What Is Multi-Factor Authentication (MFA)?

Tags MFA M365

Multi-Factor Authentication (MFA) adds a second step when you sign in. Bemidji State University and Northwest Technical College require MFA for Microsoft 365 accounts because it helps protect your information and campus systems if someone steals your password through phishing or another unauthorized attempt.

MFA checks your identity in at least two different ways. For example, you might enter your password and then approve the sign-in in an authenticator app. These checks come from different categories: something you know, something you have, or something you are.

  • Something you know: your password or PIN
  • Something you have: a registered device, authenticator app, passkey, or physical security token
  • Something you are: a biometric check such as a fingerprint or facial recognition

After setup, the verification step depends on the method you choose. You may approve a notification in an authenticator app, enter a time-based code, or use a passkey or passwordless sign-in.

You may be asked to complete the additional verification step when you sign in to Microsoft 365.

Why Use Multi-Factor Authentication?

Passwords can be guessed, stolen, or exposed in a phishing attempt. MFA adds another check, making it harder for someone else to access sensitive information in your email, files, financial accounts, or health records.

Many organizations now require MFA as a standard security measure to access systems and services.

Can't Use Your MFA Method?

If you replaced or reset your device, reinstalled your authenticator app, or can no longer use a registered authentication method, contact ITS. You may need to reset you before you can sign in again.

Because MFA protects access to your account, ITS must verify your identity and perform the reset when you no longer have access to a registered authentication method.

Microsoft 365 Applications That Require MFA

MFA is required when you sign in to Microsoft 365 services such as:

  • Outlook
  • OneDrive
  • Power Automate (formerly Flow)
  • Teams
  • Word
  • OneNote

Choose an MFA Method

Choose the method that works with your device and sign-in needs. When possible, register more than one supported method so you have a backup if your primary device is unavailable.

For most students, Microsoft Authenticator is the easiest option. Choose the Android or iPhone instructions below if you have a mobile device. Students enrolled at BSU or NTC who use a school district-managed Chromebook may be able to use Google Authenticator. Passkey and passwordless options are also available for supported devices.

Microsoft Authenticator App

 For the initial Microsoft Authenticator setup, use a computer to display the QR code. Scan the code with the Microsoft Authenticator app on your mobile device.

Passkey and Passwordless Sign-In

Google Authenticator for School District-Managed Chromebooks

Students enrolled at BSU or NTC who use a school-managed Chromebook may use Google Authenticator to generate verification codes. The school district can install the app on its managed devices.

  • Generates secure, time-based verification codes
  • Works without network access after setup when an offline code is needed
  • Meets Minnesota State authentication requirements
  • Provides a simple interface for students
  • Get Google Authenticator from Google Play

Installation and setup instructions for students using school district-managed Chromebooks will be available in a separate KB article. If the methods above do not work for you, contact ITS to ask about an approved alternative, such as a physical token or fob.

 

Need Help Setting Up MFA?

Select the setup instructions for your device or authentication method above. Follow those steps when Microsoft asks you to provide additional security information. If you cannot finish setup or none of the listed methods work for you, please submit a service request for assistance.