The Microsoft Authenticator app in the app store is the preferred app for MFA authentication. It will use your phone’s security to verify you – which adds another layer of security. The Authenticator app can be set to unlock with my Face ID, and you must also authenticate to unlock your phone and activate the app.
Adding your cell phone number will set up both text messaging and calling to your mobile device. Cell phone is the preferred phone setup since you will have that phone with you and can get text/phone calls from the device.
Cell phone setup (text message and voice call)
- Sign into the MFA link https://mysignins.microsoft.com/security-info.
- Choose the link to + Add method
- Choose Phone.
- If this phone is a mobile phone (recommended) enter your phone number and choose Text me a code. Click Next.
- Enter the code in the box and click Next.
- Click Done at the success screen.
Microsoft Authenticator App
- Sign into the MFA link https://mysignins.microsoft.com/security-info.
- Choose the link to + Add method
- Choose + Add method
- Select Authenticator app and then click Add.
- You will see the wizard start. Click Next.
- Your screen will display a QR Code. Stop here and perform the next steps on your cell phone.
- On your mobile phone, download the Microsoft Authenticator app from your device’s app store.
- You can search for “Microsoft Authenticator” but be careful as advertised apps might show up before the right app in search results.
- Agree to the license terms
- Allow notifications from this app if prompted.
- Add an account with the + button.
- Sign in with Microsoft Account. Choose Work or School account. If you are prompted for Work or Personal, choose Work.
- Choose to Scan QR code
- Choose Allow to permit the app to access your camera.
- Scan the code on your screen using your device camera.
- On your computer, click Next once the app has scanned the code.
- The app will try out the setup. You should see a notification on your phone from Microsoft Authenticator.
- Click to approve the sign-in.
- When everything works properly you will see the success message.
Email setup
**We hear reports that email backup isn't working yet. This section will be revisited.
As a failsafe you can also set up a personal email address as a backup authentication method. You may need to authenticate to login to work email so don’t add your work email here.
- Sign into the MFA link https://mysignins.microsoft.com/security-info.
- Choose the link to + Add method
- Choose email. Follow the prompts to enter your email address and verify the account.
Set your default authentication option
Now that you have more than one option for MFA authentication you should pick one to be the default.
- Click the Set default sign-in method.
- Set your preferred option. The Default will be displayed on the screen now.