Multifactor Authentication (MFA) with Microsoft Entra MFA

IMPORTANT: Current students, faculty, and staff should use Duo as their primary multi-factor authentication service. For more information and instructions on how to set up and use Duo, please visit Multifactor Authentication with Duo: Setup, Methods, and Troubleshooting.

Multi-factor authentication, or MFA, adds another layer of security to your Pitt account by requiring two or more  “factors” to verify your identity:

  • Something you know: A password, PIN, or personal security questions.
  • Something you have: A mobile phone, security key, or smart card that generates or receives a one-time code or serves as a physical key.
  • Something you are: Biometric authentication such as fingerprints or facial recognition.

While Duo is the University's primary MFA service for Pitt Passport, some select Microsoft cloud applications and services provided by the University of Pittsburgh are additionally protected by Microsoft Entra MFA. 

Since October 2024, Microsoft now requires Entra MFA for access to the following:

For more information on Microsoft's mandatory MFA requirements, please see Microsoft's MFA documentation for Azure

Contents

 

Authentication Options

1NOTE: As of February 1, 2027., Microsoft will be retiring SMS and voice call based authentication methods in Entra MFA and they will no longer available for use.  Beginning September 1, 2026, SMS and voice users will begin to be prompted when signing in to an Entra MFA protected application to register a stronger method, such as a Passkey or the Microsoft Authenticator app. For additional information, please see Passkeys by default and retirement of Microsoft-provided SMS and voice authentication.

Pitt Digital strongly recommends registering at least one application-based or phishing-resistant method, such as a Passkey or the Microsoft Authenticator app, before this date to maintain access to your account. 

The authentication methods available through Entra MFA can be organized into three categories based on their relative strength, or their ability to resist attacks. The below table lists these categories In order from strongest to weakest.

Authentication Method Strengths

Category Description Examples
Phishing-resistant Device-bound cryptographic authentication that resists credential theft and phishing attacks Passkey, Windows Hello for Business, Apple Keychain, FIDO2 Security Key
Application-based Authentication performed through a trusted application or token. Provides a better user experience and greater resistance to account compromise than phone-based methods Microsoft Authenticator, Duo Push, Software OATH Tokens
Phone-based & recovery Authentication that relies on phone numbers, voice networks, email, or temporary recovery credentials. Primarily retained for compatibility, recovery, and users who can not yet use modern authentication methods. SMS, voice calls, email OTP, temporary access pass

Microsoft Entra MFA currently supports the following options for authentication. 

Available Authentication Methods

Method Strength
Passkey (FIDO)1 (Microsoft default as of September 1, 2026) Phishing-resistant
Microsoft Authenticator Application-based
Software OATH token Application-based
SMS1 (unavailable after February 1, 2027) Phone-based & recovery
Voice call1 (unavailable after February 1, 2027) Phone-based & recovery

Getting started with the Microsoft Authenticator app

  1. If Entra MFA is required for your sign in and you have not yet set up ,  you will be prompted with a “More information required” message similar to the screen shot below. Click the Next button to begin the set-up process.

Uploaded Image (Thumbnail)

  1. Alternatively, browse to My Sign-Ins and log in with your Pitt Passport user name and password. Click the Add sign-in method button and then select Authenticator app from the drop-down menu to continue.
  2. Before continuing, download and install the Microsoft Authenticator app on your iOS or Android smart phone. Once installed, click Next to continue. 

Uploaded Image (Thumbnail)Uploaded Image (Thumbnail)

  1. Open the Microsoft Authenticator app on your smart phone. IMPORTANT: If prompted, allow notifications.  
  2. Follow the on-screen prompts to add an account, and select “Work or school account” and then “Scan QR code.

Uploaded Image (Thumbnail)

  1. Return to the setup wizard and click the Next button.

Uploaded Image (Thumbnail)

  1. Use your smart phone’s camera to scan the displayed QR code and connect your account with the Microsoft Authenticator app.

Uploaded Image (Thumbnail)

  1. You should now see University of Pittsburgh listed in the Microsoft Authenticator app with your email address.

Uploaded Image (Thumbnail)

  1. Click the Next button in the setup wizard to continue.
  2. The wizard will now test to make sure your account is configured correctly. Note the number displayed at the bottom of the window.

Uploaded Image (Thumbnail)

  1. Open the Microsoft Authenticator app and you should see a prompt asking “Are you trying to sign in?”. Confirm that this prompt includes University of Pittsburgh and your Pitt Passport email address, enter the number provided by the setup wizard into the text box, and press Yes.

Uploaded Image (Thumbnail)

  1. If successful, the setup wizard will confirm that the notification was approved. Click the Next button.

Uploaded Image (Thumbnail)

  1. Click the Done button to complete the enrollment process.

Uploaded Image (Thumbnail)

Congratulations! Your account is now protected with Microsoft Authenticator for MFA!

The next time you sign in to a University service that requires Microsoft Authenticator for MFA, such as the Azure administration portal, you may be prompted on your smart device to approve the sign in request from the Microsoft Authenticator app. Open the app and enter the number shown to complete the sign in process.

Please see the Work/school account tab at the following link for more information: Microsoft - How to add your accounts to Microsoft Authenticator

Register a Passkey

On devices that you use regularly, it is highly recommended to register a passkey to secure your account using phishing-resistant protections.

Please see the Work/school account tab at the following link for detailed instructions on adding a passkey to your account.

Microsoft - Create and save a passkey

Tip: Save passkeys in 1Password for cross-device access.
When a website or app offers to create a passkey, 1Password can store it in your vault instead of locking it to a single device. This is especially valuable if you use multiple computers or travel frequently. See Passkeys in 1Password for supported sites and setup details.

Add a phone number (being retired)

As of February 1, 2027., Microsoft will be retiring phone-based authentication methods such as SMS and voice call. Pitt Digital highly recommends registering a stronger method, such as a Passkey or the Microsoft Authenticator app, before this date to maintain access to your account. For additional information, please see Passkeys by default and retirement of Microsoft-provided SMS and voice authentication.

  1. Open a web browser and navigate to Outlook.
  2. Sign in with your Pitt Passport account.
  3. In the upper right corner of the window, click on your name and then the “View account” link.

Uploaded Image (Thumbnail)

  1. Click Security info on the left navigation bar.

Uploaded Image (Thumbnail)

  1. Click Add sign-in method.

Uploaded Image (Thumbnail)

  1. Select Phone from the drop down menu and then click the Add button.

Uploaded Image (Thumbnail)

  1. Select your country code, enter the phone number you wish to use in the space provided, and then select the method you wish to use to verify that the number entered is yours:
  • Receive a code – You will receive an SMS text message at the number provided with a one time access code.

  • Call me – You will receive a phone call with instructions on how to complete the verification process.

    Uploaded Image (Thumbnail)
  1. Click the Next button to begin the verification process. If Receive a code was selected, enter the 6 digit code that was sent to you via SMS text message into the prompt. If Call me was selected, answer the phone call and follow the voice prompts to complete the process.

Uploaded Image (Thumbnail)Uploaded Image (Thumbnail)

 

Approving Sign in Requests

Once your account has been set up for MFA with Microsoft Authenticator, you may be required to approve sign in requests after using your user name and password to sign in to Pitt Passport.

There are several options available for approving sign in requests with Entra MFA, including:

  1. Passkey
  2. Microsoft Authenticator Push Notification
  3. Microsoft Authenticator one-time passcode (OTP)
  4. SMS Text Message (being retired)
  5. Voice Call (being retired)

 

Passkey

Please see Microsoft's guidance on how to Sign in with a synced passkey (FIDO2)

 

Microsoft Authenticator Push Notification

  1. Upon being prompted to “Approve sign in request”, a number will be displayed and a notification sent to the Microsoft Authenticator app on your smart phone.

Uploaded Image (Thumbnail)

Uploaded Image (Thumbnail)

  1. Open the Microsoft Authenticator app and you will be asked to confirm that you are trying to sign in with your University of Pittsburgh account.

Uploaded Image (Thumbnail)

  1. Enter the number that was provided and press Yes to complete the sign in process

 

Microsoft Authenticator One-Time Passcode (OTP)

If you do not receive the push notification or are not automatically prompted within the Microsoft Authenticator app, you can use a temporary, one-time passcode to confirm your identity and complete the sign in process.

  1. When prompted to approve your sign in request, click the link for “I can’t use my Microsoft Authenticator app right now”.

Uploaded Image (Thumbnail)

  1. You will be presented with a list of alternative methods to approve the request. Click on “Use a verification code”.

Uploaded Image (Thumbnail)

  1. You will be prompted to enter a code to continue.

Uploaded Image (Thumbnail)

  1. Open the Microsoft Authenticator app on your smart phone and open the entry for University of Pittsburgh and your Pitt Passport email address. 

Uploaded Image (Thumbnail)

  1. Enter the six-digit number shown under “One-time password code" into the “Enter code” prompt and click the Verify button to complete the sign in process. IMPORTANT: Note the small timer to the left of the code in the Microsoft Authenticator app. When this timer reaches 0, the displayed code will no longer be valid and a new code will be automatically provided.

Uploaded Image (Thumbnail)

 

SMS Text Message (being retired)

If you have registered a phone number with your account and the Microsoft Authenticator app is not available to you, you can elect to receive an SMS text message to verify your identity and approve the sign in request.

  1. When prompted to approve your sign in request, click the link for “I can’t use my Microsoft Authenticator app right now”.

Uploaded Image (Thumbnail)

  1. You will be presented with a list of alternative methods to approve the request. Click on “Text +X XXXXXXXXXX”.

Uploaded Image (Thumbnail)

  1. Enter the code sent via SMS text message and click the Verify button to approve the request.​​​​​​​

Uploaded Image (Thumbnail)

 

Phone Call (being retired)

If you have registered a phone number with your account and the Microsoft Authenticator app is not available to you, you can elect to receive a phone call to verify your identity and approve the sign in request.

  1. When prompted to approve your sign in request, click the link for “I can’t use my Microsoft Authenticator app right now”.​​​​​​​

Uploaded Image (Thumbnail)

  1. You will be presented with a list of alternative methods to approve the request. Click on “Call +X XXXXXXXXXX”.​​​​​​​

Uploaded Image (Thumbnail)

  1. Answer the phone call from +1 (855) 330-8653 and follow the voice instructions to approve the request.​​​​​​​

Uploaded Image (Thumbnail)

 

Reporting Fraud

IMPORTANT: If you are prompted to approve a sign in request and are not certain of the reason, it's important to deny the request and report it as fraudulent to protect your account from unauthorized​​​​​​​ activity.

  1. If you are prompted by Microsoft Authenticator to approve a sign in request that you do not recognize, press the No, it's not me button.​​​​​​​

Uploaded Image (Thumbnail)

  1. You will then be asked if you want to Report suspicious activity. Press Report to deny the sign in request and report the sign in attempt as fraudulent to Pitt Digital. A member of the Pitt Digital Security team may contact you for additional information.​​​​​​​

Uploaded Image (Thumbnail)

If you receive ANY unexpected SMS text messages providing verification codes or voice calls asking to confirm sign in activity for your Pitt Passport account, DO NOT APPROVE these requests and immediately contact the Pitt Digital Help Desk to report the fraudulent activity.

 

Adding Additional Devices

  1. Open a web browser and navigate to Outlook.
  2. Sign in with your Pitt Passport account.
  3. In the upper right corner of the window, click on your name and then the “View account” link.​​​​​​​

Uploaded Image (Thumbnail)

  1. Click Security info on the left navigation bar.​​​​​​​

Uploaded Image (Thumbnail)

  1. Click Add sign-in method.​​​​​​​

Uploaded Image (Thumbnail)

  1. Select Authenticator app from the drop down menu in the prompt that appears and then click the Add button.​​​​​​​

Uploaded Image (Thumbnail)

  1. Download the Microsoft Authenticator app on the new device and follow the on screen instructions to complete the set up process.​​​​​​​

Uploaded Image (Thumbnail)

 

Removing a device

If a device set up to approve your sign in requests, either with the Microsoft Authenticator app, SMS message, or phone call, is lost, stolen, replaced, or otherwise no longer available to you, it is important to timely update your account information and remove that device to maintain the security and integrity of your Pitt Passport account.​​​​​​​

  1. Open a web browser and navigate to Outlook.
  2. Sign in with your Pitt Passport account.
  3. In the upper right corner of the window, click on your name and then the “View account” link.​​​​​​​

Uploaded Image (Thumbnail)

  1. Click Security info on the left navigation bar.​​​​​​​

Uploaded Image (Thumbnail)

  1. Locate the device you wish to remove in the list of sign-in methods and click the Delete link to remove it from your account.​​​​​​​

Uploaded Image (Thumbnail)

  1. Click the link to Sign out everywhere to ensure the removed device can no longer be used with your account and your data is protected.​​​​​​​

Uploaded Image (Thumbnail)

 

Troubleshooting

Please contact the Pitt Digital Help Desk for any questions, issues, or concerns related to using the Microsoft Authenticator app with your Pitt Passport account.​​​​​​​

Print Article

Related Articles (2)

Explains Pitt's multifactor authentication (Duo and Microsoft Authenticator) and single sign-on services (Pitt Passport, HSConnect), and how people with both Pitt and UPMC accounts can avoid browser sign-in conflicts when moving between them. Links to Duo and Microsoft Authenticator setup and troubleshooting.
Register, replace, or remove a Duo Mobile device for multifactor authentication with Pitt Passport, compare authentication methods, and enroll phishing-resistant options including passkeys, FIDO2 security keys, 1Password, and Windows Hello. Covers what to expect at login, how to report a fraudulent sign-in request, and troubleshooting steps for common Duo issues.

Related Services / Offerings (1)

IDENTITY AND ACCESS MANAGEMENT Duo provides multifactor authentication to add another layer of security to your online accounts.