Current students Staff Alumni Library

Multi-factor authentication (MFA)

Updated: 2026-08-22 Applies to: All staff and students Action required by 1 February 2027 Staff Students

What is changing

Microsoft is phasing out SMS-based multi-factor authentication. SMS codes are a security risk. They can be intercepted, stolen in SIM-swap attacks, or phished. They also fail when you have no phone signal.

All staff and students need to move to a better method by 1 February 2027. After that date, SMS codes stop working for MFA.

You still sign in with your SCU email and password. MFA is the second check. What changes is how you prove it is really you.

Your options

Method Speed Offline? Needs a phone? Can it be phished?
Passkey (recommended) ~1 second Yes No No
Microsoft Authenticator ~3 seconds No Yes No
TOTP app ~15 seconds Yes No No
Security key ~1 second Yes No No
SMS code 10-30 seconds No Yes Yes

The passkey is fastest and most secure. Microsoft Authenticator and TOTP apps are also solid choices if a passkey does not suit you.

Option 1: a passkey

A passkey uses your fingerprint, face, or device PIN instead of a code. It takes about a second and cannot be phished.

A passkey is a digital key stored on your device. When you sign in, your device confirms it is you locally. Your fingerprint or face data never leaves your device.

You only need one passkey. Add at least two as a backup.

Where How it works
Your laptop or desktop The passkey sits in your device's secure chip. Use Windows Hello, Touch ID, or your PIN.
Your phone or tablet The passkey lives on your phone. When you sign in on a computer, your phone confirms your identity over Bluetooth.
A security key A small USB or NFC key. Plug it in or tap it. Good for shared computers or if you do not have a phone.

Register a passkey

Before you start, have your SCU username, password, and current MFA method (SMS or voice call) ready. If using a phone, turn Bluetooth on and keep the phone nearby.

  1. On your computer, go to mysignins.microsoft.com/security-info
  2. Sign in. Complete MFA if asked.
  3. Click Add sign-in methodPasskeyAdd.
  4. Pick where to store it:
- This device — saves to your computer. Use Windows Hello, Touch ID, or your PIN. - Phone or tablet — scan the QR code with your phone camera. Authenticate with fingerprint, face, or PIN. Your phone will confirm future sign-ins from this computer. - Security key — insert or tap your key. Touch the button or sensor when prompted.
  1. Check Passkey appears on your Security info page. Done.

If you registered on your phone: when you sign in on a computer, your phone will ask you to verify. Keep Bluetooth on for both devices.

Sign in with a passkey

  1. Sign in with email and password as usual.
  2. At the MFA prompt, click Continue or Use passkey.
  3. Authenticate — fingerprint, face, PIN, or security key.
  4. Done.

Option 2: Microsoft Authenticator

Microsoft Authenticator is a free phone app. You tap Approve on a push notification instead of typing a code. You need a smartphone (iPhone or Android) with internet access.

Set it up

  1. Install Microsoft Authenticator on your phone. Do not open it yet.
  2. On your computer, go to mysignins.microsoft.com/security-info and sign in.
  3. Click Add sign-in methodAuthenticator appAdd.
  4. A QR code appears on screen. Leave this page open.
  5. Open Authenticator on your phone. Tap + or Add accountWork or school accountScan QR code. Point your camera at the code.
  6. A test notification lands on your phone. Open it, tap Approve, and type the two-digit number from your screen.
  7. Click Next then Done.

Sign in with Authenticator

  1. Sign in with email and password.
  2. A notification appears on your phone. Open it.
  3. Type the two-digit number shown on your computer screen.
  4. Tap Yes or Approve.

Option 3: a TOTP app

TOTP stands for time-based one-time password. The app shows a six-digit code that changes every 30 seconds. You type this code at sign-in.

It works on phones and desktop computers. You do not need a Microsoft account. It works offline. Common apps: Google Authenticator (free), Authy (free, desktop and phone), Bitwarden (built into the password manager).

Set it up

  1. Install your TOTP app.
  2. On your computer, go to mysignins.microsoft.com/security-info and sign in.
  3. Click Add sign-in methodAuthenticator appAdd.
  4. Below the QR code, click I want to use a different authenticator app. A new code appears. This one works with any TOTP app.
  5. Scan the QR code with your app (Google Authenticator: tap + then Scan a QR code).
  6. The app now shows a six-digit code. On your computer, click Next, type the code, click Done.

Sign in with a TOTP app

  1. Sign in with email and password.
  2. Click Use a verification code.
  3. Open your app. Find the six-digit code for SCU. Type it in.
  4. Click Verify.

Common questions