What is happening
Microsoft is turning off SMS-based multi-factor authentication. SMS codes are no longer secure enough. They can be intercepted, stolen in SIM-swap attacks, or phished. They also fail when you have no phone signal.
Everyone at SCU needs to switch to a better method by 1 February 2027. After that date, SMS codes stop working.
What you need to do
Pick a new method and set it up. It takes about five minutes.
The recommended method is a passkey. It uses your fingerprint, face, or device PIN instead of a code. It is faster than SMS and cannot be phished.
Your other choices:
- Microsoft Authenticator — a free app. Tap Approve on a push notification.
- TOTP app — Google Authenticator or similar. Shows a six-digit code. Works on desktop computers.
- Security key — a small USB or NFC key. Plug it in and tap.
Where to start
Read the MFA guideThis one guide covers everything: what is changing, the options compared, and step-by-step instructions for passkeys, Microsoft Authenticator, and TOTP apps.
Questions
If you are stuck, contact Technology Services. Do not wait until February.
servicedesk@scu.edu.au