Improvements to University MFA (Multi-Factor Authentication) Sign-in
To help keep University IT accounts secure, some users will soon be seeing changes to the way they sign in to access University IT Services.
These changes are part of Microsoft's ongoing investment in protecting accounts against increasingly sophisticated cyber threats, while making sign-in quicker, simpler and more secure.
What's changing?
From September 2026, you may notice new sign-in options offering stronger security than text message (SMS) or phone call verification, which Microsoft plans to phase out from 2027.
Depending on your device and how you access University IT services, you may be encouraged to use methods such as:
- Microsoft Authenticator
- Passkeys
- Windows Hello (where available)
These modern authentication methods are designed to offer stronger security while making it easier to access your account.
Why is this change necessary?
Cyber threats continue to evolve, are becoming more sophisticated, and criminals are increasingly targeting passwords and text message verification methods. Microsoft is moving customers towards stronger methods of verifying their identity, helping to better protect personal information and University data.
What does this mean for me?
- Faster sign-in to University accounts and services
- Better protection against account compromise
- Fewer prompts to verify user identity over time
- A simpler, more consistent sign-in experience across devices
Do I need to do anything?
No action is required at this stage.
However, from September, if you have text message (SMS) or phone call verification registered for Multi-Factor Authentication (MFA), you may start to see prompts encouraging you to set up a more secure sign-in method, such as Microsoft Authenticator, a passkey, or Windows Hello (where available).
These prompts are part of Microsoft's move towards stronger authentication methods and will help University colleagues and students transition away from SMS and phone call verification.
If you receive a prompt, we recommend following the below guidance:
Register passkeys in Authenticator on Android and iOS devices - Microsoft Entra ID | Microsoft Learn.
Any future changes will be communicated clearly, with guidance provided well in advance of any action becoming mandatory.
What support is available?
NUIT will provide:
- Easy-to-follow guidance
- Frequently Asked Questions (FAQs)
- Step-by-step instructions
- Support from the IT Service Desk if you need assistance.
Frequently Asked Questions
Will my password change?
No. Your University password will remain the same.
What is a passkey?
A passkey is a modern way of signing in without needing a text message or remembering additional codes. It uses your devices built-in security features, such as fingerprint, face recognition, or your device PIN. Find out more about Passkeys on Microsoft’s website:
What is a Passkey? Secure Signins | Microsoft Security
What are passkeys and why they matter | Microsoft Support
Is Microsoft Authenticator safe?
Yes. Microsoft Authenticator is a secure and widely recommended method for verifying your identity.
Will SMS codes stop working immediately?
No. We'll communicate any mandatory changes well in advance and support you throughout the transition.
Will I receive help if I need it?
Yes. Guidance and support will be available before any changes take effect. Microsoft provide the following pages to help support this change:
What is a Passkey? Secure Signins | Microsoft Security
What are passkeys and why they matter | Microsoft Support
Register passkeys in Authenticator on Android and iOS devices - Microsoft Entra ID | Microsoft Learn.
Colleagues and students who require additional support can contact the IT Service Desk.
published on: 7 August 2026