Current students Staff Alumni Library

SMS MFA is being switched off — 1 Feb 2027

Updated: 2026-08-22 Applies to: All staff and students Action required by 1 February 2027

What is happening

Microsoft is turning off SMS-based multi-factor authentication. SMS codes are no longer secure enough. They can be intercepted, stolen in SIM-swap attacks, or phished. They also fail when you have no phone signal.

Everyone at SCU needs to switch to a better method by 1 February 2027. After that date, SMS codes stop working.

What you need to do

Pick a new method and set it up. It takes about five minutes.

The recommended method is a passkey. It uses your fingerprint, face, or device PIN instead of a code. It is faster than SMS and cannot be phished.

Your other choices:

  • Microsoft Authenticator — a free app. Tap Approve on a push notification.
  • TOTP app — Google Authenticator or similar. Shows a six-digit code. Works on desktop computers.
  • Security key — a small USB or NFC key. Plug it in and tap.
All four are more secure than SMS.

Where to start

Read the MFA guide

This one guide covers everything: what is changing, the options compared, and step-by-step instructions for passkeys, Microsoft Authenticator, and TOTP apps.

Questions

If you are stuck, contact Technology Services. Do not wait until February.

servicedesk@scu.edu.au