This article describes the multi-factor authentication (MFA) methods available to University of Maine System (UMS) users, which methods are recommended, and which are not allowed.
Detailed Information
What is an "authentication method"?
Authentication methods define how users can verify their identity in Microsoft Entra. Traditionally this meant MFA methods “in addition to the password”, but today several methods can also replace the password entirely (for example passkeys and Windows Hello for Business). In other words, authentication methods control what options users have available when signing in or performing MFA.
Why you might be prompted for a specific method
INFO: UMS sign-in is set up to automatically ask for your strongest registered method first. If you have a passkey registered, you will be prompted for it instead of your password. If more than one method is registered to your account, you can always select Sign in another way at the sign-in screen to choose a different one.
If you have registered more than one method, here is the order UMS will ask for them, strongest first:
- Passkey or Windows Hello for Business (WHfB)
- Microsoft Authenticator app (push notification)
- Duo
INFO: Microsoft Authenticator ranks above Duo. If you have both Microsoft Authenticator and Duo registered, UMS will prompt you for Authenticator first, even if you intended to keep using Duo. If you want to keep signing in with Duo for now, do not add the Authenticator app until you are ready to make the switch.
If you just added a new sign-in method, it may take a sign-in or two before UMS begins offering it automatically. This is expected; give it a little time before contacting the IT Service Desk.
MFA method explanations
Passkeys
Passkeys are the preferred MFA method at UMS because they are phishing-resistant—they cannot be stolen through fake login pages, reused, or leaked in data breaches. When you use a passkey, you verify your identity with biometrics (fingerprint or face recognition) or a PIN on your device. You do not need to enter your password separately.
There are two types of passkeys:
- Device-bound passkeys are stored on one specific device (such as your phone or a YubiKey) and cannot be copied elsewhere. They are the most secure option.
- Syncable passkeys are backed up to a cloud account (such as iCloud or Google) and are automatically available on any device you sign in to with that account. They are very convenient and still phishing-resistant, though their security depends on the security of your personal account.
Microsoft Authenticator app
Microsoft Authenticator is a free app for iOS and Android. It provides MFA through push notifications with number matching. When you sign in, a number appears on the screen—you open the app and enter the same number to approve the sign-in. This is the minimum requirement; once the app is set up, you can add a passkey inside it for a better experience.
See Microsoft's support page for current device requirements (External Link).
FIDO2 security key (YubiKey)
A YubiKey is a small physical key that plugs into a USB port or taps via NFC. It is phishing-resistant and does not require a smartphone. YubiKeys are available to faculty and staff who cannot use a smartphone.
Third-party authenticator apps (OATH-TOTP)
DANGER: Third-party authenticator apps are the least secure MFA method allowed at UMS and should only be used as an absolute last resort. Use this option only if all of the following are true: the user's phone does not meet the Microsoft Authenticator app's requirements, a hardware security key is not available to them, and no other method on this page is an option. OATH-TOTP codes are not phishing-resistant—unlike a passkey or hardware security key, a code can be captured and reused if someone is tricked into entering it on a fake sign-in page.
If a user has a computer but no smartphone, or a phone that does not meet the Microsoft Authenticator app's requirements, Microsoft Entra ID accepts verification codes from third-party apps that support the OATH-TOTP standard, the same standard used to generate 6-digit rotating codes. See MFA Without a Smartphone: Your Options for setup guidance.
Hardware OATH tokens
Hardware OATH tokens display a one-time passcode that changes every 30 to 60 seconds. They work offline. These are only available to existing Duo hardware token users—they will not be issued to new users.
Recommendations by device and user type
All users
Minimum requirement: Microsoft Authenticator app —set this up first. It is the minimum requirement for MFA methods.
Employees (faculty/staff) with UMS-managed Windows computers
Best option: Windows Hello for Business (WHfB)—built into your managed Windows computer. Uses your face, fingerprint, or PIN. Note that WHfB requires access to UMS domain controllers, so it must be set up while connected to eduroam or VPN.
If you have an auxiliary (aux) account, you can also save its passkey to Windows Hello for Business.
Employees (faculty/staff) with UMS-managed Mac computers
Best option: iCloud Keychain syncable passkey—stored in your Apple iCloud account and available across all your Apple devices, including iPhone, iPad, and Mac.
Students and Employees on Personal Devices (BYOD: Bring Your Own Device)
Students and users on personal devices should set up MFA in the following order—each step improves the experience:
- Microsoft Authenticator app (minimum requirement) —set this up first. It is required before you can add a passkey in the app.
- Passkey in the Authenticator app (device-bound)—the simplest passkey to set up. Stored on your phone; does not sync to other devices.
- Syncable passkey via iCloud Keychain or Google Password Manager (best day-to-day experience)—automatically available on all your personal devices. Set this up on every personal device you use regularly.
WARNING: Do not save a passkey on someone else's computer or a shared computer. Passkeys are personal—saving one on a shared machine means others could potentially sign in as you.
Lab computers and shared computers
WARNING: Do not register or save a passkey on a lab or shared computer.
To sign in on a lab computer, use one of these approaches:
- Passkey via QR code—the sign-in screen shows a QR code. Scan it with your phone to complete authentication using the passkey on your phone. This requires Bluetooth to be enabled on the lab computer.
- Microsoft Authenticator push notification—if Bluetooth is not available on the lab computer, use the Authenticator app on your phone to approve a push notification instead.
Remote access (RDP)
Remote Desktop Protocol (RDP) access continues to use Duo. There is no change to the RDP authentication process. Duo and Microsoft MFA are separate systems—changes to one do not affect the other.
Methods that are not allowed
The following methods are not available for MFA at UMS:
- SMS text message—not secure enough; vulnerable to SIM-swapping attacks.
- Voice phone call—not secure enough.
- Email one-time password—not secure enough.
All available methods at a glance
Environment
- Microsoft Entra
- Windows, macOS, iOS, Android
- FIDO2-compatible browsers and devices
- Remote access (RDP): Duo—no change