Multi-Factor Authentication

Frequently Asked Questions

What is multi-factor authentication?

Click below to watch a short (3 minute) video about Multi-Factor Authentication.

Multi-Factor Authentication, sometimes referred to as Two-Step Login, Two-Factor Authentication, or 2FA, is a security enhancement that requires you to present two (or more) pieces of evidence of who you are when logging in to an account. This evidence should fall into two (or more) of these three categories:

  • something you know: for example, a password or PIN
  • something you have: for example, an application on your phone or a bank card
  • something you are: for example, a fingerprint or retinal scan

In fact, you probably already use multi-factor authentication in some form. For example, you’ve used MFA if you’ve:

  • swiped your bank card (something you have) at the ATM and then entered your PIN (something you know).
  • logged into a website, like Amazon, with a username and password (something you know) and was then sent a numeric code to your phone (something you have), which you entered to gain access to your account.

Multi-factor authentication helps to protect your personal data, identity and money. ITS recommends enabling multi-factor authentication (or Two-Step Login) where available for any online services that you use regularly such as Google/Gmail,  Apple and others.

Can I use SMS/Text Messages as my factor?

Starting in Fall 2026, you will no longer be able to use SMS to authenticateyour account.

I can’t use a smartphone or SMS messaging. How can I use multi-factor authentication?

If you’re in a position where you can’t use either the smartphone application to authenticate your account, please contact the Help Desk.

How can I update my factors?

You may need to do this if you buy or sell your smartphone, change your phone number, or just want to manage your factors.

What happens if I forget my phone at home and need to teach?

If you are a faculty or staff member, multi-factor authentication (for most systems) is only required when connecting from off-campus. If you are teaching a class, running a meeting, or need to access resources while on campus, you will not be required to authenticate with your second factor.

Students will be required to use multi-factor authentication both on and off campus. If you forget your second factor, you can contact the Help Desk for further advice.

How often will I need to authenticate using multi-factor authentication?

You will need to authenticate the first time you use a new device (computer, laptop, phone, tablet, etc.), or browser to access protected systems.

After the initial authentication on a device, you may be asked to reauthenticate again in the future, usually after a number of days/weeks. ITS will calibrate the timing of reauthentication requests to best balance security needs and your convenience.

What happens if I lose my phone?

When using multi-factor authentication, your smartphone is an important step in accessing your account. If you lose your device, please reach out to the Help Desk so we can verify your identity and get you back into your account as quickly as possible.