Microsoft Authenticator - Frequently Asked Questions

 

What is MFA?

How does the Microsoft Authenticator system work?

How do I get setup to use the Microsoft Authenticator?

What if I don't have a smart phone?

What if I change phones?

Who will need to use the Microsoft Authenticator system?

Why is New Paltz using the Microsoft Authenticator system?

What is MFA?

Multi-factor Authentication systems are those that require at least two of the following factors (only the first two being used by New Paltz).

  • Something you know (such as user names and passwords)
  • Something you have (such as an app on a smart phone, or a small key chain token) which is tied to your account
  • Something you are (biometrics such as fingerprints - don't worry - we have no intention of using biometrics at New Paltz - though you may have this in place on your smart phone or tablet via fingerprint or face ID scans).

An account protected by MFA cannot be accessed by one of those factors alone.  Were someone to get your password, but does not have your smart phone, they would be unable to access accounts protected with MFA (unless you authorize a log in that you are not making).  Vice-versa, if someone had your phone but not your password, they would also be unable to access accounts protected with MFA.

MFA has become very common - in particular on financial/banking accounts, email accounts, social media, or other systems which are at high risk for compromise for criminals.  New Paltz has been using MFA for faculty, staff, and student logins since 2020 to better protect our students, faculty, staff, alumni, applicants, and any others who communicate or share data with the university.

How does Microsoft Authenticator work?

If you chose the authenticator app option

Once you have the Microsoft Authenticator app setup, you'll see a prompt like the following when you log in to a university service.  It will show you a number on the service that you are trying to log into, that you need to enter on the Microsoft Authenticator app to verify your login.

On the web browser where you are trying to log in to a site (for example Brightspace, or Outlook), you'll see a prompt like the following with two digits shown.

Screenshot of the Microsoft Authenticator prompt in a web browser

 

On your phone, you'll then receive a notification from the Microsoft Authenticator app which will look like the following.  It will show the application you are trying to log in to, the approximate location that the log in attempt is coming from, and an "Enter number here" prompt.  You would enter the two digit number shown in your browser, into the app, to verify your log in.


 

If you chose the phone option

As of Fall 2026, we strongly recommend against using the phone/text message option.  Microsoft is removing this option as of February 2027 and any users who only have SMS/Text as their verification option will not be able to log in.

If you do not have a cell phone that can install the free Microsoft Authenticator app, please contact InformationSecurity@newpaltz.edu.

How do I get setup?

Faculty, staff, and students, are automatically enrolled in the system within 24 hours of their account being setup here.  When you log in to your New Paltz account for the first time you should be prompted to set it up.

See our "Microsoft Authenticator - Getting Started" page for instructions on how to set it up.

What if I don't have a smart phone and cannot install the free Microsoft Authenticator application?

If you do not have a smart phone - you can log in with a hardware security key.  Please contact our Service Desk (845-257-HELP or via servicedesk@newpaltz.edu) and let them know you do not have a smart phone and need another login option.

 

What if I change phones?

If you changed phones and still have the old phone:

  1. Go to https://aka.ms/mfasetup
  2. Click Add sign-in method
  3. Choose Microsoft Authenticator (recommended) to use the app on the new phone
  4. Follow the steps there.

If you are getting rid of your old phone, you can use that same page (https://aka.ms/mfasetup) to remove the older phone.

 

If you changed phones and no longer have the old phone:

Contact our Service Desk (servicedesk@newpaltz.edu, in-person at Humanities 103, or via 845-257-HELP) for assistance.
 

Who will need to use the Microsoft Authenticator system?

All faculty, staff, and students, as well as recent alumni (who still have their Microsoft 365 accounts for appproximately 9 months after graduation), will need to use this system.

 

Why is New Paltz using this system?

You may ask "Why is New Paltz is using the Microsoft Authenticator, or any other Multi-Factor Authentication (MFA)?".  There are a number of reasons.

  • Phishing: Phishing (fraudulent attempts to get people's username & password) has continued to be a significant problem both at New Paltz and at organizations worldwide.  Although the vast majority of these phishing messages are being blocked or marked as spam here at New Paltz (and many of our faculty and staff are fantastic about reporting these messages) some do get through.  At this point, the training and simulations are not a sufficient defense on their own.
  • Password reuse: Though we want all people to use a different password for all systems - we know that doesn't always happen.  People sometimes use the same password on multiple services.  When an external service gets compromised - the passwords used at that external site may be at risk.  They may be used to try to access other accounts, including those at New Paltz.  The same is true of common passwords.
  • Brute force attacks: Hackers are often trying to just 'guess' passwords.  They are doing this based on patterns of password.
  • General security issues: The number of attacks by criminal gangs against businesses, organizations, schools, and even individuals has been increasing greatly.  It seems that a week doesn't go by without a major ransomware attack.  Many ransomware attacks start with compromised computer accounts - often of just regular users.  Once they compromise one account (faculty, staff, or student) they can use that as a foot in the door to try to trick other users, or compromise other systems.

We have a duty to protect the data of our students, faculty, staff, alumni and donors.  Even an account of someone who does not have direct access to that data - can provide a criminal a level of access to the university which could lead to a further breach.  Because of this - we need to protect accounts with more than just a user name and password.