What is Multi-Factor Authentication (MFA)?

Multi-Factor Authentication (MFA) combines two or more independent credentials or "factors" -- what you know (i.e. your password) with something you have (e.g. mobile phone) -- to create a second layer of security for your UWin Account. Even if someone has your password, they will be prevented from accessing your account when it is protected by MFA, unless they have access to your secondary authentication method.

MFA is enabled on all student, faculty, staff, and sessional accounts, and is used with most University of Windsor apps and services, including key ones such as:

  • Office 365 and associated apps: Office 365 Portal, Microsoft Office, Outlook, OneDrive, and Teams
  • Brightspace (LMS)
  • UWinsite Student
  • UWinsite Finance
  • UWinsite People

Need help?

  • To report any MFA related issues, submit a request for assistance by opening a ticket.

Authentication Methods

The University of Windsor supports several MFA methods to meet different user needs. For most students, faculty, staff, and sessional instructors, a device-bound or synced passkey is recommended because it provides strong, phishing-resistant protection and securely stores credentials on your device.

You can choose from the secondary authentication methods listed below. We recommend enabling more than one method in your Microsoft work / school account profile so you can Sign in another way if your default method is unavailable.

  1. Device-Bound Passkey
    A device-bound passkey is stored on the device and can only be used from the device where it was created. It cannot be synchronized to other devices and typically provides stronger device-specific security. When you sign in, the device (or security key) verifies your identity using a fingerprint, face recognition, or PIN.

    Passkey in Microsoft Authenticator
    A passkey in Microsoft Authenticator is a device-bound passkey stored securely in the Microsoft Authenticator app on your mobile device. It uses cryptographic authentication and verifies your identity using your phone’s fingerprint, face recognition, or device PIN. When signing in, you may be prompted to scan a QR code or approve the sign-in through Authenticator, allowing you to securely access University resources without using a text message code or traditional push notification. The passkey remains protected on your phone and is not stored on the computer you are signing in from.
    Learn how to set up a passkey in Microsoft Authenticator.

    Windows Hello for Business
    Windows Hello for Business is Microsoft's enterprise authentication solution that uses biometrics (face or fingerprint), a PIN, or both, backed by cryptographic keys stored on the device, to provide passwordless access to corporate resources.
    If you have a university-owned or research-funded, primary user Windows OS (PC) device, this method is automatically set up for you.

    FIDO2 Security Key
    A FIDO Security Key is a physical hardware device (USB) that stores cryptographic credentials and is used to authenticate users through a simple action such as touching or inserting the key. FIDO2 Keys can be purchased through the University at Security Key | Information Technology Services. Alternatively, for a list of vendors with known-compatible FIDO2 keys, see: Azure Active Directory passwordless sign-in - Microsoft Entra | Microsoft Learn.
     
  2. Synced Passkey
    A synced passkey is securely synchronized across a user's devices through a cloud service (such as Microsoft, Apple, or Google account sync), allowing sign-in from multiple devices.
    Learn how to set up a synced passkey.
     
  3. Microsoft Authenticator push notification 
    A push notification is sent to the Microsoft Authenticator app installed on your mobile device when accessing MFA protected services and apps on non-trusted computers. You will view the notification and select Approve to complete verification. If your phone is not connected to wi-fi or does not use mobile data, you will be prompted to enter verification code (i.e. second credential) when accessing MFA protected services and apps on non-trusted computers, right after entering their password. The Microsoft Authenticator app is available for iOS and Android platforms and can be downloaded from Apple and Google app stores.
     
  4. Microsoft Authenticator Time-based One-time Passwords (TOTP) (by request only)
    A time-based one-time password (TOTP) is a temporary verification code generated in the Microsoft Authenticator app on your mobile device. When prompted for MFA, open the app, select your University of Windsor account, and enter the current six-digit code to complete verification. This method can be used even when your phone does not have Wi-Fi or mobile data, but the Microsoft Authenticator app must already be set up on your device.

Note: In the fall of 2026, text message (SMS) to your mobile phone method will gradually phase out and will be discontinued by January 31, 2027.

New to UWindsor and need to set up MFA? 

Already have MFA and want the most secure options?

Signing in with MFA

Once you have configured your authentication methods and MFA is enabled on your UWin Account, the next time you log in to any MFA protected resources, you will be prompted for your login, password, passkey and your MFA code or verification through the authenticator app. You will have the option to not ask again on that device for 30 days. Do not check that box if you are using a public computer (e.g. library or computer lab workstation).

If you did not configure your authentication methods as part of extending or activating your UWin Account, you will need to go through MFA setup on your first access of an MFA-protected resource.

If you are unable to proceed with your default secondary authentication method (as configured in your Microsoft work account profile), you can click on Sign in another way link and select a different method.

 

 

 

 

 

 

 


 

 

Note for Office 365 Android Users: Currently there are no supported mail apps for Android that support MFA - IT Services recommends installing the Outlook app from the Google Play store, which will give you improved functionality over the built-in mail/calendar app as well as the ability to use MFA.

Note for Office 365 iPhone Users: If you are using the built-in mail/calendar app on iOS 11 or above, it does support MFA, but you must remove and re-add the account in order for it to function. See the instructions here on how to remove and re-add your account:

How to add or remove my University Office 365 account to my iPhone or iPad

However for the best supported experience, IT Services recommends the Outlook app.

 

50% helpful - 2 reviews
Print Article

Related Articles (7)

The different authentication options available in the My Profile under “My Security Info” page exist to let users prove their identity using multiple methods, which strengthens account security and provides flexibility during sign‑in or account recovery. Instead of relying only on a password—which can be stolen or guessed—these options (such as the Microsoft Authenticator app or passkeys) add extra verification factors so that access requires something you know, have, or are.
To provide additional security for sensitive data stored on your University-owned Windows 10 laptop, I.T. Services can assist you with enabling Bitlocker drive encryption.
How to sign in with Multi-Factor Authentication
When you sign in to your new account for the first time, you will be guided through a short setup process to configure multi-factor authentication (MFA). You must complete this step before gaining full access to your account. The setup process is designed to be simple and only takes a few minutes, helping ensure your account is protected from unauthorized access from the very beginning.
Microsoft Authenticator is a free mobile app from Microsoft for iPhone, iPad, and Android devices that helps protect your UWin Account (Microsoft work/school account). Passwords alone are no longer enough to keep accounts secure. Microsoft Authenticator adds an extra layer of protection that helps prevent unauthorized access, even if someone else knows your password.
If you have access to a computer, you may be able to update your MFA configuration to include your new phone following steps outlined in this article. If you can't, you have to submit a request by opening a ticket to have your MFA reset.
Microsoft recently announced that on October 1, 2022, basic authentication will be permanently disabled in Microsoft 365 for all organizations.