MFA on Microsoft 365 (M365)
What is Multi-Factor Authentication (MFA)?
Multi-Factor Authentication (MFA) is widely adopted as a way to tighten security during login to major or sensitive systems. It requires the user to provide what he knows (e.g. password) and what he has (e.g. a registered mobile phone). This means that when you log in to certain online services, you will be asked to provide your password and confirm your identity with a separate media such as SMS, phone call or a designated device like your mobile phone.
This additional identification step will block hackers from logging into your account even when your password is compromised/leaked. You will also be notified when someone tries to login with your password. As a result, information in systems covered by MFA is better protected. MFA is commonly deployed in universities as well as in Internet banking. At EdUHK, test run of Microsoft's Multi-Factor Authentication for M365 services started in Jan 2019. Implementation of MFA for students is scheduled in Nov 2024.
How it works?
When you access services covered by MFA:
- Enter username and password.
- Use your designated device to verify your identity (e.g. your mobile phone or tablet) as the second verification step.
- You are securely logged in.
After you have enrolled in multi-factor authentication, you will need to login using your username / password and then verify your identity with your designated device to access the service/application covered by MFA.
The second step verification can be done through one of the following:
- Mobile app on a mobile device (This is highly recommended as you can bring your mobile with you wherever you go.)
- SMS with verification code to a registered phone number, either mobile or land line.
- Phone call to a registered phone number, either mobile or land line
How to enable the MFA for M365 services via the Microsoft Authenticator app?
It is crucial that all users use MFA to login major and sensitive systems. Setting up of the MFA feature takes only a few moment. Users should then follow the setup procedures below.
- Checklists
- Update your clients to a version which supports modern authentication. Supported clients include:
OS Office / Mail clients Windows OS: ‐ Office 2016 Mac OS: ‐ Outlook 2016 for Mac
- Mail app on macOS Mojave (10.14.x)iOS: ‐ iOS 15 or above + native mail client (bundled in iOS) / Outlook App Android OS: ‐ Android 8.0 or above + Outlook App (Note: native mail client is NOT supported) - The user account must be enabled by OCIO to use MFA. (Users will be notified separately.)
- A designated mobile device with ‘Microsoft Authenticator’ app installed.
Install and configure MFA Mobile App for M365 services
Please follow the procedures below to install the MFA app - Microsoft Authenticator and turn on notification for this app:
- Setting up Microsoft Authenticator app on mobile device.
Get the "Microsoft Authenticator" App for your system:
- Do I need to approve every login?
You will not be asked to approve every time when you login the desktop software or application (e.g. Outlook, Outlook app for mobile, Teams, and OneDrive sync client). Once you have successfully logged in the software on your office PC, the approved session will continue to be valid unless it is inactive for 90 days, meaning you have not logged in in 90 days.
However, if you access M365 using a browser, you have to approve login on your app every time you sign in. There is an option called "Stay signed in" but it is not recommended especially when you are using a shared or public computer.
- Ways to verify your identity
Once your account has been enabled to use multi-factor authentication for M365, the easiest verification method to use is Microsoft Authenticator as a security token. It's just one click instead of typing in a 6-digit code. And if you travel, you won't incur roaming fees when you use it.
If you are looking for other possible ways to verify your identity, please visit FAQ: How can I verify my identity for MFA on M365? for details.
- What if I do not have my mobile with me when login or I want to change the MFA verification method?
You can switch to authenticate via a different device. Please see FAQ: How can I change my MFA verification method on M365?.
How to access M365 service with MFA?
Once you have configured the MFA with the Microsoft Authenticator app, you can access M365 services with MFA using your phone as a security token. For details, please visit FAQ: How do I sign in to Microsoft 365 with MFA?. Note: The use of number matching in the Microsoft Authenticator app will be effective from 27 Feb 2023.
What if the email client software I use does not support MFA?
If the software you use (e.g. Android's native email client, Thunderbird mail client) does not support modern authentication like MFA, you need to generate an "App Password" for authentication. Please visit FAQ: How can I create an app password if my device doesn't support MFA? for details.
Applications currently covered by MFA at EdUHK
Currently, MFA is implemented in M365 services (e.g. Outlook (for staff), OneDrive, Teams etc.).
Note: If you have any questions about Multi-Factor Authentication (MFA) on M365, please visit the FAQ: MFA on M365 or Microsoft Two-step verification Help for details.