Image
Smartphone and laptop

Retirement of text message and phone call verification for access to campus services

Submitted by stauffeg
on

Faculty, staff, students, retirees, alumni and former students who currently use text messages or phone calls to verify their identity when signing in to university services will need to transition to a different authentication method over the coming months.

As part of an upcoming change from Microsoft, CU Boulder is retiring SMS text message and phone call verification for multi-factor authentication (MFA). Microsoft is retiring these methods as they are more susceptible to phishing, social engineering and SIM-swapping attacks than modern authentication methods. More applications and services are also beginning to require stronger forms of authentication.

To help ensure a smooth transition, OIT will conduct two phased campaigns targeting users who currently rely on text message and phone call authentication.

Action recommended now

If you currently use text messages or phone calls to verify your identity when signing in to university services, OIT encourages you to update your authentication methods now.

Find out how to check and update your Microsoft MFA security info and make sure you are using the Microsoft Authenticator app as your default sign-in method

Taking action now can help you avoid interruptions when signing in to university services later this fall.

Campaign 1: Faculty, staff and students

The first campaign will focus on active faculty, staff and students.

  • Campaign begins: Sept. 21
  • Campaign ends: Nov. 20
  • Affected users: Active faculty, staff and students who currently use SMS text messages or phone calls as part of their MFA configuration

Users in this group who need to take action will receive direct email communications from OIT explaining:

  • Why they are receiving the message
  • What action they need to take
  • The deadline to complete the change
  • Where to find instructions and support resources

Some users may also receive reminders during the sign-in process encouraging them to update their authentication methods.

Campaign 2: Retirees, alumni and former students

The second campaign will focus on users who are less directly tied to the academic calendar.

  • Campaign begins: November 2026
  • Campaign ends: January 2027
  • Affected users: Retirees, alumni and former students who currently use SMS text messages or phone calls as part of their MFA configuration

Like Campaign 1, impacted users will receive direct email communications with instructions and an individual deadline for completing the transition.

Why is OIT recommending Microsoft Authenticator?

While several authentication methods are available, including security keys and passkeys, OIT is recommending Microsoft Authenticator for most faculty, staff and students because it provides a consistent, reliable and easy-to-use authentication experience across the broad range of devices and services used by the campus community.

Other approved authentication methods will continue to be available where appropriate.

What happens if I do nothing?

Users who do not update their authentication methods before their assigned deadline will eventually lose the ability to verify their identity using text messages or phone calls and be blocked from accessing campus services until they update.

Affected users will receive direct communications in advance of any deadline and will be provided with instructions for completing the transition.

Learn more

For step-by-step instructions on viewing and updating your authentication methods, visit:

Find and update your Microsoft MFA security information

If you need assistance, contact the IT Service Center at oithelp@colorado.edu or 303-735-4357.