Penn State & Microsoft To Change Multifactor Authentication Options

Microsoft is set to discontinue Short Message Service (SMS) text and phone Multifactor Authentication (MFA) options for all Penn State account holders starting on February 1, 2027, according to a Penn State mass email sent on Tuesday morning.
The move will introduce other phishing-resistant MFA methods, such as passkeys. The change affects how Penn State students, faculty, and staff log into Outlook, Canvas, LionPATH, Workday, and more.
All Penn State account holders will need to change their primary MFA sign-in method beginning September 1. There will be a prompt set upon login that will continue to show up until the change is made.
Penn State recommends that account holders set up a passkey, which the school says is the most phishing-resistant form of MFA.
Passkeys range from Face ID, Touch ID, fingerprint, and PIN, and are meant to provide extra protection from cyberattacks as information that cannot be easily stolen. Account holders will no longer have to enter their password when logging in to their accounts, unless they are on a lab computer or classroom podium.
“Unlike traditional MFA methods that use SMS text message codes or a call to a cellphone or landline home or office phone to sign in with a code, it helps prevent scammers from tricking you into approving the phone call and giving away your login information. This is increasingly important in this AI era. Furthermore, while Microsoft Authenticator push notifications and number matching provide strong account security, they are not considered truly phishing-resistant,” the email said.
Penn State IT said additional details, along with other phishing-resistant MFA options and setup instructions, will be rolled out in the coming weeks.
Your ad blocker is on.
Please choose an option below.
Purchase a Subscription!
