What is changing?
Microsoft is retiring SMS (text message) and voice call verification as authentication methods for Microsoft 365 accounts. As a result, anyone who currently uses text messages or phone calls to complete Multi-Factor Authentication (MFA) will need to enroll in another approved authentication method. Microsoft is encouraging users to move to phishing-resistant methods such as Microsoft Authenticator and passkeys.
Why is this change happening?
Text messages and phone calls are no longer considered secure MFA methods. Microsoft is forcing more secure methods to better protect user accounts and personal information.
When will this change take place?
Concordia Nebraska will be disabling phone number verification over Winter Break.
What is Multi-Factor Authentication (MFA)?
MFA adds an extra layer of security to your account. After entering your password, you must verify your identity using a second method, such as:
- Microsoft Authenticator
- A passkey
- A security key
- An authentication code generated by an authenticator app
This helps protect your account even if your password is compromised.
What should I do now?
If you currently use text messages or phone calls to verify your identity:
- Visit https://aka.ms/mfasetup to add an authentication method.
- Install and set up Microsoft Authenticator or configure a passkey.
- Set your default authentication method to something other than a phone number.
What is Microsoft Authenticator?
Microsoft Authenticator is a free mobile app that allows you to securely approve sign-in requests and generate verification codes without relying on text messages. It is the recommended and preferred MFA method.
What is a passkey?
A passkey is a secure sign-in credential that uses your device's built-in security, such as:
- Fingerprint recognition
- Face recognition
- Device PIN
Passkeys are considered phishing-resistant. You can read more about passkeys in Microsoft's support article.
Will I lose access to my account immediately?
No. You may begin seeing prompts from Microsoft encouraging registration of a new authentication method, but these prompts are intended to help you prepare before SMS authentication is retired.
What if I already use Microsoft Authenticator?
No action is required if you already use Microsoft Authenticator, a passkey, or another supported authentication method for MFA.
What if I do not have a smartphone?
Alternative authentication options are available for anyone who does not have access to a smartphone. Contact the Helpdesk to discuss available accommodations and authentication methods.
How can I check which MFA methods I have registered?
Visit your Microsoft security information page and review your registered authentication methods. If text message or phone call is your only method, you should add Microsoft Authenticator or another approved option as soon as possible.
Are there articles where I can get more information?
Here are some articles to help you set up multifactor authentication methods.
Here are some additional informational articles from Microsoft about securing your account.
Where can I get help?
If you have questions or need assistance setting up Microsoft Authenticator, please contact the Helpdesk.
- Email: helpdesk@cune.edu
- Phone: 402-643-7100
- Website: helpdesk.cune.edu
- Visit Dunklau 056