UNIVERSITY PARK, Pa. — Microsoft is changing its current voice-only multifactor authentication (MFA) defaults and options, moving to phishing-resistant MFA methods such as passkeys — a modern, passwordless sign-in method that makes it harder for attackers to steal or reuse — and discontinuing all short message service (SMS) and voice/phone MFA options beginning Feb. 1, 2027.
This change affects how some members of the Penn State community authenticate to Penn State secure resources, including but not limited to Outlook, Canvas, LionPATH, Workday and SIMBA.
What is phishing-resistant MFA?
Phishing-resistant MFA provides additional protection for your Penn State Account by using sign-in methods that are designed to prevent phishing attacks. Unlike traditional MFA methods that use SMS text message codes or a call to a cellphone or landline home or office phone to sign in with a code, it helps prevent scammers from tricking you into approving the phone call and giving away your login information. This is increasingly important in this AI era. Furthermore, while Microsoft Authenticator push notifications and number matching provide strong account security, they are not considered truly phishing-resistant.
Passkeys are a phishing-resistant MFA technology that replaces your password. Unlike traditional passwords, they cannot be easily stolen or entered into a fraudulent website. They can be stored in several ways, including on your smartphone, computer, password manager or a physical FIDO2 security key.
Using your passkey, you will verify your identity with your device’s unlock method, such as face ID, touch ID, fingerprint, PIN or by physically tapping your FIDO2 security key. If your passkey is stored on your smartphone, you will be prompted to scan a QR code first, then use your phone’s unlock method to complete sign-in. This makes phishing-resistant MFA one of the most effective ways to protect accounts from cyberattacks.
Who will be affected by this change?
Those who have SMS or voice/phone MFA as their default or secondary sign-in option will be required to switch to a stronger, more secure MFA method by the February deadline.
To help with this transition, starting Sept. 1, those who currently receive an SMS text message or phone call to authenticate will automatically be prompted to change their MFA method when they sign in to a Penn State secure resource and go through the MFA process. They can either click “Next” to follow the prompt to register another MFA method or click “Not now” to postpone the process for the next 24 hours. However, they will continue to receive the prompt every time they sign in until they act.
Although this University-wide initiative, driven by Microsoft’s enforcement requirement, primarily impacts those who use SMS or voice/phone as their default or secondary MFA method, Penn State IT encourages the adoption of phishing-resistant methods, such as passkeys, whenever possible to better protect accounts and sensitive data from phishing attacks, credential theft and unauthorized access.
Penn State Knowledge Base resources
To learn about the available MFA options, visit MFA: Which MFA Option Should I Choose?
To learn more about passkeys, visit MFA: What is a Passkey?
For instructions on how to set up phishing-resistant MFA, visit MFA: What Is Phishing-Resistant MFA and How Do I Enroll?
For assistance, contact the IT Service Desk via chat, submit a Get Help ticket, call 814-865-4357 or email ITservicedesk@psu.edu.