Multi-Factor Authentication (MFA)

Table of Contents

Multi-Factor Authentication (MFA) helps protect Baker College accounts by requiring an additional form of verification during sign-in. Even if a password is compromised, MFA can help prevent an unauthorized person from accessing the account.

Account holders should register more than one supported verification method when possible. Registering methods on separate devices can help maintain access if a primary device is lost, replaced, or unavailable.

Register a passkey only on a personal device or an individually assigned Baker College device. Do not register a passkey on a shared, public, or lab computer.

For information about Microsoft changes affecting MFA and passkeys, review the Changes to Microsoft MFA and Passkey Requirements article.

Select any article screenshot to open a larger version.

First-Time MFA Setup

If MFA has not previously been configured for your Baker College account, the following prompt may appear during sign-in.

More information required prompt with a Next button

  1. Select Next to open the MFA registration page.
  2. Select the verification method you want to register. The methods available to you may vary.
  3. Follow the instructions for that method in this article.
  4. After registration is complete, return to the Microsoft Security info page to confirm that the method is listed.
  5. When possible, register an additional supported method on a separate device.

Keep your account secure page with Authenticator and alternate setup choices

Return to top.

Accessing Your MFA Settings

You may add, remove, or review registered authentication methods from the Microsoft Security info page.

  1. Sign in with your Baker College account.
  2. Select + Add sign-in method to register another method.
  3. To remove a method, select Delete next to that method and confirm the change.

Important: Do not remove an existing working method until a replacement method has been registered and tested.

The email option shown on the Security info page is used for account recovery and cannot be used to complete MFA verification. For instructions, review the Setting Up Recovery Methods for Self-Service Password Reset article.

Return to top.

Supported MFA Verification Methods

  • Microsoft Authenticator: Approve sign-in requests with number matching, generate verification codes, configure passwordless sign-in, or store a device-bound passkey.
  • Apple Passwords/iCloud Keychain: Store a synced passkey on compatible iPhone, iPad, and Mac devices. A passkey on an Apple mobile device can also be used to sign in on Windows or a Chromebook by scanning a QR code.
  • FIDO2 security key: Store a device-bound passkey on a compatible physical security key for use with supported devices and browsers.
  • Google Password Manager: Store a synced passkey on compatible Android devices or in Chrome on supported Windows, Mac, and Chromebook devices.
  • Different authenticator app: Use a compatible software authenticator app to generate time-based one-time verification codes.

Traditional code-generating physical hardware tokens are not supported. These tokens are different from FIDO2 security keys, which store passkeys and are supported.

Return to top.

Microsoft Authenticator

Microsoft Authenticator can approve sign-in requests, generate verification codes, and provide passwordless or passkey sign-in options.

Standard Microsoft Authenticator Setup

[Video] Setting Up Microsoft Authenticator
Microsoft Authenticator video transcript

  1. On a computer or another device separate from the mobile device where Microsoft Authenticator will be installed, go to the Microsoft Security info page and select + Add sign-in method.
  2. Select Authenticator app, select Add, and then follow the prompts until a QR code appears.
  3. Install Microsoft Authenticator from the application store on your mobile device. Confirm that you have selected the official Microsoft application.

Microsoft Authenticator app listing used to identify the correct application

  1. Open Microsoft Authenticator and add a Work or school account.
  2. Select Scan QR code and scan the code displayed in the browser. If the code cannot be scanned, select Can't scan image? in the browser and follow the manual setup instructions.

QR code displayed while registering Microsoft Authenticator

  1. Return to the browser and select Next. Microsoft will send a test request to the app.
  2. Enter the number displayed in the browser into Microsoft Authenticator and approve the request. Your device may also require its PIN, fingerprint, or facial recognition.

Number-matching request displayed while confirming Microsoft Authenticator

  1. Complete the remaining prompt. Microsoft Authenticator will appear on the Security info page after registration succeeds.

Do not approve a sign-in request that you did not initiate. If you receive an unexpected request, deny it and change your Baker College password.

Passkey in Microsoft Authenticator

A passkey in Microsoft Authenticator is stored on the device where it is created. It does not sync or transfer to a replacement device. If the device is replaced, reset, or unavailable, register a new passkey after regaining access with another method.

Microsoft Authenticator passkeys require a compatible mobile device, a device screen lock, and a current version of Microsoft Authenticator. The mobile device must use iOS 17 or later or Android 14 or later. Availability may vary by Android device manufacturer.

  1. Confirm that Microsoft Authenticator is installed and current and that the mobile device has a screen lock configured.
  2. Go to the Microsoft Security info page and select + Add sign-in method.
  3. Select Passkey in Microsoft Authenticator and then select Next.
  4. On the mobile device, open Microsoft Authenticator, select your Baker College account, and select Create a passkey.
  5. Follow the device prompts to allow Microsoft Authenticator as a passkey provider if it is not already enabled.
  6. Complete the identity-verification prompts, and then select Done when the passkey-created message appears.
  7. Return to the browser and select Next to finish registration.
  8. Confirm that Passkey (device-bound) Microsoft Authenticator appears on the Security info page.

Device-bound Microsoft Authenticator passkey listed as a registered method

To use the passkey when signing in on another device, follow Using a Passkey on Another Device.

Passwordless Sign-In

Passwordless sign-in through Microsoft Authenticator may be available for Baker College accounts. Microsoft may still require a password in some situations. Baker College IT cannot override a Microsoft prompt that requires password entry.

[Video] Setting Up Passwordless Sign-In
Passwordless sign-in video transcript

  1. Open Microsoft Authenticator and select your Baker College account.
  2. Select Set up phone sign-in or Set up phone sign-in (sign in without a password).
  3. Select Continue, sign in if prompted, and then select Register.
  4. Select Finish after registration succeeds.

During a later sign-in, you may need to select Other ways to sign in and then Approve a request on my Microsoft Authenticator app.

Return to top.

Apple Passwords/iCloud Keychain

Apple Passwords/iCloud Keychain can store a synced passkey for a Baker College account. The passkey may be available on compatible Apple devices signed in to the same Apple Account when iCloud Passwords and Keychain is enabled.

Registering Apple Passwords on an iPhone or iPad

Apple Passwords/iCloud Keychain passkeys require iOS 16 or later or macOS 13 or later. Before beginning, confirm that the Apple device has a passcode or other screen lock and that two-factor authentication is enabled for the Apple Account.

  1. On an iPhone or iPad, open Settings, select your name, select iCloud, and then select Passwords. On iOS 17 or earlier, this option may be labeled Passwords and Keychain. Turn on Sync this iPhone or Sync this iPad.
  2. Go to Settings > General > AutoFill & Passwords and select Passwords under Set Up Codes In.
  3. On the Apple device, open a supported browser and go to the Microsoft Security info page. Sign in and complete MFA.
  4. Select + Add sign-in method, select Passkey, and then select Next.
  5. Select Next again when Microsoft begins the passkey setup.
  6. Follow the Apple prompt to save the passkey in Apple Passwords/iCloud Keychain. Use Face ID, Touch ID, or the device passcode to confirm the registration.
  7. Enter a recognizable name for the passkey, select Next, and then select Done.
  8. Confirm that the passkey appears on the Security info page.

Representative Apple Passwords passkey setup: prepare the device, select Passkey, verify, name, and finish

Representative screens: The appearance and wording may vary by Apple device, browser, and software version.

Registering Apple Passwords on a Mac

  1. Confirm that iCloud Passwords and Keychain is enabled for the Apple Account on the Mac.
  2. On the Mac, open a supported browser and go to the Microsoft Security info page. Sign in and complete MFA.
  3. Select + Add sign-in method, select Passkey, and then select Next.
  4. Follow the macOS prompt to save the passkey in Apple Passwords/iCloud Keychain. Confirm with Touch ID or the Mac login password when prompted.
  5. Enter a recognizable name for the passkey, select Next, and then select Done.
  6. Confirm that the passkey appears on the Security info page.

Return to top.

FIDO2 Security Key

A FIDO2 security key is a physical device that stores a device-bound passkey. A security key may connect through USB or another supported connection method. The key must be FIDO2 compatible.

Traditional code-generating hardware tokens are not supported. They are not the same as FIDO2 security keys.

Microsoft does not currently support registering a new FIDO2 security key from macOS, iOS, or ChromeOS browsers. Complete registration from a supported Windows browser when possible. After registration, sign-in support may be available on additional devices and browsers.

[Video] Setting Up a FIDO2 Security Key
FIDO2 security key video transcript

Note: The video shows an earlier Microsoft setup screen that lists Security key as the initial method. If the current screen differs, follow the numbered steps below and select Passkey first.

  1. Go to the Microsoft Security info page and select + Add sign-in method.
  2. Select Passkey and then select Next.
  3. At the prompt asking where to save the passkey, select Use another device or More options if the security-key option is not displayed.
  4. Select Security key.
  5. Insert or connect the security key when prompted.
  6. Create or enter the security key PIN or use the key's biometric verification. This PIN belongs to the key and is not the Baker College account password.
  7. Touch or activate the security key when prompted.
  8. After returning to the Security info page, enter a recognizable name for the key.
  9. Select Done and confirm that the security key appears on the Security info page.

Prompts may vary based on the operating system, browser, and security-key model. To sign in with the key, select Sign-in options, choose the security-key or passkey option, connect the key, enter its PIN, and touch or activate it when prompted.

For purchasing guidance, review How do I choose a security key? in the Frequently Asked Questions.

Return to top.

Google Password Manager

Google Password Manager can store a synced passkey for a Baker College account. The passkey may be available on compatible devices signed in to the same Google Account.

Registering Google Password Manager on Android

Google Password Manager passkeys require Android 9 or later. Before beginning, confirm that the device has a screen lock and is signed in to a Google Account. Menu names and provider availability vary by Android version and device manufacturer.

Samsung devices: Microsoft does not currently support native Google Password Manager passkeys on Samsung devices. Use Microsoft Authenticator or a FIDO2 security key instead.

  1. Search the Android Settings application for passkey. Depending on the device, select Passwords, passkeys & accounts or Security and privacy > More security settings > Passwords, passkeys, and autofill.
  2. Confirm that Google Password Manager is selected or enabled as a passkey provider.
  3. On the device, open a supported browser and go to the Microsoft Security info page. Sign in and complete MFA.
  4. Select + Add sign-in method, select Passkey, and then select Next.
  5. When Android displays the passkey prompt, confirm that Google Password Manager is the selected provider. Select the Google Account to use if prompted.
  6. Select Continue or Create and confirm the registration using the Android screen lock.
  7. Enter a recognizable name for the passkey in Microsoft, select Next, and then select Done.
  8. Confirm that the passkey appears on the Security info page.

Representative Google Password Manager passkey setup: prepare the device, select Passkey, verify, name, and finish

Representative screens: Android menu names, provider availability, and wording may vary by device manufacturer, browser, and software version.

Registering Google Password Manager in Chrome

Google Password Manager can store a passkey in Chrome on Windows 10 or later, macOS 13 or later, or ChromeOS 129 or later. Use a current version of Chrome and sign in to Chrome with the Google Account that will store the passkey.

  1. In Chrome, go to the Microsoft Security info page. Sign in and complete MFA.
  2. Select + Add sign-in method, select Passkey, and then select Next.
  3. At the prompt asking where to save the passkey, select Google Password Manager. Select More options if Google Password Manager is not displayed.
  4. Confirm the Google Account that will store the passkey.
  5. Complete the device-verification prompt. Google may require a Google Password Manager PIN when a passkey is first used on a computer.
  6. Enter a recognizable name for the passkey, select Next, and then select Done.
  7. Confirm that the passkey appears on the Security info page.

Return to top.

Using a Different Authenticator App

A compatible software authenticator app may be used to generate time-based one-time verification codes. Button names and setup screens vary by application.

  1. Go to the Microsoft Security info page and select + Add sign-in method.
  2. Select Authenticator app and then select I want to use a different authenticator app.
  3. Follow the instructions in the selected authenticator app to scan the QR code or enter the setup information manually.
  4. Enter the verification code generated by the app when Microsoft requests it.
  5. Complete setup and confirm that the authenticator method appears on the Security info page.

This option applies to software authenticator apps. Traditional code-generating physical hardware tokens are not supported.

Return to top.

Using a Passkey on Another Device

A passkey stored on a compatible mobile device can be used to sign in on another device by scanning a QR code. Both devices must have Bluetooth enabled and an active internet connection. Keep the devices near each other until sign-in is complete.

  1. On the device where you are signing in, select Use passkey from another device. If that option is not displayed, select Sign-in options and then Face, fingerprint, PIN, or security key.
  2. On the passkey prompt, select iPhone, iPad, or Android device. The wording may vary by operating system and browser.

Passkey prompt with the iPhone, iPad, or Android device option

  1. Use the mobile device camera to scan the QR code displayed on the other device. Do not share the QR code with another person.

QR code prompt for signing in with a passkey stored on a mobile device

  1. On an Apple device, select Sign in with passkey. On an Android device, select Use passkey to sign in.
  2. Select the passkey for the Baker College account.
  3. Confirm the sign-in with the mobile device PIN, fingerprint, or facial recognition.
  4. Wait for the browser or application on the other device to finish signing in.

Scanning the QR code does not copy the passkey to the other device.

Return to top.

Frequently Asked Questions

Why is MFA required?

MFA helps protect Baker College accounts and information. A password can be stolen or compromised; requiring another form of verification makes unauthorized access more difficult.

How often will I be asked to complete MFA?

The frequency of MFA prompts depends on the application, browser, device, and security conditions associated with the sign-in. A new browser session, password change, or security event may require another verification.

Will I need MFA to use Baker College applications on a mobile device?

An application that uses Baker College single sign-on may require MFA on a mobile device. The timing of the prompt depends on the application and sign-in session.

Will I need MFA to access email and other Baker College services?

Services that use Baker College single sign-on may require MFA. This includes services such as Gmail, Zoom, My Baker, Canvas, and other applications connected to the Baker College sign-in page.

What should I do if I lose, replace, or reset a device used for MFA?

If another registered method is available, select Sign in another way or Other ways to sign in and use that method. After signing in, register the replacement device from the Microsoft Security info page. Do not remove the old method until the replacement has been registered and tested. If no working method is available, contact the IT Help Desk.

Can an alternate email address be used for MFA?

No. An alternate email address can be used for account recovery but cannot be used to complete MFA verification. Review the Setting Up Recovery Methods for Self-Service Password Reset article for more information.

Can I register a passkey on a shared, public, or lab computer?

No. Register passkeys only on a personal device or an individually assigned Baker College device. If setup begins on a shared, public, or lab device, cancel the process and complete it later from an appropriate device.

Do passkeys transfer to a replacement device?

Passkeys stored in Apple Passwords/iCloud Keychain or Google Password Manager may sync to compatible devices through the account connected to that service. Passkeys stored in Microsoft Authenticator or on a FIDO2 security key are device-bound and do not sync to another device.

How do I choose a security key?

Choose a key listed as FIDO Certified that uses a connection supported by the devices you use, such as USB-A, USB-C, or NFC. Baker College IT has tested models available from Yubico and TrustKey Solutions. A traditional code-generating hardware token is not a substitute for a FIDO2 security key.

Why is passwordless sign-in requesting my password?

Microsoft may require a password based on the sign-in context or a security condition. After completing a successful sign-in with the password, select Other ways to sign in and choose the Microsoft Authenticator option again when it is available.

Why is a passkey on my mobile device not completing sign-in on another device?

Confirm that Bluetooth is enabled on both devices, both devices have an active internet connection, and they are near each other. Also confirm that the passkey selected on the mobile device belongs to the Baker College account being used.

What should I do if I receive an MFA request I did not initiate?

Deny the request. Do not provide a verification code or approve the sign-in. Change your Baker College password and contact the IT Help Desk if the unexpected requests continue.

How do I get help if no registered method works?

Contact the Baker College IT Help Desk (ITSC) by email at ITSC@baker.edu or by phone at (800) 645-8350.

Return to top.

Submit a Ticket Print Article

Related Articles (4)

Instructions for setting up Mobile Phones to access Baker services.
Directions for setting up multiple self-service password reset options.

Related Services / Offerings (1)

For general issues logging into all systems.