MFA

What’s MFA (Multifactor Authentication)?

Microsoft multifactor authentication works by requiring two or more of the following authentication methods:

  • Something you know, typically a password.
  • Something you have, such as a trusted device that’s not easily duplicated, like a phone or hardware key.
  • Something you are – biometrics like a fingerprint or face scan.

In many cases you are already using this in situations like a bank machine, your fingerprint or face recognition on your phone, or your banking where you need to enter a generated code that is sent to you.

When will it be required for staff?

We will be configuring Microsoft MFA for staff to prompt when you are not in a school or when you log in on a new or unrecognized device. Using your regular device while in a school should let you in to Microsoft tools without MFA when complete.

Three Ways to MFA with Microsoft

  1. Microsoft Authenticator on a mobile device – Most secure and recommended
  2. Passkey setup with your mobile device
  3. Physical security key (eg YubiKey)

Download the app on your mobile device – https://www.microsoft.com/en-ca/security/mobile-authenticator-app

Learn More

What is Multifactor Authentication? https://support.microsoft.com/en-us/topic/what-is-multifactor-authentication-e5e39437-121c-be60-d123-eda06bddf661

Microsoft MFA – https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-howitworks

Trusted Networks

After the first MFA sign up, staff working in schools should rarely receive a request for a multi factor response on their regular device from Microsoft tools as the school networks are recognized as a trusted network. If staff are working off-site, travelling, using a new computer, or switching buildings, they may receive an MFA prompt. This should limit dramatically the number of times people may have to complete the MFA prompt process.