Using MFA
General FAQs
Multi-Factor Authentication (MFA) adds an extra layer of protection to your Brockport account. It helps make sure that only you can access your information — even if someone else knows your password.
MFA works by using two things:
- Something you know (like your password)
- Something you have (like your phone or tablet)
Think of it like using an ATM: you need your card (something you have) and your PIN (something you know). Without both, you can’t get in.
Brockport accounts are under constant attack from all over the world and passwords are becoming increasingly easy to compromise. Passwords can be stolen, guessed, hacked, and new technology and hacking techniques combined with the limited pool of passwords used for multiple accounts means information online is increasingly vulnerable.
In addition, experience has shown that people are not as good at recognizing malicious email as you might think. Multi-Factor Authentication adds a layer of security to your account to make sure that your account stays safe, even if someone else knows your password. This second factor of authentication is separate and independent from the NetID and password step — MFA never uses or even sees your password.
All Brockport person accounts are required to use Multi-Factor Authentication when logging into campus systems.
If you have any questions or need assistance setting up MFA, please contact the Brockport IT Service Desk at 585-395-5151 Option 1.
Once you have signed up for MFA, when you attempt to access campus resources, you will be prompted to enter your username and password as usual (the first “factor”). You will then be taken to the MFA screen where you will select the device of your choice and the preferred method of verification: push notification, or a passcode — you will use to verify that it’s you (the second “factor”).
You will be prompted to register your devices and authentication methods when you log into your account for the first time. It is strongly encouraged to have at least two devices registered. Instructions to setup MFA can be found in the Multi-Factor Authentication (MFA): Installing the Authenticator App and Registering Your Devices article .
MFA has the ability to link multiple devices to your account. You may use the Microsoft Authenticator app on a mobile device such as a phone or tablet. Additionally a hardware token may be used as your second factor. We strongly suggest setting up multiple devices if possible.
When you are performing your initial setup, you may add as many supported devices as you like. Subsequently, when you are logging in you may choose which device the authentication request is sent to and which authentication method you would like (via Microsoft Authenticator Mobile App, Token, or SMS).
You can sign in with the link to use a different method. From there you can use the other device option you setup when you registered.
Follow these instructions on managing devices and enrolling/registering a new phone, tablet, etc.
We recommend that all users add at least 2 methods, such as the Microsoft Authenticator App and passphrases.
No, you can use a token as well. We recommend that users who have a smartphone choose to use the Microsoft Authenticator App as it is the easiest to use while still being secure.
We encourage users to set up multiple authentication devices with MFA, so that when one method is unavailable, you have others from which to choose. For example, you could set up your smartphone for “push” and also a hardware token as a backup.
Contact the IT Service Desk at 585-395-5151 Option 1 immediately if you lose your phone or suspect that it's been stolen.
While it's important that you contact the IT Service Desk if you lose your phone, remember that your password will still protect your account.
If you have a new phone with the same number, you can use the alternate MFA device to authenticate and add your new phone.
If you have a new number, but still have your old phone you can use that to authenticate, remove your old number, and register your new number.
If you do not have access to your old number or device you will need to contact the IT Service Desk.
”Push” authentication uses a very small amount of Internet data traffic to function. The Microsoft Authenticator app also works like a token and can generate a passcode, this functionality will not require any data and works even when your smart phone is in airplane mode.
The Microsoft Authenticator app provides options that work without a data plan, a texting plan or even a connection, if necessary. The app can generate the required code without need of either a cell signal or data plan, and it can do so anywhere in the world. If you have a signal and data plan, the app makes two-factor authentication as easy as a pushing a single button, but if you don’t, you can use the app to generate a six digit code and enter that instead.
The Microsoft Authenticator app can generate a passcode without a cellular or wireless connection. Alternately, you may use a landline phone if an Internet connection is unavailable.
The Microsoft Authenticator app is designed to work internationally. If you install the app, it can generate the required code without need of either a telephone signal or data plan, and it can do this anywhere in the world. If you have a signal and data plan, the app makes two-factor authentication as easy as a pushing a single button, but if you don’t have one of those two things, you can use the app to generate a six digit code and enter that manually.
Yes, MFA can handle international phone numbers. If entering an international phone number, you can leave a space between country code, city code, and the phone number.
If you need further assistance, please place a ticket here: Submit a Ticket!, or call the call the IT Service Desk at (585) 395-5151 Option 1.