IMG_2767

USU to retire phone call function for Microsoft Authenticator

Starting Dec. 21, Utah State University will no longer be allowing students or staff to use the phone call verification method to log in to accounts or apps safeguarded by Microsoft multifactor authentication. 

In the coming months, USU’s Information Technology department will be urging users to set up multiple safer avenues for authentication. 

Madonna Bortle, the director for USU IT, said the decision to eliminate phone call verification was made by Microsoft. 

“We have no control over it,” Bortle said. “They are eliminating it and going to more secure methods of securing via multifactor.”

According to Bortle, phone call verification is not as secure as other verification options.

“When you call somebody and all they have to do is hit pound, it’s really easy to just hit that pound and not even think about it,” she said. “You aren’t having to really engage.”

Microsoft echoes this sentiment, writing in a post on Microsoft Learn that phone call and SMS verification are more prone to being hacked or scammed than other more secure methods.

“Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default,” the post says. 

Bortle said passkeys are safe and effective because they tie a user’s phone directly to their computer, a security measure a call to a phone number that can be moved to any device doesn’t guarantee.

While Microsoft will make passkeys the default method, Bortle recommended that users create at least two different backup methods for verification. 

“I can do my iPad or a passkey, or I can do a YubiKey or my Microsoft Authenticator app,” she said. 

Bortles said setting up multiple forms of verification is also critical if someone were to lose, break or upgrade their phone. 

“That way if something happens to your phone, you don’t have to call the service desk to be able to do it,” Bortle said. “The other option is when you replace your phone, keep your old one if you have it. It won’t help if you broke it or lose it, but use your phone to authenticate on your new device and get it set up on your new device before you retire your old phone.”

On Sept. 2 during Day on the Quad, USU IT offered ice cream and shared information with students about the sign-in methods available to them. These included push notifications, six-digit codes, passkeys and YubiKeys. 

During the event, students expressed their opinios on the upcoming change. 

“It’s a little annoying, honestly, but it was already annoying to begin with,” said sophomore Ashlyn Porter. “I get that it’s necessary, but it’s kind of tedious.”

While students who rarely use the phone call method have less of an issue with the change, students who use it regularly expressed more concern. 

“I prefer it a lot more over the two-digit code because then I have to enter in the pin and then I have to enter in my fingerprint and so it just takes longer,” said senior Alta Stott. “I love it, and I hate that it’s going away.”

To prepare campus for the change, Bortle said USU IT will be sending emails and notifications to users throughout the next few months encouraging them to remove the phone call option from their accounts.

“All phone numbers will actually be removed on Dec. 21,” Bortle said. 

If students or staff don’t make the switch in time, Bortle said their password may be changed, and they’ll need to contact the USU IT Service Desk to regain access to their accounts. 

“They wouldn’t be able to get in at all if we just let the phone number go away,” she said, “so we may change their password.”

To ensure the university has time to adjust, Bortle said they’ve set their deadline almost two months prior to the official Microsoft deadline, which is Feb. 1, 2027.

“Always set up your MFA, that’s the key,” Bortle said. “Make sure and always do a backup.”




There are no comments

Add yours