Available Multifactor Authentication Options


Starting February 1, 2027, Microsoft will no longer be offering SMS (text message) and phone calls as options for multifactor authentication (MFA, also known as two-step log in). To prepare for this vendor-driven change, UMass IT has removed SMS and phone calls as available MFA options for new accounts as of Friday, August 14, 2026.

Method  

What It Is  

Requires Smartphone?  

Passwordless?  

Self-Service Reset Password? 

Recommended For  

Potential Challenges 

Microsoft Authenticator Push  

Approve a notification in App after entering your password.  

Yes  

No  (can be passwordless but isn't by default)

Yes (but not with MS Auth App OTP) 

Most users  

Requires phone access and app setup on replacement phones.  

Passkey in Microsoft Authenticator  

Sign in using the Authenticator app and your phone biometric or PIN instead of a password.  

This is a phishing resistant multi-factor authentication method.

Yes  

Yes  

No 

Most users  

Replacing or resetting your phone will require re-registering the passkey.  

Need to have Bluetooth enabled on mobile device and the endpoint used for login. 

Windows Hello for Business  

Use Windows PIN, fingerprint, or facial recognition.  

This is a phishing resistant multi-factor authentication method.

No  

Yes  

No 

University-managed Windows users  

Requires university managed device. 

Replacement computers require re-enrollment.  

 

FIDO2 Security Key  

Physical security key such as a YubiKey.  

No  

Yes  

No 

Users wanting strong security without a phone  

If the key is lost or damaged, you need a backup method.  

Software OTP Application  

Authenticator or password manager generates temporary codes.  (MS Authenticator, Google Authenticator, Outlook [iOS, Android] if MS Auth App not on device) 

Optional  

No  

Yes (but not with MS Auth App push) 

Password manager users  

Codes may need to be restored after device replacement.  

Hardware OTP Token  

Physical token that displays a temporary code.  

No  

No  

Yes 

Users without smartphones  

Lost, damaged, or expired tokens must be replaced.  

Passkey in Browser 

A passkey stored in your web browser, such as Chrome or Firefox 

No 

No 

No 

Users without a phone. You should not store your passkey outside of your UMass account/browser profile or login. 

Syncing the Passkey stored in a browser to multiple computers could expose the key if one of the computers is compromised. 


If you have questions regarding any of these options, please contact the IT Service Desk: it@umass.edu or 413-545-9400 Option 1.