Microsoft 365 Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds an extra layer of security to your account by requiring another form of verification in addition to your username and password. At St. Cloud State University, MFA is required to help protect Microsoft 365 accounts, university data, and systems from unauthorized access. MFA is used with Microsoft 365 applications such as Outlook, Teams, OneDrive, Word, and OneNote, as well as other services that use Minnesota State's Microsoft authentication.
MFA Options
Beginning October 1, 2026, the following options are available for new accounts. SMS/text message and voice/phone-call authentication are being retired February 1, 2027, so current users who rely on those methods are encouraged to move to a supported option before then. Microsoft Authenticator is the recommended option. If you are unable to use Microsoft Authenticator, please contact HuskyTech for an alternative option that does not require a mobile device, such as a security key or hardware token.
Please keep your authentication device with you to help ensure uninterrupted access.
| Supported MFA Option |
Description |
| Recommended: Microsoft Authenticator approval notification (number matching) |
Receive a sign-in request in Microsoft Authenticator and approve it using number matching. |
| Passkey stored in Microsoft Authenticator |
Use a passkey stored in Microsoft Authenticator and your device's PIN, fingerprint, or facial recognition to sign in. |
| Microsoft Authenticator verification code |
Enter a rotating six-digit code generated by Microsoft Authenticator. The code can be used even when the device does not have cellular service. |
| Another supported authenticator app |
Enter a rotating six-digit code generated by an authenticator app, such as Google Authenticator or Cisco Duo Mobile. |
| Physical security key (passkey) |
Use a USB, NFC, or Bluetooth security key instead of a phone. Examples include YubiKey, Feitian Security Key, and other FIDO2 security keys. |
| Hardware token verification code |
Enter a rotating six-digit code displayed on a physical token or fob, such as a Token2 hardware token. A smartphone is not required. |
Set Up MFA
When prompted to set up additional security verification:
- Go to Microsoft 365 sign-in.
- Sign in using your StarID credentials:
- Students:
StarID@go.minnstate.edu
- Faculty, staff, and emeriti:
StarID@minnstate.edu
- When More information required appears, select Next.
- Follow the prompts to configure a supported MFA method.
Add or Change an MFA Method
Sign into the Microsoft Security Info to review or update your MFA methods. Select + Add sign-in method to configure another supported method, or use the options provided to change or remove an existing method or update your default sign-in method.
Example:

Getting a New Phone?
If possible, set up Microsoft Authenticator on the new phone before erasing, trading in, or otherwise losing access to the old phone. Sign into the Microsoft Security Info page, add Microsoft Authenticator as a sign-in method, complete the registration process on the new phone, test it, and then remove the old device’s registration. Simply installing Authenticator on the new phone does not automatically unregister the old device.
If you no longer have access to a functioning authentication method, contact HuskyTech to reset your MFA settings.
Unable to Access MFA? (e.g. lost phone, MFA not working, etc.)
If you have access to an alternative authentication method, use it to sign in. If you do not have access to any functioning MFA method, contact HuskyTech to reset your MFA settings.
Traveling?
Before traveling, especially internationally or to areas with limited connectivity, take steps to ensure you can continue accessing Microsoft 365 and other Minnesota State services that use your Microsoft organizational account.
Before you travel:
- Configure at least two supported authentication methods whenever possible.
- Test each authentication method before you leave to confirm it works as expected.
- If you use Microsoft Authenticator, verify that you can access the app and any required device PIN, fingerprint, or facial recognition.
- If you use a passkey, confirm you can access the device or application where the passkey is stored.
- If you use a physical security key, bring it with you and consider carrying a backup authentication method if available.
- If you rely on Microsoft Authenticator, consider configuring verification codes as a backup to approval notifications.
While traveling:
- Keep your authentication device, passkey-enabled device, or physical security key with you.
- If internet access is unavailable, Microsoft Authenticator verification codes can still be generated and used without cellular service or an internet connection.
- Approval notifications in Microsoft Authenticator generally require an internet connection to receive and approve sign-in requests.
- If you experience issues with your primary authentication method, setup and use an alternate method before your trip.
If you do not use a smartphone:
- Ensure you have another supported authentication method available, such as a passkey stored on a compatible device or a physical security key.
- Test your authentication method before departure to confirm it works with the devices you plan to use while traveling.
If you lose access to your authentication method while traveling:
- Attempt to sign in using another registered authentication method, if setup.
- If no alternative authentication method is available, contact your campus help desk for assistance with account recovery.
We strongly recommend keeping your authentication device with you anytime you may need it to log in to help ensure uninterrupted access.
Need Help?
If you have trouble setting up MFA, lose access to your authentication method, or are unable to sign in, contact HuskyTech for assistance.