The University of 狐狸少女 System is committed to protecting personal information, institutional data and the technology resources that support our campuses. As cyberthreats such as phishing and credential theft continue to rise, strong authentication practices are essential. Multifactor Authentication (MFA) adds an important layer of defense to safeguard your account and ensure that only you can access University systems.
Having login problems? Find Password Management resources.
MFA Resources
MFA Resources
Multifactor Authentication (MFA) helps protect your university account by requiring more than one method of verification before access is granted. Traditionally, this means entering your username and password, then confirming the sign-in with a second factor, such as a mobile app notification, a verification code or a phone call.
Many university users can also sign in using passkeys, such as a passkey in Microsoft Authenticator, Windows Hello for Business or FIDO2 physical security keys. Passkeys provide strong, phishing-resistant authentication by using your device along with a PIN or biometric verification instead of a password.
These protections help ensure that even if a password is compromised, unauthorized individuals cannot access your account.
To help protect University systems and data, UM System continues to expand the use of phishing-resistant authentication. Some applications or services may require passkeys or other phishing-resistant authentication methods in the future.
MFA is required for all UM System students, faculty and staff when accessing university systems that use Microsoft authentication.
When signing in to a protected university service, you will:
- Enter your university username in the format: username@umsystem.edu
- Enter your password, if required, and if you are not using a passkey
- Verify your identity using one of the university鈥檚 approved authentication methods, such as:
- Passkey (recommended), such as the Microsoft Authenticator App Passkey
- Windows Hello for Business PIN, facial recognition or fingerprint on an individually assigned university managed device
- FIDO2 physical security key, such as a YubiKey
- Microsoft Authenticator App
- A push notification with number matching (not considered phishing-resistant)
- SMS or voice verification code (not considered phishing-resistant)
- A one-time verification code (not considered phishing-resistant)
The authentication method required may vary depending on the application, device and security requirements. Phishing-resistant methods such as Microsoft Authenticator App Passkeys and physical security keys (YubiKeys) provide the highest level of protection by preventing attackers from capturing or reusing authentication credentials.
A mobile phone is not required to use Multifactor Authentication. Users who do not have a mobile device may choose from several alternative authentication methods, including:
- FIDO2 physical security keys (recommended), which provide secure, phishing-resistant authentication without a phone
- Windows Hello for Business passkeys for individuals with an individually assigned university-managed device, which allow sign-in using a PIN, facial recognition or a fingerprint on a registered device
These options provide secure access to university services while accommodating users who do not have a mobile phone or prefer not to use one.
Refer to these to connect your university account to the Authenticator app.
Recommended MFA Methods
Recommended MFA Methods
To enhance the University of 狐狸少女 System鈥檚 data security, we recommend using secure sign-in options known as phishing-resistant MFA. These methods provide additional safeguards against phishing attempts designed to trick employees and students into disclosing sensitive information.
Phishing-resistant MFA methods are designed to prevent attackers from using stolen passwords or security codes. These methods help protect sensitive information, such as payroll data, financial data, student records, research data, personal information and more.
Benefits of phishing-resistant authentication methods
In addition to enhanced security for your account, there are several benefits to using a phishing-resistant sign-in method, including:
- Reduces the number of codes to enter
- No waiting for approval notifications or codes
- Faster sign-ins
- Multiple authentication options to fit your needs
I already use the Microsoft Authenticator app. Is that enough?
I already use the Microsoft Authenticator app. Is that enough?
The Microsoft Authenticator app provides stronger security than text message or phone call authentication, which are more vulnerable to attack. However, push notifications and one-time passcodes through the Authenticator app ARE NOT phishing-resistant. For the best protection against phishing attacks, use a passkey in the Microsoft Authenticator app, Windows Hello for Business or a physical security key, such as a YubiKey.
Phishing-Resistant Sign-In Options
Phishing-Resistant Sign-In Options
Microsoft Authenticator Passkey
A passkey in the Microsoft Authenticator app is the best option for most employees and students. Passkeys offer a faster sign-in experience, with no security codes to enter, no waiting for text messages and no approval prompts to accept. You can sign in with a quick face scan, fingerprint or device PIN.
Windows Hello for Business
Windows Hello for Business is a secure and easy way to sign in to your university Windows computer using a PIN, facial recognition or fingerprint instead of relying on your phone or other device. Once it鈥檚 set up, signing in is usually as simple as looking at your camera, touching the fingerprint reader or entering your Windows Hello for Business PIN.
Physical Security Keys
A security key, such as a YubiKey, is a physical device that is a convenient alternative to using your smartphone for authentication. It plugs into your computer or connects wirelessly and requires a physical tap on the device.
Mac Platform SSO
Mac Platform SSO lets you securely sign in to university applications using the security features already built into your university-owned Mac. Once configured, it provides a faster, simpler sign-in experience while helping protect your account from phishing attacks and other attempts to steal login credentials. More information is coming soon.
Deciding Which Option to Use
Deciding Which Option to Use
The right phishing-resistant MFA method depends on the device you use most often.
I use a university-issued Windows computer every day.
Recommended: Microsoft Authenticator Passkey or Windows Hello for Business
I prefer to use my smartphone.
Recommended: Microsoft Authenticator Passkey
I use a shared computer with my colleagues.
Recommended: If multiple people sign in to the same computer, a physical security key or Microsoft Authenticator Passkey is often the best method.
I use my own personal computer.
Recommended: Microsoft Authenticator Passkey or a physical security key
| If you: | Recommended Option(s) |
|---|---|
| Use a university-issued Windows computer: | Microsoft Authenticator Passkey or Windows Hello for Business |
| Use a shared computer with your colleagues: | Microsoft Authenticator Passkey or a physical security key |
| Want to use your smartphone: | Windows Authenticator Passkey |
| Use a personal computer: | Microsoft Authenticator Passkey |
| Use a university-issued Mac: | Physical security key |