MFA: Fall 2026 Changes FAQ

Summary

This article covers changes to account Single Sign-On (SSO) logins and Multi-Factor Authentication (MFA) verification methods effective as of Fall 2026.

 

Overview

To enhance account security, better protect against phishing and identity theft, and streamline the authentication experience, USNH made a number of changes to account logins over the summer.  Going forward, you may notice:

  • Single Sign-On (SSO) session lifetime reduced to 7 days
  • Ability to use push-based Passwordless Authentication through the Microsoft Authenticator app
  • Ability to register passkeys which are more secure than passwords

Additionally, Microsoft has launched a world-wide change to authentication that affects all members of the USNH community:

  • Microsoft removing SMS text and phone calls as a method of MFA

Back to top

 

What is Changing?

Single Sign-On (SSO) Session Lifetime

ET&S has reduced the SSO global session length to 7 days. This small adjustment means your session will automatically expire more frequently, making it harder for unauthorized users to access your account. You may notice you are prompted to sign in a bit more often than before.

 

Ability to use Passwordless Sign-In through Microsoft Authenticator app

ET&S has enabled the option for push-based Passwordless Sign-In through the Microsoft Authenticator app. This enhancement provides a more streamlined sign-in experience while improving security using a stronger authentication method that reduces reliance on passwords.

  • To get started, see our article on Using Passwordless Sign In through Microsoft Authenticator 
  • Microsoft Authenticator Passwordless sign-in is available for Windows, iOS, and Android but not currently supported on macOS devices. Mac users should continue using existing supported authentication methods.

 

Ability to Register Passkeys

Passkeys are a phishing-resistant method of MFA, requiring the device where the passkey is stored to be present alongside your authentication attempt. The passkey can be used from the device itself seamlessly (like your biometric login) or with the device within close proximity via Bluetooth, such as when using your phone as a passkey to access your account on a PC or Mac.

 

Microsoft Removing Text and Voice as Multi-Factor Authentication (MFA) Verification Methods

Microsoft is discontinuing text message (SMS) and phone call MFA verification methods and moving to more secure authentication options. MFA is the extra step used to confirm your identity when signing into your account.

Beginning in Fall 2026, Microsoft will begin prompting users who currently authenticate using text messages or phone calls to enroll in a more secure authentication method. You can click Snooze to be reminded later but eventually you will be required to register another method.

If you do not use text message or phone call verification, no additional action is required. Your other MFA methods will become the default if these are not already.

Back to top

 

Frequently Asked Questions (FAQ)

Questions

Q1Why are text messages and voice calls being removed as MFA methods?

Q2 - When is this change going into effect?

Q3 - What are my MFA options going forward?

Q4 - Are there any other options?

Q5 - Can I use these methods with multiple accounts? 

Q6 - How can I MFA without using my cell phone? 

Q7Will Microsoft store any of my personal data used for a passkey or the Microsoft Authenticator app? 

Q8Does using the Microsoft Authenticator app (or another authentication app) on my personal cell phone give USNH access to data on my phone? 

 

Answers

A1 - Why are text messages and voice calls being removed as MFA methods?

Microsoft is phasing out SMS text messages and voice phone call verification methods because they are less secure than newer authentication methods and are more vulnerable to phishing and account compromise.

Back to Questions

 

A2 - When is this change going into effect?

Starting September 1, 2026, users who currently use SMS text or voice calls for multifactor authentication (MFA) will begin receiving prompts to register Microsoft Authenticator as an MFA method. These prompts can be postponed ("snoozed") for a period of time.  SMS and voice options will no longer be supported as of October 30, 2026.

Back to Questions

 

A3 - What are my MFA options going forward?

USNH recommends using one of the following more secure authentication methods:

  • Microsoft Authenticator on a smartphone or tablet
  • A passkey stored on a supported device
  • A YubiKey security key 

Back to Questions

 

A4 - Are there any other options?

Yes. While these options provide less phishing resistance than the methods listed above, you may also use:

  • A Time-based One-Time Passcode (TOTP) application
  • An alternative authenticator app, such as Google Authenticator 

Back to Questions

 

A5 - Can I use these methods with multiple accounts?

Yes. Some USNH administrators and others in similar roles may have multiple accounts. Based on our testing, Microsoft Authenticator, passkeys, and YubiKeys all support use with multiple accounts.

Back to Questions

 

A6 - How can I MFA without using my cell phone?

There are several options:

  • Use a passkey stored on the device where you need to log in (free).
  • Use a passkey stored on a physical security key like YubiKey (cost to purchase, free to use). 
    • See instructions for how to create and store passkeys.
  • Use the Microsoft Authenticator app or another authenticator app on an iPad or Android tablet instead of on a cell phone.

Back to Questions

 

A7 - Will Microsoft store any of my personal data used for a passkey or the Microsoft Authenticator app?

The Microsoft Authenticator app collects account information needed for accounts you add, limited non-personally identifiable usage data, and diagnostic logs if you send feedback. Location is requested only when an administrator has created a policy requiring it, in which case country and location coordinates are sent to determine access location. The actual location coordinates are not stored on Microsoft or USNH servers. 

Passkey data is stored encrypted and stored locally on the device in which it was generated unless you choose to sync it with a passkey service like iCloud Passwords & Keychain or Google Password Manager.

Back to Questions

 

A8 - Does using the Microsoft Authenticator app (or another authentication app) on my personal cell phone give USNH access to data on my phone? 

No. Using a mobile app for authentication does not enroll your mobile device in any USNH device management or inventory process.  The data is fully protected by any password, PIN, or biometric options you have on your mobile device. The data collected by the app is shared with the app provider as needed to verify your identity.  See A7 above on what data Microsoft Authenticator will store.

Back to Questions
 

Back to top 

 

Further Readings

MFA: Installing the Microsoft Authenticator App 

MFA: Setting up the Microsoft Authenticator App for M365

MyAccount: Managing Account Verification Methods

MFA: Adding Backup Multi-Factor Authentication (MFA) Methods

MFA: Choosing a preferred method of Multi-Factor Authentication (MFA) for M365

MFA: Using Passwordless Sign In through Microsoft Authenticator 

MFA: Setting up YubiKey for Microsoft Authentication

Windows Hello: Configuring Windows Hello on Managed Windows Computers

Back to top 

 

Need additional help?

Visit the Technology Help Desk Support page to locate your local campus contact information or to submit an online technology support request.  For password issues you must call or visit the Help Desk in person.