Body
Overview
This article provides a guide to getting started with Microsoft MFA.
Before You Begin
To familiarize yourself with Microsoft MFA, we highly recommend reading through What do I need to know about Microsoft MFA? prior to following the below instructions to set up Microsoft MFA.
Note: You will still need to use Duo to authenticate to some university services, including the VPN. Do not delete the Duo Mobile app from your device during the transition period, which lasts until April 2027. Technology Solutions and your local IT teams will provide further communications when the Duo Mobile app is no longer needed.
Table of Contents
Registering Microsoft MFA methods
To register new Microsoft MFA methods:
- Visit aka.ms/mfasetup and log in with your UIC NetID and password.
- The Microsoft MFA setup page will display your available sign-in methods. If you haven't already, review How do I choose the right MFA method for me?
Note: it is strongly recommended that you set up Microsoft Authenticator as a backup method, while also setting up passkeys as your primary methods on your commonly used devices for the best sign-in experience.

- Select + Add sign-in method
- If you have not yet done so, set up the Microsoft Authenticator mobile app. This will be an important backup MFA method.
- If you have already set up the Microsoft Authenticator app, follow the instructions for setting up a Passkey to have the simplest sign-in experience.
- If you have a USB security key, follow the Security Key setup instructions.
- Finally, if you have a C200 hardware token, jump to setting up a Hardware Token.
- Visit aka.ms/mfasetup and select Add Sign-in Method. On the following screen, select Passkey.

- On the next screen, select Next.

- Once the next screen is displayed, select Next and your device will prompt you to create a passkey in your password manager (e.g. Google Password Manager, Apple Passwords, Microsoft Password Manager, Bitwarden, etc) or on your device (e.g. Windows Hello). Examples are shown for Apple Passwords, Windows Hello, and Bitwarden.




- Once created, you will be prompted to name your passkey. Enter any name that is easily identifiable to you.
- Visit aka.ms/mfasetup and select Add Sign-in Method. On the following screen, seleect Hardware Token.

-
A pop up window will ask for the hardware token Serial Number.

You can find your Hardware Token's serial number on the back of the device.

-
Enter a name for your Hardware Token.

-
The next pop up will ask for the 6-digit verification code on the device you just registered. Enter the code.

-
The next pop up screen will have the confirmation that your device has been added to your Microsoft account.

-
Your New C200 Hardware token will now be listed on the Security Info screen.
Once you have registered your desired MFA methods, familiarize yourself with how to sign in using Microsoft MFA.
Managing Sign-in Methods
To manage your sign-in methods, visit aka.ms/mfasetup.
To remove a sign-in method, select Delete next to the method you'd like to remove.
Note: Do not remove the Duo MFA (external mfa) entry as this is still needed to access some university services, such as the VPN. This method will be removed automatically at the end of the transition period.
