Changes to Multi-Factor Authentication (MFA) at UNC Asheville
UNC Asheville is changing the authentication methods used to protect University accounts. Users who currently rely on SMS text messages or voice phone calls for multi-factor authentication (MFA) will need to transition to Microsoft Authenticator or an approved security key.
Important Dates
September 9, 2026: UNCA will begin prompting affected users to register Microsoft Authenticator when signing in.
October 12, 2026: UNCA will no longer support SMS text messages or voice phone calls as MFA methods. Users who have not registered Microsoft Authenticator or an approved security key may be unable to access UNCA systems until registration is completed.
Why is this changing?
Microsoft is moving organizations away from SMS text messages and voice calls for authentication because these methods provide weaker protection against phishing and account compromise than modern authentication methods.
Who is affected?
You need to take action if you currently use a:
-
Text message sent to your phone to approve an MFA request; or
-
Voice phone call to approve an MFA request.
If you already use Microsoft Authenticator for MFA, you do not need to register Authenticator again.
However, you may still receive a separate prompt asking you to register or update information used for password recovery. This is separate from MFA.
What do I need to do?
Beginning September 9, affected users may receive a prompt while signing in to UNCA cloud applications such as OnePort or Google Workspace.
The prompt will guide you through registering Microsoft Authenticator.
You will need:
-
A compatible mobile device.
-
The Microsoft Authenticator app installed on that device.
-
Access to your UNCA account during registration.
Microsoft Authenticator is available for iOS and Android.
When prompted during sign-in, follow the instructions displayed on the screen to complete registration. Microsoft also provides instructions for registering security information from the sign-in page.
You can also review and manage your registered authentication methods through Microsoft's Security Info page.
Manage your Microsoft Security Info
Can I skip the registration prompt?
For a limited time, affected users will be able to postpone registration and continue signing in.
Do not wait until the deadline if you can complete registration now.
Beginning October 12, 2026, UNCA will require affected users to have Microsoft Authenticator or an approved security key registered. Users who have not completed registration may be unable to access UNCA systems until an approved method is registered.
Why am I being asked for my personal email address?
Some users may also be asked to provide a personal email address during the security-information registration process.
This is not an MFA method.
A personal email address can be used as a password-recovery method through Microsoft's Self-Service Password Reset system. For example, it may help you verify your identity if you forget your UNCA password.
Microsoft identifies email as a password-reset authentication method and not as a method for completing MFA.
Registering a personal email address with Microsoft for password recovery does not give UNCA access to your personal email account or mailbox. Microsoft states that authentication contact information is not published in the organization's global directory; it is visible to the user and authorized administrators.
What if I do not want to use or cannot use Microsoft Authenticator on a personal mobile device?
A personal mobile device is not the only option.
UNCA also supports approved FIDO2 security keys as an authentication method.
A security key is a small physical device that is connected to or tapped against your computer when you need to authenticate. Depending on the model, security keys may use USB, NFC, or other supported interfaces.
Microsoft describes FIDO2 security keys as device-bound passkeys whose private credentials remain on the physical key, providing strong protection against remote phishing attacks.
Only purchase or use a security key approved by UNCA ITS. ITS cannot guarantee compatibility with devices that have not been approved.
Approved UNCA Security Keys:
Link
If you are unsure whether a security key will work for your situation, contact the ITS Service Desk before purchasing one.
Microsoft provides additional information about registering and using security keys with work or school accounts.
Does installing Microsoft Authenticator give UNCA access to my personal phone?
No. Registering Microsoft Authenticator for MFA does not give UNCA access to the contents of your personal phone, such as your photographs, text messages, personal applications, or personal email.
Authenticator is used to verify that you are the person attempting to access your UNCA account.
What if I already use Microsoft Authenticator?
If Microsoft Authenticator is already registered for MFA on your UNCA account, you do not need to register it again.
You may still receive a prompt to register additional security information if your account does not currently have the information required for password recovery.
Microsoft uses a combined security-information registration experience for MFA and Self-Service Password Reset, so authentication and password-recovery information may be requested through the same registration process.
What happens if I do nothing?
Beginning October 12, 2026, SMS text messages and voice calls will no longer be supported by UNCA as MFA methods.
If one of these is your only registered MFA method and you have not registered Microsoft Authenticator or an approved security key, you may be unable to sign in to UNCA systems until an approved authentication method is registered.
We strongly recommend completing registration as soon as you receive the prompt.
What if I need help?
If you have trouble registering Microsoft Authenticator, cannot use a mobile device, need assistance with a security key, or are unable to access your account, contact the UNC Asheville ITS Service Desk.
Microsoft References
The following Microsoft documentation provides additional information about these changes and supported authentication methods:
Setting up security information during sign-in
Microsoft Support — Set up Security info from a sign-in page
View Microsoft instructions
Microsoft Authenticator
Microsoft Learn — Microsoft Authenticator authentication method
View Microsoft Authenticator documentation
FIDO2 security keys
Microsoft Support — Set up a security key as your verification method
View Microsoft security key instructions