Turning on Multi-Factor-Authentication (MFA) in Microsoft

Texas Woman’s University is strengthening its security posture by enabling multi-factor authentication (MFA) (also referred to as two-factor authentication (2FA) or two-step verification) for specific systems across the University. MFA adds an extra layer of protection when accessing accounts and requires users to provide additional verification beyond a password.

As part of Microsoft's security enhancements, Microsoft is transitioning away from SMS (text message) and voice call authentication and moving to passkeys, a more secure, phishing-resistant authentication method. Beginning February 1, 2027, Microsoft will retire its native SMS and voice authentication services. Users who currently rely on SMS or voice authentication should transition to a passkey or Microsoft Authenticator.

Enable Microsoft 365 MFA

TWU recommends setting up Microsoft 365 MFA using one of the following options:

To set up your Microsoft 365 security methods, follow Microsoft's guide:

Enrolling in Microsoft 365 MFA turns on MFA for your entire TWU Microsoft 365 account. When you log into Microsoft 365 using your TWU Portal credentials, you will be asked for your second factor. This includes checking Teams or accessing other applications in Microsoft 365.

What Is a Passkey?

A passkey is a modern sign-in credential that uses your device's built-in security features, such as:

  • Fingerprint
  • Facial recognition
  • Device PIN
  • Hardware security key (FIDO2)

Passkeys provide stronger protection against phishing, SIM-swapping attacks, and account compromise than traditional passwords, text messages, or phone-based verification methods.

How do I create a Passkey?

Depending on your device, you can create a passkey using:

  • Microsoft Authenticator
  • Apple iCloud Keychain
  • Google Password Manager
  • Windows Hello
  • A supported FIDO2 hardware security key

If you currently authenticate using SMS text messages or voice calls, you may be prompted by Microsoft to register a passkey during sign-in. Follow the on-screen instructions to complete setup.

If you do not have access to a compatible mobile device, contact the Technology Service Desk for assistance with alternative authentication options.

What can I expect after I enroll?

When you log in to Microsoft 365 using your TWU credentials, you will be asked to verify your identity using your enrolled authentication method.

Microsoft 365 MFA Transition Information

I Already Use Microsoft Authenticator or a Passkey

No action is required at this time. You may continue using your current authentication method.

I Use Text Messages or Phone Calls for MFA

Microsoft is retiring SMS and voice authentication. You will be prompted to register a passkey when signing in. We encourage you to complete passkey registration as soon as possible to avoid future sign-in disruptions.

What's the Timeline?

  • September 1, 2026: Users who rely on SMS or voice authentication may begin receiving passkey registration prompts.
  • February 1, 2027: Microsoft-provided SMS and voice authentication services will be retired.
  • Users whose only authentication method is SMS or voice will be required to register a passkey or another supported authentication method to continue accessing their accounts.

Microsoft 365 MFA Troubleshooting

Additional Resources

For additional support, contact the Technology Service Desk at 940-898-3971, servicedesk@twu.edu, or submit a request through the Technology Service Center.

Print Article

Related Articles (3)

A "Portal account" is required for all students, faculty and staff at TWU to log-on to the network and all other systems. This is created on "Pioneer Portal," our intranet site, hence the name "Portal account."
Microsoft 365 for active students
This guide provides step-by-step instructions on how to setup your TWU Portal account, Google MFA, access Self-Service, and TWU email; canvas access, support resources, and troubleshooting tips.