This article contains general information pertaining to Microsoft Authenticator and Multi-Factor Authentication (MFA) as a concept. Frequently Asked Questions (FAQs) regarding Microsoft Authenticator / MFA are also present within this article. Multi-Factor Authentication with Microsoft Authenticator will be required for faculty, staff, and students starting October 30th, 2026.
Table of Contents
Overview

Multi-Factor Authentication (MFA) adds an additional layer of security to your university account. Instead of relying solely on a password (which can be guessed, stolen, or compromised in a data breach), MFA requires you to verify your identity using two or more distinct factors:
- Something you know: Your Oakland University NetID password.
- Something you have: A registered trusted device, such as a smartphone with an authenticator app, a physical security key, or an external email address.
- Something you are: Biometric verification, such as a fingerprint or face scan on a compliant device.
Higher education institutions like Oakland University are prime targets for cyberattacks, including phishing, credential harvesting, and ransomware. We want to help keep you safe from these threats. MFA protects both individual users and the University as a whole:
- Prevent Account Takeovers: Over 99% of automated account attacks are blocked by enabling Multi-Factor Authentication.
- Protect Sensitive Data: Ensures that academic records, personal information, payroll details, and research data remain confidential.
- Maintain Compliance: Meets cybersecurity industry standards, federal privacy regulations (such as FERPA), and university insurance policies.

Oakland University supports several authentication factors/methods registered through Microsoft Entra ID:
| Method |
Type |
Description |
Recommended For |
| Microsoft Authenticator (Push / Number Matching) |
App-based |
Sends a push notification to your smartphone with a 2-digit number match. |
Primary (Recommended) |
| Email One-Time-Password (OTP) |
Email |
Sends a verification code via an email to an alternate email account that you control. |
Secondary backup factor option (Recommended) |
| Passkeys / FIDO2 Security Key* |
Hardware / Biometric |
Uses a USB hardware key (e.g., YubiKey) or device biometrics (Windows Hello / Touch ID).** |
Phishing-resistant security |
| Hardware Tokens* (TOTP) |
Device-based |
Generates a 6-digit rolling code (Google Authenticator, 1Password, Duo, etc.). |
Offline or backup access |
* - These methods are not available to all users.
**- Oakland University does not currently support Windows Hello on university-owned Windows-based workstations, or Touch ID on university-owned macOS-based workstations.
How do I register my methods?
You will be prompted to register for Microsoft Authenticator and an alternate email address starting in late October 2026. The following Knowledge Base articles detail the registration further:
Why do I need to enter a number every time I approve an MFA request?
With our previous Multi-Factor Authentication system, DUO, users may have found it easier to simply approve a push notification. Microsoft Authenticator uses number matching in the application because a simple “Approve” push is vulnerable to MFA fatigue attacks. An attacker who has your password can repeatedly send login prompts until you accidentally approve one. Entering the number confirms that you initiated the specific sign-in.
It’s a small inconvenience, but it helps prevent:
- Accidental approval of someone else’s login
- Repeated push-spam attacks
- Attackers tricking you over the phone into approving a request
What methods do I need to register?
We require two Multi-Factor methods: an alternate email address and the Microsoft Authenticator application. You will sometimes be prompted to verify your identity with Microsoft Authenticator when logging in to Oakland University online services.
When attempting to reset your Oakland University password with the Self-Service Password Reset utility, you will need to use Microsoft Authenticator and a mobile device.
Do I need to use MFA when logging into my Oakland University workstation or lab computer?
No. Multi-Factor Authentication will only be applied if you are logging into a University service or portal - not for logging into your workstation.
Will I have to approve an MFA prompt every single time I log in?
No, as long as you are using a trusted device. When logging in through the Oakland University sign-in page, select Yes when prompted with "Stay signed in?" (and check "Don't show this again"). This saves a persistent cookie in your browser so you won't be asked for your password or Authenticator app every time you open Microsoft 365, Google Workspace, Sail, or campus web applications.
Important: Only click "Yes" on your own computer or mobile device. If you are using a public computer (like a library PC or lab computer), always click "No" and log out when finished.
Does Microsoft Authenticator work on Apple Watch/Android wearable devices?
No, Apple Watch and Android wearable devices (such as Samsung Galaxy Watch) are currently incompatible with Authenticator's security features, but you can mirror Authenticator notifications from your phone to your wearable device.
Does MFA work when I am traveling, offline, or without cell service?
Yes - using Microsoft Authentication. Open the Microsoft Authenticator app on your mobile device, tap your university account, and use the rotating 6-digit One-Time Password Code (OATH) displayed in the app. This code works without Wi-Fi or cellular service.
Please reference the following article to see an overview of all other articles pertaining to Microsoft Authenticator and the new Self-Service Password Reset (SSPR) solution:
Additional Resources
Microsoft provides an official FAQ document for Microsoft Authenticator, which can be reviewed in conjunction with this article:
The OU Technology Center can provide support for any issues you may encounter with SSPR & Authenticator. Their contact information is below:
- 44 Oakland Center
- Rochester, MI 48309-4479
- (248) 370-4357
- Office Hours: M-F 8:00am - 5:00pm