[MFA Modernization Pilot] Replacing or Recovering an MFA Sign-In Method (Lost, New, or Replacement Device)

⚠️ WARNING: This article is intended for participants in the MFA Modernization Pilot only. If you are not a pilot participant, the information in this article may not apply to you. Contact the IT Service Desk if you have questions about your current sign-in experience.

Whether you lost your phone or security key, or you just got a new phone, you may need to update how you sign in to your UMS account with multi-factor authentication (MFA). Find your situation below.

INFO: UMS IT highly recommends adding a backup sign-in method so you can still access your account if your primary device is unavailable. You can manage your sign-in methods at aka.ms/mysecurityinfo.

Table of Contents

  1. I lost my phone, security key, or passkey device
    1. Microsoft Authenticator app
    2. Synced passkey
    3. Device-bound passkey
  2. I got a new phone
    1. Microsoft Authenticator app
    2. Synced passkey
    3. Device-bound passkey
  3. I have no backup method

Instructions

I lost my phone, security key, or passkey device

Microsoft Authenticator app:

  1. Go to aka.ms/mysecurityinfo
  2. Sign in with your username and password
  3. When prompted for MFA, select "Sign in another way"
  4. Select your backup method and complete authentication
  5. Remove your old Microsoft Authenticator from your account
  6. Select "Sign out everywhere" (listed below your sign-in methods) to sign the lost device out of your account
  7. Add MFA Sign-in Method: Microsoft Authenticator App

If you do not have a backup sign-in method, see I have no backup method below.

Synced passkey (iCloud Keychain, Google Password Manager, or a password manager):

Synced passkeys are tied to an account, not a single device. If you sign back in to the service that stores your passkey, your passkey will be available again on your new device, and you will not need to re-enroll.

Device-bound passkey (YubiKey, Windows Hello for Business, or Microsoft Authenticator passkey):

Device-bound passkeys are stored on a specific device and cannot be recovered if that device is lost.

  1. Go to aka.ms/mysecurityinfo
  2. Sign in with your username and password
  3. When prompted for MFA, select "Sign in another way"
  4. Select your backup method and complete authentication
  5. Remove your old passkey from your account
    • Make sure you are removing the correct device-bound passkey, and not a synced passkey
  6. Select "Sign out everywhere" (listed below your sign-in methods) to sign the lost device out of your account
  7. Add a new passkey or sign-in method for your replacement device

If your lost device was a University-provided YubiKey, report the loss to your department. YubiKeys are tracked as IT assets, and your department will need to request a replacement.

If you do not have a backup sign-in method, see I have no backup method below.


I got a new phone

Before you begin: If you still have your old phone, keep it nearby until your new phone is working. You may need it to approve the change.

Microsoft Authenticator app:

Add the app on your new phone, then remove the old device:

  1. On your new phone, install the Microsoft Authenticator app from the App Store (Apple) or Google Play (Android).
  2. Follow Add MFA Sign-in Method: Microsoft Authenticator App to set it up on your new phone.
  3. Remove your old phone using Remove an MFA Sign-In Method from Your UMS Account.

Synced passkey (iCloud Keychain or Google Password Manager):

Your passkey is tied to your Apple Account or Google Account, not to a single phone. When you sign in to the same account on your new phone, the passkey syncs automatically. If you need to set it up again, see the guide for your device:

Device-bound passkey (saved only to your old phone):

A device-bound passkey does not transfer to a new phone. Register a new passkey on your new phone using Add MFA Sign-in Method: Microsoft Authenticator Passkey.

If you no longer have your old phone or any backup method, see I have no backup method below.


I have no backup method (or my backup method is also unavailable)

During the pilot: Contact the SSO/MFA Modernization Project team at sso-mfa-project-group@maine.edu for assistance.

After the pilot: Contact the UMS IT Service Desk.

If you were provided with a Temporary Access Pass (TAP) after contacting UMS IT, follow these instructions: How to Sign In with a Temporary Access Pass (TAP).

Environment

  • Applies to all University of Maine System (UMS) accounts using Microsoft Entra sign-in
  • iOS and Android personal devices
  • Microsoft Authenticator app
  • Synced passkeys (iCloud Keychain, Google Password Manager, password managers)
  • Device-bound passkeys (YubiKey, Windows Hello for Business, Microsoft Authenticator passkey)