What is changing?
Beginning February 1, 2027, Microsoft-provided SMS text messages and voice calls will no longer be available as multifactor authentication methods for most Microsoft 365 users. If you currently receive a text message or automated phone call when signing in, you must set up another authentication method before this date.
Microsoft is making this change because SMS and voice authentication provide weaker protection against phishing and account compromise than phishing-resistant authentication methods.
This change affects Microsoft 365 and other services where you sign in using:
- Employees:
StarID@minnstate.edu
- Students:
StarID@go.minnstate.edu
Important: Do not wait until February 1, 2027. Set up and test another authentication method now to avoid a disruption when signing in.
What do I need to do?
Set up at least one supported authentication method before February 1, 2027.
The recommended options include:
- Microsoft Authenticator
- A passkey
- Windows Hello, when available on your device
- A physical security key or fob, when arranged through ITS
We recommend configuring more than one method whenever possible. Having a second method can help you access your account if your preferred device is lost, replaced, or unavailable.
If you cannot use a smartphone, contact ITS. Alternative options, including a security fob, may be available based on your situation.
Before you begin
You will need:
- A computer with an internet connection
- Your smartphone or tablet
- Your StarID and StarID password
- The Microsoft Authenticator app installed on your mobile device
Download Microsoft Authenticator from your device’s official app store:
Security reminder: Install only the official app, Microsoft Authenticator, published by Microsoft Corporation.
Set up Microsoft Authenticator
1. Open your security information
On a computer, open the following Microsoft page:
https://minnstate.edu/mfa
Sign in using your Minnesota State Microsoft 365 username:
- Employees:
StarID@minnstate.edu
- Students:
StarID@go.minnstate.edu
Complete your current MFA verification if prompted.
2. Add a sign-in method
On the Security info page:
- Select + Add sign-in method.
- Choose Authenticator app.
- Select Add.

3. Install or open Microsoft Authenticator
If Microsoft Authenticator is not already installed, install it from your device’s app store.
On your computer:
- Select Next.
- Leave the Set up your account window open.

4. Add your work or school account
On your mobile device:
- Open Microsoft Authenticator.
- Allow notifications if prompted.
- Select + or Add account.
- Select Work or school account.
- Select Scan a QR code.
- Allow camera access if prompted.


5. Scan the QR code
Return to your computer and select Next to display the QR code.
Use Microsoft Authenticator on your mobile device to scan the QR code displayed on your computer.
Do not scan the QR code with your regular camera app. Scan it from within Microsoft Authenticator.
If you can't scan the QR code, select Can’t scan the QR image? and follow the on-screen instructions to enter the information manually.

6. Approve the test notification
After scanning the QR code:
- Select Next on the computer.
- Microsoft will send a test notification to your mobile device.
- Open Microsoft Authenticator.
- Enter the number shown on the computer, if prompted.
- Select Approve.
- Return to the computer and select Done.
The Microsoft security information page should now list Microsoft Authenticator as a sign-in method. Microsoft’s documented setup process uses a test notification to confirm that the app was added successfully.

Test Microsoft Authenticator
After setup, test the method before you need it:
- Open a private or InPrivate browser window.
- Sign in to Microsoft 365.
- Enter your Minnesota State Microsoft 365 username and StarID password.
- When prompted, choose the Microsoft Authenticator option.
- Open Microsoft Authenticator and approve the request.
Microsoft will display a number on the sign-in screen. Enter that number in Microsoft Authenticator and then select Approve.
Never approve an unexpected request. If you receive an authentication request when you are not signing in, deny the request and contact ITS.
What happens if I do not make the change?
After February 1, 2027, users will no longer be able to use Microsoft-provided SMS text messages or voice calls to complete MFA.
If SMS or voice is your only available authentication method, Microsoft says you'll need to register a passkey during sign-in before you can continue accessing your account. This registration prompt will be blocking.
Setting up a supported method now will help prevent interruptions when accessing email, Microsoft 365, Teams, OneDrive, D2L Brightspace, and other services that use your Minnesota State Microsoft 365 account.
Frequently asked questions
Can I continue using SMS text messages or voice calls until February 1, 2027?
Microsoft-provided SMS and voice authentication remain available during the transition period. However, users should establish and test another method before February 1, 2027.
Will Microsoft Authenticator read information on my phone?
Installing Microsoft Authenticator does not give Microsoft, Minnesota State, or the institution control of the device or its data.
Does Microsoft Authenticator require cellular service?
Authenticator-generated verification codes do not require internet access or cellular service. However, the device must have an internet connection to receive and approve sign-in notifications.
What if I replace or lose my phone?
If possible, set up your new phone while you still have access to your old phone. This is the easiest option because you can use your existing authentication method to sign in and add the new device to your account.
Adding Microsoft Authenticator to a new device does not automatically remove it from your old device. After you successfully enroll your new phone and confirm it works, remove Microsoft Authenticator from the old device and unregister the old device from your work or school account.
If you no longer have access to your old phone, cannot approve authentication requests, or can't sign in, contact ITS for help. To protect your account, ITS must verify your identity before resetting your multifactor authentication methods. Verification may be completed:
- In person with a photo ID, or
- Through a Zoom meeting with your camera enabled and photo ID.
Once ITS verifies your identity, it can reset your MFA registration so you can enroll Microsoft Authenticator or another approved authentication method on your new device.
Tip: Whenever possible, keep your old phone until you have successfully set up and tested Microsoft Authenticator on your new device. This can help you avoid delays and the need for an MFA reset.
What if I do not have a smartphone?
Contact ITS as soon as possible to explore alternative authentication methods before SMS and voice are no longer available on February 1, 2027.
Should I remove my phone number from Security info?
Do not remove an existing method until you have successfully registered and tested the replacement method.
Get help
If you need help setting up Microsoft Authenticator, do not have access to a smartphone, or cannot access your account:
When requesting help, please do not send your password, a verification code, or a screenshot containing a live QR code.