Summary
This article covers changes to account Single Sign-On (SSO) logins and Multi-Factor Authentication (MFA) verification methods effective as of Fall 2026.
Overview
To enhance account security, better protect against phishing and identity theft, and streamline the authentication experience, USNH made a number of changes to account logins over the summer. Going forward, you may notice:
- Single Sign-On (SSO) session lifetime reduced to 7 days
- Ability to use push-based Passwordless Authentication through the Microsoft Authenticator app
- Ability to register passkeys which are more secure than passwords
Additionally, Microsoft has launched a world-wide change to authentication that affects all members of the USNH community:
- Microsoft removing SMS text and phone calls as a method of MFA
Back to top
What is Changing?
Single Sign-On (SSO) Session Lifetime
ET&S has reduced the SSO global session length to 7 days. This small adjustment means your session will automatically expire more frequently, making it harder for unauthorized users to access your account. You may notice you are prompted to sign in a bit more often than before.
Ability to use Passwordless Sign-In through Microsoft Authenticator app
ET&S has enabled the option for push-based Passwordless Sign-In through the Microsoft Authenticator app. This enhancement provides a more streamlined sign-in experience while improving security using a stronger authentication method that reduces reliance on passwords.
- To get started, see our article on Using Passwordless Sign In through Microsoft Authenticator
- Microsoft Authenticator Passwordless sign-in is available for Windows, iOS, and Android but not currently supported on macOS devices. Mac users should continue using existing supported authentication methods.
Ability to Register Passkeys
Passkeys are a phishing-resistant method of MFA, requiring the device where the passkey is stored to be present alongside your authentication attempt. The passkey can be used from the device itself seamlessly (like your biometric login) or with the device within close proximity via Bluetooth, such as when using your phone as a passkey to access your account on a PC or Mac.
Microsoft Removing Text and Voice as Multi-Factor Authentication (MFA) Verification Methods
Microsoft is discontinuing text message (SMS) and phone call MFA verification methods and moving to more secure authentication options. MFA is the extra step used to confirm your identity when signing into your account.
Beginning in Fall 2026, Microsoft will begin prompting users who currently authenticate using text messages or phone calls to enroll in a more secure authentication method. You can click Snooze to be reminded later but eventually you will be required to register another method.
If you do not use text message or phone call verification, no additional action is required. Your other MFA methods will become the default if these are not already.
Back to top
Frequently Asked Questions (FAQ)
Questions
Q1 - Why are text messages and voice calls being removed as MFA methods?
Q2 - When is this change going into effect?
Q3 - What are my MFA options going forward?
Q4 - Are there any other options?
Q5 - Can I use these methods with multiple accounts?
Q6 - How can I MFA without using my cell phone?
Q7 - Will Microsoft store any of my personal data used for a passkey or the Microsoft Authenticator app?
Q8 - Does using the Microsoft Authenticator app (or another authentication app) on my personal cell phone give USNH access to data on my phone?
Answers
A1 - Why are text messages and voice calls being removed as MFA methods?
Microsoft is phasing out SMS text messages and voice phone call verification methods because they are less secure than newer authentication methods and are more vulnerable to phishing and account compromise.
Back to Questions
A2 - When is this change going into effect?
Starting September 1, 2026, users who currently use SMS text or voice calls for multifactor authentication (MFA) will begin receiving prompts to register Microsoft Authenticator as an MFA method. These prompts can be postponed ("snoozed") for a period of time. SMS and voice options will no longer be supported as of October 30, 2026.
Back to Questions
A3 - What are my MFA options going forward?
USNH recommends using one of the following more secure authentication methods:
- Microsoft Authenticator on a smartphone or tablet
- A passkey stored on a supported device
- A YubiKey security key
Back to Questions
A4 - Are there any other options?
Yes. While these options provide less phishing resistance than the methods listed above, you may also use:
- A Time-based One-Time Passcode (TOTP) application
- An alternative authenticator app, such as Google Authenticator
Back to Questions
A5 - Can I use these methods with multiple accounts?
Yes. Some USNH administrators and others in similar roles may have multiple accounts. Based on our testing, Microsoft Authenticator, passkeys, and YubiKeys all support use with multiple accounts.
Back to Questions
A6 - How can I MFA without using my cell phone?
There are several options:
- Use a passkey stored on the device where you need to log in (free).
- Use a passkey stored on a physical security key like YubiKey (cost to purchase, free to use).
- See instructions for how to create and store passkeys.
- Use the Microsoft Authenticator app or another authenticator app on an iPad or Android tablet instead of on a cell phone.
Back to Questions
A7 - Will Microsoft store any of my personal data used for a passkey or the Microsoft Authenticator app?
The Microsoft Authenticator app collects account information needed for accounts you add, limited non-personally identifiable usage data, and diagnostic logs if you send feedback. Location is requested only when an administrator has created a policy requiring it, in which case country and location coordinates are sent to determine access location. The actual location coordinates are not stored on Microsoft or USNH servers.
Passkey data is stored encrypted and stored locally on the device in which it was generated unless you choose to sync it with a passkey service like iCloud Passwords & Keychain or Google Password Manager.
Back to Questions
A8 - Does using the Microsoft Authenticator app (or another authentication app) on my personal cell phone give USNH access to data on my phone?
No. Using a mobile app for authentication does not enroll your mobile device in any USNH device management or inventory process. The data is fully protected by any password, PIN, or biometric options you have on your mobile device. The data collected by the app is shared with the app provider as needed to verify your identity. See A7 above on what data Microsoft Authenticator will store.
Back to Questions
Back to top
Further Readings
MFA: Installing the Microsoft Authenticator App
MFA: Setting up the Microsoft Authenticator App for M365
MyAccount: Managing Account Verification Methods
MFA: Adding Backup Multi-Factor Authentication (MFA) Methods
MFA: Choosing a preferred method of Multi-Factor Authentication (MFA) for M365
MFA: Using Passwordless Sign In through Microsoft Authenticator
MFA: Setting up YubiKey for Microsoft Authentication
Windows Hello: Configuring Windows Hello on Managed Windows Computers
Back to top
Need additional help?
Visit the Technology Help Desk Support page to locate your local campus contact information or to submit an online technology support request. For password issues you must call or visit the Help Desk in person.