What do I need to know about Microsoft MFA?

Summary

As the University of Illinois transitions to Microsoft Multifactor Authentication (MFA), this article highlights some of the key changes and improvements to expect.

Body

Overview

The University of Illinois is transitioning to Microsoft Multi-factor Authentication (MFA) to provide a more secure and streamlined sign-in experience.

Microsoft MFA introduces new ways to securely access university applications and services, including passkeys, which allow you to sign in using your fingerprint, face recognition, device PIN, or another device security method instead of entering your university password.

This article explains what is changing, the authentication methods available to you, how to choose the best methods for your needs, and what you should do to prepare for the transition.

Table of Contents

What is changing with MFA? 

The University of Illinois is transitioning to Microsoft Multi-factor Authentication (MFA), which provides new options for securely signing in to university applications and services. Instead of relying on Duo for authentication, Microsoft MFA will provide several authentication options, including passkeys and Microsoft Authenticator.

One of the biggest changes is support for passkeys, which provide a faster, more phishing-resistant sign-in experience.

What is a passkey?

A passkey allows you to securely sign in using the same method you use to unlock your device, such as: 

  • Fingerprint
  • Face recognition
  • Device PIN
  • Another supported device security method

Instead of entering your university password and then completing a separate MFA prompt, a passkey can authenticate you in a single step using the built-in security features of your device..

Important: Passkeys do not eliminate your university password. Your password will continue to exist and may still be required for some university systems and sign-in scenarios.

Watch this short video to learn how passkeys work:

 

Why should I use a Passkey?

Passkeys provide a faster, simpler, and more secure way to sign in.

Faster & Easier Sign-In

  • No need to type password
  • No need to approve a push notification every time
  • Sign in with a fingerprint, face scan, or device PIN
  • Fewer steps during everyday sign-ins

Better Security

  • Resistant to phishing attacks
  • Protects against stolen-password scams
  • Reduces the risk of accidental MFA approval

Useful Beyond UIC

Many banks, shopping sites, and online services are adopting passkeys. Learning how to use them at UIC can help you better protect your personal accounts as well.

What passkey options are available at UIC?

With the shift to Microsoft MFA, UIC supports a variety of passkey authentication options.

Passkey Option How it works Best For
Passkeys (Synced)
  • Stored in a supported password manager and synced across your devices.
  • Examples include Apple Passwords, Google Password Manager, Microsoft Password Manager, and Bitwarden.
  • Recommended for most clients.
  • Convenient if you use multiple devices.
  • Some privileged individuals and accounts at the university are not eligible to use synchronized passkeys.
  • Those individuals should use one of the other options listed in this table instead.
Passkeys (Device Bound)
  • Stored on a specific device and uses its built-in security features
  • Examples include Windows Hello and Microsoft Authenticator.
  • Clients who primarily sign in from the same device.
Passkey in Microsoft Authenticator
  • Stored in the Microsoft Authenticator app on your mobile device.
  • It can also be used to sign in on another device by scanning a QR code.
  • Clients who want to use their phone as their primary passkey.
  • To use a passkey in Microsoft Authenticator, your mobile device must be registered with UIC's Microsoft environment.
Physical security key
  • A physical device, such as a YubiKey, that stores your passkey and connects through USB or NFC.
  • Must be purchased separately. See Obtaining a Security Key. for purchasing information.
  • Clients who cannot use other passkey options or prefer a separate physical authentication method.

How do I choose the right MFA methods for me?

We know that no one solution works best for every individual in every situation, and so we have prepared a breakdown of the pros and cons for each option, along with our recommendations for the best experience based on different use cases.

We strongly recommend registering at least two authentication methods, so you have a backup if your primary method is unavailable.

Comparison of MFA Methods

MFA Method Pros Cons
Passkeys (Synced)
  • Fast and simple login on any device with access to the password manager
  • Does not require mobile app
  • If you don't have access to the password manager (e.g. on a shared or public computer), requires scanning QR code to use the passkey from your mobile device
Passkeys (Device Bound)
  • Fast and simple login when on the same device
  • Does not require mobile app
  • Can't be used on other devices
Passkey in Microsoft Authenticator
  • Fast and simple login when on the same mobile device
  • Requires minimum iOS 17 or Android 14
  • Requires scanning QR code to sign in on different device
Physical Security Keys
  • Fast and simple login
  • No need to enter your password
  • Does not require mobile app
  • Must be purchased
  • Must have the security key with you (e.g. on a keychain/etc) to use it
Microsoft Authenticator (without Passkey)
  • Does not require iOS 17 or Android 14
  • One-time passcodes can be used offline
  • Not passwordless - must enter password and then receive push notification to Authenticator app to sign in
Hardware Tokens
  • Supports edge uses such as command-line interfaces
  • Can be used offline
  • Must be purchased
  • Is not passwordless - must enter password and then enter the one-time passcode to sign in
  • Must have the token with you (e.g. on a keychain/etc) to use it

Recommended MFA Methods

I sign in to university resources and applications routinely on: Recommended Microsoft MFA Methods:
my personal mobile device (phone/tablet) running iOS 17+ or Android 14+ Passkey in Microsoft Authenticator and Passkeys (Synced)
my personal mobile device (phone/tablet) running below iOS 17 or Android 14 Microsoft Authenticator (without Passkey) and Passkeys (Synced)
my personal or university-issued Windows laptop Passkeys (Synced and Device Bound)
my personal or university-issued Apple laptop Passkeys (Synced)
public / shared computers  Passkey in Microsoft Authenticator and/or Physical Security Key
command-line interfaces (e.g. SSH) Hardware Token

What if I can't or don't want to use passkeys?

While we recommend shifting to passkeys for a smoother sign-in experience, alternatives remain available. When not using a passkey, you will still need to enter your university password, followed by completing an MFA prompt via one of the below options:

Microsoft Authenticator

The Microsoft Authenticator mobile app supports a passkey, but it can also be used as a push-style MFA option, where you receive a 2-digit code after entering your password and you must enter that code into your Authenticator app. Alternatively, after entering your password you can also obtain a 6-digit one-time passcode from the Authenticator app and enter it on the login screen when prompted.

Hardware Token

For particular use-cases where other solutions do not work, a C200 hardware token is available via the U of I WebStore for either personal or departmental purchase. This device provides a rotating one-time passcode that can be entered after submitting your university password.

How can I get started?

Ready to get started? Head over to How do I get started with Microsoft MFA?

Frequently Asked Questions

What should I do with the Duo app?

You will still need to use Duo to authenticate to some university services, including the VPN. Do not delete the Duo Mobile app from your device during the transition period, which lasts until April 2027. Technology Solutions and your local IT teams will provide further communications when the Duo Mobile app is no longer needed.

Can I create more than one passkey?

You can (and should) register multiple passkeys - this means if, for example, you use an Apple iPhone but also the Chrome browser on a Windows laptop, and sometimes use a computer in one of UIC's computer labs, you can:

  1. Register a passkey in Apple Passwords for use on your phone
  2. Also, register a passkey in Google Password Manager via Chrome to use on your laptop
  3. Also register the Microsoft Authenticator app to use with public machines or when you don't have your phone or laptop.

This way, you will always have access to a secure passkey option on your devices, with the Microsoft Authenticator app as a backup.

What happens if I lose my device?

Passkeys are protected by your device's security features, such as a PIN, fingerprint, or facial recognition. If your device is lost or compromised, log in to aka.ms/mfasetup and remove the sign-in method and it will not longer be usable.

Microsoft Authenticator prompted me to register my device with UIC - what does this mean?

In order for device passkeys to maintain your account security, they must register the device to associate it with your identity and with UIC's authentication systems.

Device registration is not the same as device management. Registering your personal device does not give UIC control of your device or access to your personal data.

UIC cannot:

  • View your personal files, photos, messages, or other content
  • Manage or control your device
  • Install or remove apps
  • Track your location
  • Remotely wipe your device

UIC can see limited device information, such as your device type and operating system version. Registration confirms that the device is associated with your account and allows it to be used for secure authentication.

How can I use Microsoft MFA while traveling internationally?

There are multiple Microsoft MFA methods available while traveling or with limited network access. The easiest to use is the Microsoft Authenticator app. While the passkey in the Authenticator app won't work without internet connection, the one-time passcode within the app can be used: see Signing in without a passkey and select Use a verification code at step 4.

Alternatively, if you travel regularly or for longer periods, you may benefit from purchasing and registering a Security Key or Hardware Token.

Details

Details

Article ID: 3159
Created
Wed 9/2/26 10:21 AM
Modified
Tue 9/22/26 5:05 PM

Related Articles

Related Articles (2)

This article provides a guide to getting started with Microsoft MFA by registering new devices and passkeys.
This article summarizes the different different sign-in experiences you may encounter depending on the type of Microsoft MFA you are using.

Related Services / Offerings

Related Services / Offerings (1)

Multi-Factor Authentication is a method of confirming your identity by utilizing something you know (password) AND something you have (a second factor).