Microsoft 365 Multi-Factor Authentication

Update: Retirement of text messages & phone calls

Microsoft is retiring text message (SMS) and phone call verification as MFA methods. As part of CU Boulder's transition plan, those who use SMS or phone verification methods will need to set up and begin using Microsoft Authenticator before their assigned transition date.

Affected faculty, staff and students will be directly emailed and need to make these changes in September 2026. Affected retirees, alumni and former students will go through these changes starting in November 2026.

Learn more about these changes on the MFA Improvement Project webpage (IdentiKey login required). Need assistance? Check out our support resources. 

 

What is multi-factor authentication?

Multi-factor authentication (MFA) increases account security by requiring multiple forms of verification to prove your identity when signing in to an application.

Microsoft MFA is used to validate Microsoft products like Outlook or Teams, as well as other campus applications including Buff Portal, MyCUInfo, Canvas, Google Workspace, Zoom, VPN, and more. Watch our video below for a quick preview of how MFA behaves when logging into multiple services: 

How to enroll and use Microsoft MFA

When you first log in to your campus Microsoft 365 account, you will be prompted to register for multi-factor authentication and set up the Microsoft Authenticator mobile app

  • Set up the Microsoft Authenticator mobile app: This allows you to click a notification on your phone to quickly and easily log in when prompted and is the recommended method for most users.You do not need to grant the app access to your location in order to use it successfully.
  • Find and Update your MFA settings: Follow these instructions to check your Microsoft MFA settings, change your default method, or set up a back-up method to authenticate.
  • Security key: Use a physical device like a YubiKey to verify your identity. YubiKeys are available for purchase from the CU Bookstore and via CDW-G in the Marketplace.

Please note: After your account is enabled for MFA, you may be prompted to re-authenticate to multiple Microsoft 365 servers (e.g., Teams, Outlook).

Additional Authentication Methods

After setting up the Microsoft Authenticator app, you may want to set up a secondary or backup method. Here are the additional approved options for MFA available at CU Boulder: 

  • Passkey: A passkey is a secure way to sign in without using text messages, phone calls, or one-time codes. The passkey is a credential stored on a personal device or in a password manager (like Apple's Face ID, a finger print, or Windows Hello). 
  • Security Key: A security key is a physical device that users can plug into a computer via USB and authenticates without requiring a code (e.g. YubiKey).
  • Hardware token: Similar to security keys, hardware tokens are physical devices that display a temporary One-Time Password (OTP) on a small screen or key fob that users type into the login prompt.

If you want to set up a back up method, follow the Find and Update your Security Info tutorial which shows where to check your MFA methods and add new a one.

Support