What is changing
Microsoft is phasing out SMS-based multi-factor authentication. SMS codes are a security risk. They can be intercepted, stolen in SIM-swap attacks, or phished. They also fail when you have no phone signal.
All staff and students need to move to a better method by 1 February 2027. After that date, SMS codes stop working for MFA.
You still sign in with your SCU email and password. MFA is the second check. What changes is how you prove it is really you.
Your options
| Method | Speed | Offline? | Needs a phone? | Can it be phished? |
|---|---|---|---|---|
| Passkey (recommended) | ~1 second | Yes | No | No |
| Microsoft Authenticator | ~3 seconds | No | Yes | No |
| TOTP app | ~15 seconds | Yes | No | No |
| Security key | ~1 second | Yes | No | No |
| SMS code | 10-30 seconds | No | Yes | Yes |
The passkey is fastest and most secure. Microsoft Authenticator and TOTP apps are also solid choices if a passkey does not suit you.
Option 1: a passkey
A passkey uses your fingerprint, face, or device PIN instead of a code. It takes about a second and cannot be phished.
A passkey is a digital key stored on your device. When you sign in, your device confirms it is you locally. Your fingerprint or face data never leaves your device.
You only need one passkey. Add at least two as a backup.
| Where | How it works |
|---|---|
| Your laptop or desktop | The passkey sits in your device's secure chip. Use Windows Hello, Touch ID, or your PIN. |
| Your phone or tablet | The passkey lives on your phone. When you sign in on a computer, your phone confirms your identity over Bluetooth. |
| A security key | A small USB or NFC key. Plug it in or tap it. Good for shared computers or if you do not have a phone. |
Register a passkey
Before you start, have your SCU username, password, and current MFA method (SMS or voice call) ready. If using a phone, turn Bluetooth on and keep the phone nearby.
- On your computer, go to mysignins.microsoft.com/security-info
- Sign in. Complete MFA if asked.
- Click Add sign-in method → Passkey → Add.
- Pick where to store it:
- Check Passkey appears on your Security info page. Done.
If you registered on your phone: when you sign in on a computer, your phone will ask you to verify. Keep Bluetooth on for both devices.
Sign in with a passkey
- Sign in with email and password as usual.
- At the MFA prompt, click Continue or Use passkey.
- Authenticate — fingerprint, face, PIN, or security key.
- Done.
Option 2: Microsoft Authenticator
Microsoft Authenticator is a free phone app. You tap Approve on a push notification instead of typing a code. You need a smartphone (iPhone or Android) with internet access.
Set it up
- Install Microsoft Authenticator on your phone. Do not open it yet.
- On your computer, go to mysignins.microsoft.com/security-info and sign in.
- Click Add sign-in method → Authenticator app → Add.
- A QR code appears on screen. Leave this page open.
- Open Authenticator on your phone. Tap + or Add account → Work or school account → Scan QR code. Point your camera at the code.
- A test notification lands on your phone. Open it, tap Approve, and type the two-digit number from your screen.
- Click Next then Done.
Sign in with Authenticator
- Sign in with email and password.
- A notification appears on your phone. Open it.
- Type the two-digit number shown on your computer screen.
- Tap Yes or Approve.
Option 3: a TOTP app
TOTP stands for time-based one-time password. The app shows a six-digit code that changes every 30 seconds. You type this code at sign-in.
It works on phones and desktop computers. You do not need a Microsoft account. It works offline. Common apps: Google Authenticator (free), Authy (free, desktop and phone), Bitwarden (built into the password manager).
Set it up
- Install your TOTP app.
- On your computer, go to mysignins.microsoft.com/security-info and sign in.
- Click Add sign-in method → Authenticator app → Add.
- Below the QR code, click I want to use a different authenticator app. A new code appears. This one works with any TOTP app.
- Scan the QR code with your app (Google Authenticator: tap + then Scan a QR code).
- The app now shows a six-digit code. On your computer, click Next, type the code, click Done.
Sign in with a TOTP app
- Sign in with email and password.
- Click Use a verification code.
- Open your app. Find the six-digit code for SCU. Type it in.
- Click Verify.