Retiring Text Messages (SMS) as a Valid Multi-factor Authentication Method

Summary

Background information on the retirement of text messages as a valid Multi-factor Authentication method.

Body

Why Retire Text Messages (SMS) as an MFA Method?

We’re retiring SMS as a valid MFA Method to further improve the security of Brockport accounts against cyber attacks that have become more frequent and sophisticated. SMS as an MFA method is more vulnerable to threats, like SIM swapping and phishing. By using more secure methods, we’ll better protect our information and data. Additionally, Microsoft is retiring less secure MFA methods such as SMS and voice calls as free services. 

What is Changing

SMS-based MFA will no longer be supported as of February 1st, 2027. Instead, users will need to register secure methods, such as the Microsoft authenticator apps, passkeys, or hardware tokens. These methods provide enhanced security and reliability.

Timeline

BITS will begin alerting impacted users starting in mid-October. All SUNY Brockport user accounts will no longer be able to use SMS as an MFA method on February 1st, 2027. Accounts that have not made the change by then will be required to do so the next time they face an MFA challenge. To make sure your studies and work are not interrupted, we encourage everyone to make the switch as soon as possible.

Still Need Help?

If you need further assistance, please submit a ticket here: I Need Help, or call the IT Service Desk at  (585) 395-5151 Option 1

Details

Details

Article ID: 164847
Created
Mon 9/28/26 10:16 AM
Modified
Thu 10/1/26 5:06 PM