What is Multi-Factor Authentication?

A description of Multi-Factor Authentication (MFA) and how it is used at the University.

MFA is an approach to online security that requires you to provide more than one form of verification detail to access an account, log in or complete a transaction online.

Also known as ‘Two-step verification’, MFA adds an extra layer of protection to things you do online. It is used regularly for online transactions like banking, shopping and using payment websites like PayPal.

Signing into online services has been traditionally been done with just one type of verification factor, for example a username and password. Only using one type of verification is not very secure because usernames and passwords can be easy for cyber criminals to discover, meaning your accounts can be fraudulently accessed and your data compromised.

MFA is a more secure approach because it requires you to verify in more than one way, as an added check to ensure you are who you say you are.

Different types of verification factor include:  

  • Something you know – like a username and password  
  • Something you have – like a mobile phone or tablet on which you can receive and respond to verification requests  

For MFA to work as it is supposed to, it should involve at least two different kinds of factors to reduce the chance of fraud. Cyber criminals may be able to discover your password but they can’t easily steal your phone as well.

Why is Multi-Factor Authentication (MFA) important to you?

Using MFA significantly increases the security of accounts, and therefore helps keep your personal data, and the University’s data secure.

If MFA is used, it makes it much harder for hackers to damage University networks – they may be able to obtain account details by sending scam emails, but they would also need to be in possession of the authentication device in order to access the phished account.

What happens after Multi-Factor Authentication (MFA)Activation?

You will be asked to sign in using MFA when you access University services at least every 30 days. How often you are prompted to sign in depends on various factors, including using private web browsing, using multiple browsers and multiple devices.

Please ensure you have the phone or device you use to authenticate available to you whenever you may wish to log into University services. 

Set up a second Multi-Factor Authentication (MFA) method

You may temporarily lose access to your Microsoft 365 services and P&M if you:

  • Forget the phone or device you use for MFA
  • Lose or break the phone or device you use
  • Get a new phone or device and fail to set up MFA on a new device correctly
  • Travel away from the UK and have SMS or phone call authentication set up as your main authentication method. 

To reduce the risk of this happening, we recommend that you add a second authentication method, preferably one you can access using a different device. 

Ready to register?

Need help?

Get MFA Support