What’s MFA (Multifactor Authentication)?
Microsoft multifactor authentication works by requiring two or more of the following authentication methods:
- Something you know, typically a password.
- Something you have, such as a trusted device that’s not easily duplicated, like a phone or hardware key.
- Something you are – biometrics like a fingerprint or face scan.
In many cases you are already using this in situations like a bank machine, your fingerprint or face recognition on your phone, or your banking where you need to enter a generated code that is sent to you.
When will it be required for staff?
We will be configuring Microsoft MFA for staff to prompt when you are not in a school or when you log in on a new or unrecognized device. Using your regular device while in a school should let you in to Microsoft tools without MFA when complete.
Three Ways to MFA with Microsoft
- Microsoft Authenticator on a mobile device – Most secure and recommended
- Passkey setup with your mobile device
- Physical security key (eg YubiKey)
Download the app on your mobile device – https://www.microsoft.com/en-ca/security/mobile-authenticator-app
Learn More
What is Multifactor Authentication? https://support.microsoft.com/en-us/topic/what-is-multifactor-authentication-e5e39437-121c-be60-d123-eda06bddf661
Microsoft MFA – https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-howitworks
Trusted Networks
After the first MFA sign up, staff working in schools should rarely receive a request for a multi factor response on their regular device from Microsoft tools as the school networks are recognized as a trusted network. If staff are working off-site, travelling, using a new computer, or switching buildings, they may receive an MFA prompt. This should limit dramatically the number of times people may have to complete the MFA prompt process.

