Microsoft has announced changes to the specifications for authentication methods to enhance the security of multi-factor authentication (MFA).
Topics:
- Microsoft will retire SMS and voice call-based multi-factor authentication (MFA) for @u and @un Microsoft accounts on February 1, 2027.
- Additionally, messages promoting the settings of the Passkeys will be displayed when signing in after September 1, 2026.
Check and Solution:
<Subject>
Users setting the methods of authentication only below as the MFA on their @u and @un Microsoft accounts:
- SMS authentication
- Voice call-based multi-factor authentication
(For users who have registered only SMS and/or voice call-based multi-factor authentication, please set the MFA applications such as Microsoft Authenticator following as described “Solution” below.)
<How to Check Settings Status>
You can check the settings status for the MFA with the “My Account” (the link below).
https://mysignins.microsoft.com/security-info
(Viewing the security information requires authentication with the methods you have set up for MFA.)
Configuration status of multi-factor authentication apps (such as Microsoft Authenticator) other than phone number verification (SMS), voice call-based verification (phone call), and e-mail.
- Yes → No action required.
- No → Set the following MFA applications as “Solution” below.
<Solution>
Please register the Authenticators with either way as below:
(1) Set the Microsoft Authenticator apps
How to Set Up Multi-Factor Authentication for your University of Tsukuba Microsoft Account (@u, @un) Using Microsoft Authenticator
(Need to login with your UTID/PW for accessing this page)
(2) Set up multi-factor authentication using PC browser
If you want to avoid the MFA with personal devices (such as cell phone), you can use browser-based authenticators on a PC.
With Google Chrome: https://portal.cc.tsukuba.ac.jp/wp-content/uploads/MFAwithPC_GoogleChrome.pdf
With Microsoft Edge: https://portal.cc.tsukuba.ac.jp/wp-content/uploads/MFAwithPC_MicrosoftEdge.pdf
(available in Japanese only)
(Need to login with your UTID/PW for accessing these pages)
<About Passkeys>
Microsoft recommends using “Passkeys” as a more secure authentication method.
(The Passkeys are the systems that users can sign in with PIN, facial recognition or fingerprint authentication and do not have to enter passwords.)
After September 1, 2026, display to promote setting the Passkeys might be shown when signing in, but the setting of the Passkeys is not necessary at this time (you can skip).
For users who use @u Microsoft accounts:
You can currently enable or disable the MFA settings for your @u Microsoft accounts. However, it is projected that the MFA settings will be needed in future due to enhanced security requirements. Therefore, it is preferred to set the MFA such as the Microsoft Authenticator apps when this change of specifications occurs.
(MFA has already been made mandatory for @un Microsoft accounts.)
Contact:
ACCC: Inquiries Regarding EES and Microsoft 365