enter the current one to finish. The factor isn't active until that code verifies, so a setup you abandon half-way leaves you exactly where you were. It is listed as Authenticator app; a second one becomes Authenticator app 2.

Set up a passkey

A passkey is a key your device holds and unlocks with Face ID, Touch ID, Windows Hello, or a hardware security key. There is nothing to type and nothing that can be read off your screen and reused.

  1. 1
    Choose Add passkey
    Same page: Settings → Sign-in security.
  2. 2
    Confirm with your device
    Your browser asks for the fingerprint, face, PIN or key you already use. Where the passkey is saved — the device itself, iCloud Keychain, a password manager, a USB key — is your browser's question, not Current's.
  3. 3
    Add a second factor as well
    A passkey on one laptop is a passkey you lose with the laptop. Add your phone too, or keep an authenticator app beside it, so a single dead device isn't a call to your admin.
Note
Passkeys depend on a platform switch
Passkeys ride on a browser standard that has to be switched on for Current's platform, not just for your workspace. If the page says passkeys aren't available yet, that switch isn't on and there is nothing you can do in your workspace to change it. Use an authenticator app in the meantime; for this purpose it does the same job.

Signing in once you have one

From then on Current stops offering you the emailed code. You sign in with your password, then your app or your passkey, and the browser is trusted afterwards in exactly the same way and for exactly the same window. The code path is closed for you rather than hidden: a code requested some other way is refused.

Removing a factor

Settings → Sign-in security, then Remove on the factor. Current asks you to use that factor first — a code from the app you're removing, a touch of the passkey — so somebody sitting at your unlocked laptop can't quietly strip it. Remove your last app or passkey and you go back to the emailed code. If your workspace requires an app, Current refuses to remove your last one until you have added another.

Lost the phone, lost the key

  1. 1
    Ask a workspace admin for a reset
    Workspace → Users & roles, the ⋯ menu on your row, Reset second factor. It clears the factors on your account and un-trusts every browser you had, so you start the second step over; it never reveals a factor and never moves one to another device.
  2. 2
    Sign in again
    On the default setting you're back to the emailed code and there is nothing else to do. If your workspace requires an authenticator app or a passkey, your next sign-in asks you to enrol a new one before you reach the workspace.
  3. 3
    No admin available
    ITPartners+ support can run the same reset. Use the contact form in the Help Center; we confirm who you are with your workspace before anything changes.

What your workspace can require

A Tenant Admin can raise the floor from Email code to "Authenticator app or passkey" in the Sign-in panel at Workspace → Users & roles, with the Require an app or passkey button. The same panel's roster shows who has an app or a passkey already and who is still on the emailed code. It is a one-way change: a workspace that requires an app can't go back to email codes. After it, anyone without a factor is asked to enrol at their next sign-in. The same panel shortens how long a browser stays trusted, from 30 days to 14 or 7.

Tip
Admins: single sign-on beats enrolling everybody
If your company already runs Entra ID, Okta or Google Workspace, registering it is a better answer than asking every person to enrol an app: MFA and conditional access come from the provider you already manage, and offboarding stays in one place. See "Set up single sign-on (Microsoft Entra ID, Okta, Google Workspace)".
Was this helpful?