What You Need to Know About MFA (Multi-Factor Authentication)

If you are having problems and are already using MFA or are setting it up for the first time, please see our MFA troubleshooting article.


What is MFA (Multi-Factor Authentication)?

When users connect to a computer system, they are prompted for a username and a "factor" of authentication, typically a password. MFA is an enhanced security process that verifies a user's identity using more than one method. Rather than only ask for a password, MFA requires different additional credentials (codes, fingerprint, devices, etc). 

Why do we need to use MFA?

The simple answer: To make it hard for attackers to get into your account.

Attackers have lots of ways of stealing or learning your password, and they want access to your account to steal from you or others. There is a huge black market online for selling usernames and passwords because they lead to very important things (bank accounts, health information, credit cards, behavior, etc). If an attacker steals your password through phishing or other means, they are much less likely to get into your account if MFA is set up.

In recent years, there has been a massive increase in attackers trying to get into accounts—even at ONU—for extortion, ransomware, or other malicious purposes. Security experts have published many studies that prove the single most effective way of preventing these kinds of attacks is to use MFA with all your accounts.

Do I need to use MFA?

Yes, it is mandatory for Olivet email and Microsoft 365 applications.

Is my account really that important?

Absolutely. You may not realize it, but even if the only thing you have is email, your account is still valuable.


(Click image to open in a new window)

How do I set up MFA?

 

Do I need a smartphone in order to use MFA?

No. It is recommended but not required. You may use the Microsoft Authenticator app on any other mobile device. Or you can specify to be prompted via phone or text in the MFA setup process.

What if I lose my phone?

Log in with an alternate device, and remove the lost or stolen device as an authentication option. If you did not enroll multiple devices, contact the IT Help Desk for assistance. 

We encourage setting up multiple devices with the Microsoft Authenticator app in case you lose access to one of the devices. You can also provide additional contact methods such as an alternate phone number. It isn't a requirement to have the Microsoft Authenticator on multiple devices, but it can help out if there are problems getting into your account.

Am I required to use the Microsoft Authenticator app?

The Microsoft Authenticator app is not required, but it is recommended since it has the most options available and will provide the best experience. Alternatively, you can also set up your account to verify via text or phone call.

What if I get a new phone?

If you have set up multiple authentication devices and/or methods, you may install the Microsoft Authenticator app and still log in with your new phone. If you have difficulty, contact the IT Help Desk for assistance.

Should I enroll more than one device for authentication?

Yes, having at least 2 devices enrolled is helpful in case one of the devices is lost, stolen, or has a technical issue.

Am I going to be prompted for MFA verification dozens of times a day?

No. After the initial setup of your devices, it should be rare for you to be prompted multiple times.

MFA verification is most likely to occur when you connect from a new location or device. 

Security Note: All passwords must be kept confidential; we will never ask for your password.

Need Help?

If you're having issues, contact the IT Help Desk:

(815) 939-5302 | it@olivet.edu

0% helpful - 1 review
Print Article

Related Articles (3)

Please see this article for instructions on how to establish your ONU account.
Mutli-Factor Authentication (MFA) is an additional layer of security for your Olivet account. It makes your password easier to manage and adds extra security by requiring a second factor when logging in from an unknown device or if your account is being attacked.
How to get access to your account when you are having problems with the typical MFA prompts.