Body
Overview
Multi-factor authentication, also known as two-factor authentication, is a form of authentication which provides an added layer of account protection, beyond just your password. This additional authentication helps verify a person logging into an account is authorized to access that account and greatly increases security protection of your account.
Microsoft Authenticator Passkey is a phishing-resistant, passwordless sign-in credential that is stored in the Microsoft Authenticator app on an iOS or Android device. Instead of entering a password, users authenticate using a device-based security factor such as a fingerprint, face recognition, or device PIN. A passkey uses public-key cryptography, making it significantly more secure than traditional passwords and SMS-based multifactor authentication.
Article Sections
MFA and StarID Password Changes
SMS and voice authentication is being retired
Microsoft is retiring from SMS text messages and phone calls as authentication methods on February 1, 2027. If you currently rely on SMS or phone calls for MFA, you will need to switch to a supported method before that date. Supported options include methods available through the Microsoft Authenticator app, such as approval notifications, verification codes, and passkeys. If you cannot or prefer not to use a personal mobile device for authentication, contact 651-793-1240 to discuss another supported option, such as a physical security key or hardware token.
- Oct. 1, 2026: New SMS and voice MFA registrations blocked; new users must use the Microsoft Authenticator app. Existing users will begin receiving prompts to modify their MFA settings, yet they will be able to select “Skip for now” as many times as they wish through Jan. 18, 2027.
- Jan. 19, 2027, the number of times you can select "Skip for now" will be limited to three times before Authenticator registration becomes required, unless another supported method is in place, such as an MFA exception (e.g. hardware security key).
- Feb. 1, 2027: Users will not be able to use SMS and voice MFA. If they haven’t already done so, they will be required to set up a supported method to sign into services that leverage their Microsoft 365 credentials.
StarID password requirements change effective October 1, 1026
Minnesota State is also updating StarID password requirements to strengthen account security and align with current password best practices. New StarID passwords must:
- Be 15–128 characters long.
- Include at least three of the following: uppercase letters, lowercase letters, numbers, or special characters.
- Not have been used previously.
- Not contain your first or last name if the name is longer than two characters.
You do not need to change your password on October 1. Your existing StarID password will remain valid until its scheduled expiration date (180 days since your last password change). The next time you are required to change your password, your new password will need to meet these requirements.
Once your StarID password meets the new requirements, regularly scheduled password changes will no longer be required, unless a password reset is needed for another reason.
Register Passkeys on Authenticator
Register passkeys in Authenticator on Android and iOS devices
Use Microsoft Authenticator app with number matching to authenticate into Microsoft 365
Those using the Microsoft Authenticator app with Minnesota State Microsoft 365 services and connected applications use number matching for all MFA requests. Number matching helps ensure that the person requesting access into an account is the same person approving the sign in on a device.
- Sign into Microsoft 365 with your StarID username and password
- Students: StarID@go.minnstate.edu
- Employee: StarID@minnstate.edu

- An "Approve sign in request" window will appear with a 2-digit number.

- Open your Microsoft Authenticator app and enter the 2-digit number and press Yes

Important notes related to Microsoft Authenticator app with number matching:
- Number matching requires the latest version of the Microsoft Authenticator app. Check the Google Play Store or Apple App Store for the latest update.
- Number matching is not supported by Apple Watches.
- Never approve sign in requests that you did not request or expect.
MFA Setup Process
All new accounts are automatically enrolled in multi-factor authentication. You will be prompted to complete MFA setup when you sign in to your email for the first time.
To prepare for setup, you will need to have a computer to sign in to your account and a mobile device with the Microsoft Authenticator app installed.
To help ensure you are not locked out of your account, it is important to set up one or more alternate options in the event you do not have access to your primary phone, for instance if:
- You do not have immediate access to your primary authentication phone
- Your phone battery is dead
- Your primary phone device is lost, stolen or damaged
- You get a new phone and no longer have your original primary phone number
You can find instructions for adding alternate MFA options in the section Add or Change Alternate Sign-in methods
If you are a student and staff (at the same or different institutions) your student MFA will be different than staff MFA and need to be setup separately. The Microsoft Authenticator app supports multiple MFA accounts. If you are a student at multiple institutions or staff at multiple institutions, you only need to setup MFA once for the student accounts or once for the staff accounts.
Should you encounter "Allow my organization to manage my device" it is recommended not to select this option.

None of your personal information is stored in or accessed by the Microsoft Authenticator app. It's design and purpose is solely as an authentication utility.
Register Passkeys on Authenticator
Register passkeys in Authenticator on Android and iOS devices
Android - Set up Microsoft Authenticator app
Steps to set up the Microsoft Authenticator app on your Android mobile device.
- You will need both your Android mobile device and a computer to complete the setup.
- On your Android mobile device, go to the Play Store to download, install, and open the Microsoft Authenticator app.
- Accept the Privacy Statement, Continue past "Help us improve Microsoft Authenticator"

- If asked to "Sign in with Microsoft" select Skip at the top right of the app.

- At the Authenticator home screen, tap "Add Account" at the bottom or the "+" symbol at the top right.

- Select "Work or school account" then select "Scan a QR code". Tap Allow if prompted to "Allow Authenticator to take pictures and record video?"
- Switch to your computer.
- Browse to the Microsoft Security Info page at https://aka.ms/mfasetup
- You can also go to your Metro State email.
- Sign in with your username and StarID password.
- Student username: StarID@go.minnstate.edu
- Employee username: StarID@minnstate.edu
- Select Next on the "More information required" popup.
- On the "Keep your account secure" page under Start by getting the app, select Next.
- Under Set up your account, select Next.
- You will now be at the Scan the QR code page, which shows the QR code.

- Switch to your Android device
- Using the Microsoft Authenticator app, scan the QR code shown on the computer.
- After scanning the QR code, you will see an account named MNSCU with your StarID

- Switch to your computer
- On the Scan the QR code page, click Next
- The next page will say "Microsoft Authenticator. Let's try it out" and show a 2-digit number.
- A notification will be sent to your Android device.

- Switch to your Android device
- Open the Microsoft Authenticator app (or tap on the notification received).
- You will be asked "Are you trying to sign in?" and prompted to enter the 2-digit number shown on the computer.
- Enter the number and tap Yes.

- Switch to your computer
- You will see "Notification Approved." Click Next
- You will see "Success" and a list of your MFA sign-in methods. Click Done
- You may see a prompt to "Stay signed in?" on the computer. Click Yes
- You have finished setting up MFA on your Android mobile device.
Information Security:
What should I do when I get a verification request I don’t recognize?
If you receive approval requests for access to your Office 365 and you are not actively signing in to Minnesota State O365 connected applications (in other words you did not just attempt to log in to your O365 account using your Minnesota State O365 login credentials) then deny the access.
Stay Vigilant:
- You will not be prompted by MFA without your attempt to log in. MFA verification will never prompt you first. Do not approve or take action on any prompts if you are not logging into your account.
- No one, including IET Services, Metropolitan State University, Minnesota State Colleges or Universities, or other entities which may appear to be related, will ever contact or prompt you to ask you to “approve” an MFA notification or ask for a verification code.
- Do not press # key for verification or enter verification code if you receive a voice call on your mobile device, office, or alternate phone. Ensure your spouse or trusted family doesn’t automatically enter the key(s) without checking with you first.
iPhone - Set up Microsoft Authenticator app
Steps to set up the Microsoft Authenticator app on your iPhone.
- You will need both your iPhone and a computer to complete the setup.
- On your iPhone, go to the App Store to download, install, and open the Microsoft Authenticator app.
- Accept the Privacy Statement, Continue past "Help us improve Microsoft Authenticator".

- If asked to "Sign in with Microsoft" select Skip at the top right of the app.

- At the Authenticator home screen, tap "Add Account" at the bottom or the "+" symbol at the top right.

- Select "Work or school account" then select "Scan a QR code". Tap OK if prompted to ""Authenticator' Would Like to Access the Camera".
- Switch to your computer
- Browse to the Microsoft Security Info page at https://aka.ms/mfasetup.
- You can also go to your Metro State email.
- Sign in with your username and StarID password:
- Student username: StarID@go.minnstate.edu
- Employee username: StarID@minnstate.edu
- Click Next on the prompt "More information required".
- Click Next on the page "On the Keep your account secure".
- Under Start by getting the app, click Next.
- Under Set up your account, click Next.
- You will now be at the Scan the QR code page, which shows the QR code.

- Switch to your iPhone
- Using the Microsoft Authenticator app, scan the QR code shown on the computer
- After scanning the QR code, you will see an account named MNSCU with your StarID.

- Switch to your computer
- On the Scan the QR code page, click Next
- The next page will say "Microsoft Authenticator. Let's try it out" and show a 2-digit number.
- A notification will be sent to your iPhone.

- Switch to your iPhone
- Open the Microsoft Authenticator app (or tap on the notification received)
- You will be asked "Are you trying to sign in?" and prompted to enter the 2-digit number shown on the computer
- Enter the number and tap Yes.

- Switch to your computer
- You will see "Notification Approved." Click Next.
- You will see "Success" and a list of your MFA sign-in methods. Click Done.
- You may see a prompt to "Stay signed in?" on the computer. Click Yes
- You have finished setting up MFA on your iPhone.
Information Security:
What should I do when I get a verification request I don’t recognize?
If you receive approval requests for access to your Office 365 and you are not actively signing in to Minnesota State O365 connected applications (in other words you did not just attempt to log in to your O365 account using your Minnesota State O365 login credentials) then deny the access.
Stay Vigilant:
- You will not be prompted by MFA without your attempt to log in. MFA verification will never prompt you first. Do not approve or take action on any prompts if you are not logging into your account.
- No one, including IET Services, Metropolitan State University, Minnesota State Colleges or Universities, or other entities which may appear to be related, will ever contact or prompt you to ask you to “approve” an MFA notification or ask for a verification code.
- Do not press # key for verification or enter verification code if you receive a voice call on your mobile device, office, or alternate phone. Ensure your spouse or trusted family doesn’t automatically enter the key(s) without checking with you first.
Steps to add new sign in methods or change existing methods
- It is recommended to have more than one MFA method in the event one is unavailable.
- You will need to set up alternate MFA methods if changing phones or phone number
- These instructions assume you are making changes to your MFA account (that you have previously set up MFA)
- On your computer
- Browse to the Microsoft Security Info page at https://aka.ms/mfasetup
- Sign in with your username and StarID password
- Student username: StarID@go.minnstate.edu
- Employee username: StarID@minnstate.edu
- Click "Add sign-in method". Select the new method and click Add.
- Follow the steps for setting up the Microsoft Authenticator app or authentication phone number
- To change your default (primary) MFA method click Change to the right of the Default sign-in method
- Select the new default and click Confirm
- To delete an MFA method, click Delete next to the method you want to remove.
How to use an alternate verification during sign-in
- In the event you do not have the primary MFA method during sign in, you can select one of your alternates (if one has been setup)
- Sign into your Microsoft 365 account.
- For example, Metro State email
- Student username: StarID@go.minnstate.edu
- Employee username: StarID@minnstate.edu
- At the MFA verification screen, click "I can't use my Microsoft Authenticator app right now" or "Sign in another way"
- Select one of the alternate MFA methods, such as text message or phone call.
Steps to take when changing to a new phone number or a new mobile device
- When you know ahead of time that you will be getting a new phone number or a new mobile device, there are steps to take to avoid needing to reset MFA, which is time consuming and will prevent access to your account.
- In general, having an alternate MFA method unrelated to the phone number or device being changed will prevent losing access to your account
- For example, add an alternate sign-in method using the phone number of a trusted family member or friend.
- After setting up your new device, remove their phone number from your list of MFA methods
Changing phone number but not device
Changing device but not phone number
Changing device and phone number
- Add the Microsoft Authenticator app to a different mobile device, such as a tablet, or add the phone number of a trusted family member or friend to your alternate sign-in methods
- When you have the new device and the new phone number is active, add the Microsoft Authenticator app and the new phone number to your alternate sign-in methods
- Delete your old phone number, old mobile device, and the phone number of a trusted family member or friend from your list of MFA methods.
If these actions are not taken prior to a changing phone numbers or changing mobile devices and you are locked out of your account please contact IET Service Desk for assistance.