Audience: Franklin University staff, faculty, adjuncts, students, and alumni.
Disclaimer: The results and functionality of the following article only apply to audience listed above
Topics
- What is MFA?
- What MFA Options Are Allowed?
- How to Set Up MFA Passkeys
- What if I Get a New Phone?
- FAQs
What is MFA?
Multi-factor authentication (MFA), sometimes referred to as two-factor authentication, requires a second verification step after entering your password to provide an additional layer of account security. Your phone is the best option as your phone as a secondary source of verification of your identity when signing in. MFA is required for many different applications around the university.
What MFA Options Are Allowed?
Microsoft is retiring text message and phone call MFA by February 2027. Click here for more details.
If you keep being prompted to set up new MFA even though you currently have MFA set up, click here for more details.
What are Passkeys: Passkeys let you authenticate to websites and apps the same way you unlock your phone, using your fingerprint, face recognition, or even your device PIN. The first time you set up a passkey, you will be presented with a QR code to be scanned on your phone for set up. After initial set up, most additional MFA prompts for future log ins will often present as a new QR code or similar MFA prompt.
With the retirement of text and phone call MFA, passkeys are the preferred MFA methodology at Franklin University. However, there are other secure MFA methods that will remain active such as authenticator app push notifications or 30-second timed codes.
Passkey and MFA Options
1. Save a Passkey in Microsoft Authenticator App on your phone: You can use your phone to set up a passkey to be saved in an authentication application such as Microsoft Authenticator. This is the preferred method.
2. Save MFA information to your Phone (likely no app download needed): You can save MFA options such as a passkey into a built-in password application on your iPhone or Android. This is a helpful option for those that do not want to download an application for MFA.
- Experiences may vary and we cannot guarantee successful results. For best result, please use the Microsoft Authenticator application for passkey storage or MFA codes.
3. What about using a device that is not your phone for MFA? Click here for more information.
How to Set Up MFA Passkeys
1. When signing into a Franklin University website such as mail.franklin.edu on your computer, enter your email address and password.
2. Next, when prompted to set up an MFA method for the first time, you will see a screen such as this:
[choose the heading below that fits your scenario for next steps]
Microsoft Authenticator App
3. Install the Microsoft Authenticator App on your phone from the App Store (iOS) or Play Store (Android). Then press Next.
4. When presented with this screen, open the Authenticator app on your phone. Use the "+" button on the authenticator app to add a Work or School Account. Next, scan a QR code. Then press Next on the screen shown below to be presented with the QR code.
[below: on your phone - Authenticator App]
5. Next, you should be presented with the QR code on your computer screen. Your phone camera should open after pressing Scan QR code in the authenticator app. Scan that code with your camera to set up to save the passkey into authenticator.
6. Now that you have set up a passkey to be saved in the Authenticator app on your phone, let's talk about future MFA prompts. When prompted in the future for MFA, it will most likely appear in the form of a QR code, or other MFA prompt. Scanning the QR code with your phone or mobile device (with the saved passkey) will then trigger your fingerprint scan or face scan on your phone to serve as your MFA. Press Next to be presented with that QR code.
MFA on your Phone Password Manager
The screenshots below are shown on an iPhone. The process for Android phones may be similar, though not exact to an iPhone. There may also be multiple ways in which MFA can be set up per phone password manager.
Experiences may vary and we cannot guarantee successful results. For best result, please use the Microsoft Authenticator application for passkey storage or MFA codes.
1. When presented with the screen to install the Microsoft Authenticator App, choose instead to Set up a different authentication app. No new app download is required at this point if your phone has a password management application (such as the Passwords on an iPhone - iOS built-in application on all new iPhones).
2. If presented with this screen, press Next.
3. If presented with a QR code, scan it with your phone. You may be prompted to Save a passkey or Add a Verification Code to your password manager.
[see step 4]
-or-
[see step 5]
4. Passkeys may use your phone's face reader, fingerprint reader, or other phone unlocking mechanism for MFA.
After it is saved, when prompted in the future for MFA, most likely another QR code will be presented. Scanning that code with your phone or mobile device (with the saved passkey) will then trigger your fingerprint scan or face scan on your phone to serve as your MFA. Press Next to be presented with that QR code.
[below: future MFA prompts after an MFA passkey is set up and saved]
5. For verification codes, save they information into your passwords manager using franklin.edu as the URL. Leave the passkey that was auto-filled in the password location, even though this code differs from your university password. After the MFA information is saved, when prompted for MFA, a code will appear that changes to a new code every 30 seconds [as shown below]. This code can be used for MFA during the 30 second window.
To add a different MFA method, log into your account and verify your MFA. Then visit this page to add another method: https://mysignins.microsoft.com/security-info
What if I Get a New Phone?
If you are planning on getting a new phone, setting up a Microsoft Authenticator on your new phone while in possession of your prior phone is recommended.
However, for cases where access to both phones (old and new) at one time is not possible, it can be helpful to save a passkey to your iPhone or Android phone ahead of time. Most phones have a password application that can save passkeys. Before replacing your phone, confirm that your password manager or passkey provider is configured to synchronize and back up your saved passkeys.
Lost Phone or Unplanned Replacement Phone: If you run into an issue where your MFA needs reset administratively, please reach out to our Help Desk for assistance and we can help reset your MFA.
FAQs
I have MFA set up already. Why do I keep getting prompted to set up a passkey?
- While you have MFA set up, if you are using a phone call and/or text message MFA methods, those will soon be retired and no longer supported. Even though previously set up text and phone MFA may work until February 2027, you will continue to be prompted to use a passkey for better MFA security. Bypassing this prompt to continue using text and phone call MFA may become increasingly intrusive until such methods are retired.
Why are text messages and phone calls for MFA being retired?
- Text message and phone call MFA methods have been shown to be vulnerable to compromise. Therefore, Microsoft will no longer support these methods starting February of 2027. Additionally, any new account from September of 2026 onward will not be presented with these options and will not be able to set them up. While Microsoft has made this change, please know that such security standards are changing across many different industries and platforms. MFA through text or phone call will continue to become less common moving forward.
Can I bypass MFA?
- No, it is a regulatory requirement. If you lose access to your MFA methods, the Help Desk can assist with resetting your MFA enrollment. However, MFA will not be removed from your account.
Do I have to use the Microsoft Authenticator app, or can I use a comparable MFA app on my phone?
- We support and recommend using Microsoft Authenticator for storing your passkeys. You may also save them in your phone’s default password application. However, if you choose to download an alternative application onto your phone for MFA, such applications may or may not work as intended. Such applications will need to be installed at your own discretion, and we will not have support for such apps.
Can I use my email for MFA?
- No, Franklin University does not support email-based MFA verification.
What If I Am Not Using a Phone for MFA?
Select below based on your role with Franklin University for more information.
Staff & Faculty
For those who have been issued a Franklin University owned computer:
If you are looking for the ability to use a device other than your phone for MFA, the only other MFA option that is approved for staff and faculty is the use of a physical hardware token.
- You may purchase and setup your own physical hardware token. Click here to learn more.
- Alternatively, you may review this form to request access to a physical passkey device to be deployed by IT. If approved and deployed, this passkey must be with you whenever you need to sign in to systems requiring MFA. Approval is required for each case, and not all cases are approved.
NOTE: If your role is not already approved for a university-issued phone or phone stipend, MFA method preference is not sufficient reasoning to receive a phone from Franklin University, or to be approved for a stipend.
Data Privacy: Some staff and faculty may be concerned about privacy of their phone when installing an MFA application such as Microsoft Authenticator for storing passkeys. Keep in mind that you can also save a passkey into your phone's password manager without downloading a new application (as shown above).
Does Microsoft Authenticator give Franklin University control of my phone?
- No. Microsoft Authenticator is an authentication application, not a mobile device management (MDM) solution. Installing Microsoft Authenticator alone does not give Franklin University control of your phone or access to its contents.
Can Franklin University see my photos, text messages, emails, or web browsing history through Microsoft Authenticator?
- No. Microsoft Authenticator does not provide Franklin University access to your personal photos, text messages, personal email, call history, or browsing history.
Can Franklin University remotely wipe my phone through Microsoft Authenticator?
- No. Installing Microsoft Authenticator alone does not give Franklin University the ability to remotely wipe your personal device.
Is Microsoft Authenticator managed by Franklin University?
- No. Microsoft Authenticator is a Microsoft application published and maintained by Microsoft. Franklin University does not manage the application on your personal device simply because it is installed.
Does Microsoft Authenticator automatically collect or store all of my passwords?
- No. Microsoft Authenticator is primarily used for identity verification through notifications, verification codes, and passkeys. It is not a general-purpose password manager.
Can Franklin University track my location through Microsoft Authenticator?
- No. Microsoft Authenticator is not used by Franklin University to track the location of users or personal devices.
Does Microsoft Authenticator record my phone calls or listen through my microphone?
- No. Microsoft Authenticator is used to verify your identity during sign-in and does not monitor phone calls, microphone activity, or conversations.
Does Microsoft Authenticator allow Franklin University to see other applications installed on my phone?
- No. Installing Microsoft Authenticator alone does not provide Franklin University with visibility into the applications installed on your personal device.
Why does Franklin University recommend Microsoft Authenticator?
- Microsoft Authenticator is the authentication method that Franklin University can most consistently support and troubleshoot when users experience sign-in or multi-factor authentication issues.
Students, Adjuncts, & Alumni
For those who are using their own computer for coursework or online instruction:
While a use of a phone is recommended for MFA, There are a few alternatives available. Results may vary.
1. You may purchase and setup your own physical hardware token. Click here to learn more.
2. You can store a passkey in your computer browser’s password manager, or you can download a free authenticator app onto your computer or in your computer browser as a workaround. These applications may require use of facial recognition, a fingerprint reader, your computer PIN, Touch ID fingerprint sensor, or other method of identity verification. These methods are not permitted on Franklin University owned computers (such as on-campus computers). Your experience may vary when using a different computer.
Franklin University does not directly recommend or support computer software or browser MFA set up on your computer. Instead, we recommend using a phone for a passkey MFA as described in this article. The apps shown in the screenshots below are examples only. Therefore, we do not have MFA applications for a computer that we directly support currently. If you are not using a phone for passkey MFA, only proceed at your own risk.
[Microsoft Store Example – Not Directly supported by Franklin University]
[Chrome Store Examples – Not Directly supported by Franklin University]