Configuring your MFA methods
Click HereIssues logging in
Click HereBacking up and Restoring your MFA
Click HereFrequently Asked Questions
Click HerePassword & Self-Service Password Reset Help
Click Here Conestoga strives to provide Information Technology services to all community members with the highest availability and protections possible. As such Conestoga requires all community members to use Multi-Factor Authentication where able to provide a robust and secure user experience.
MFA can come in many forms, be it a text message, an application notification or a security key, there are many diverse and accessible options available to community members.
What is happening?
On February 1, 2027, Microsoft is retiring text/SMS authentication. If you currently receive a code by phone number, that will stop working after this date. You'll need to switch to the Microsoft Authenticator app, a USB security key, or a passkey to sign in.
What is a passkey?
A passkey lets you sign in without typing a password. You prove it's you the same way you already unlock your phone fingerprint, face, or PIN. Behind the scenes, your device and the website use a secret digital handshake that never leaves your device and can't be stolen, guessed, or phished.
This means that even a perfect fake copy of your bank's or school's login page won't work, because your passkey is built to only work on the real site.
This is why Microsoft and other providers are retiring text codes in favor of passkeys, which close these loopholes.
The Short Version
- Password: a secret word you type in and remember.
- MFA (Multi-Factor Authentication): a second check after your password, like a text code or app notification to prove it's really you.
- Passkey: replaces both the password and the second check with one step: unlocking your phone or computer with your fingerprint, face, or PIN.
Think of a password as a key you carry in your head, one you can lose, forget. A passkey is built into your phone: nobody else can use it, even if they see it, because it only works when you unlock your device.
Passkey FAQ
Configuring your MFA methods
The first step is to sign in to your Conestoga College account at https://mysignins.microsoft.com/security-info on a desktop or laptop. It is not recommended to set up MFA on a phone or mobile device, as you will be unable to scan the required QR code.
We reccomend to have at least 2 methods of authentication, though using more is encouraged if possible. You cannot set Email as a primary method and it is only used for SSPR and Account Recovery.
Follow these steps to set up your passkey
1) sign into https://mysignins.microsoft.com/security-info (or any Conestoga service) 4) on the next pop up select "iPhone, iPad, or Android device" 5) scan the QR code with your phones camera then tap "create a passkey" 6) tap "create" on your phone then the computer screen will update to say "connected" 7) name your key then press "next", it's a good idea to name it related to Conestoga so you won't get confused with other passkeys 8) click "next" again and you're done! (a): You will be brought to a page asking you to add a method. In this step, we will look at the Authenticator (b): Click on "Add method" outlined in red in the previous screenshot. The default option is "Authenticator app", click "Add".
(c): Follow the instructions in the pop-up to download the Authenticator app. You can also click on the "Download now" link to get step-by-step instructions.
(d): Continue following the steps, in the app, choose to allow notifications, then click the + button in the top right corner of the app, and select "Work or School" account.
(e): You will be shown a QR code on your display, you have to scan this QR code with your phone's camera within the Authenticator app. If you are having issues scanning the QR code, you can select "Can't Scan Image" which will provide you information to enter into the Authenticator
Note: The QR code reader is built into the Authenticator app, do not download a third-party QR code app.
If you are having trouble scanning the QR code, select "Or enter code manually" on your phone, and on the pop-up on the computer screen, select "Can't Scan Image", where you will be shown a URL and Code to enter on your phone.
(a): Phone Screen
(b): Computer Screen
(f): You will see your account listed in the (g): Click “Next” on your desktop to verify the setup. Then you will be prompted to approve the notification in the app.
Note: Due to changes on Microsoft's end, you will now be prompted to enter a 2-digit number shown on the screen where you are logging in when approving the sign-in request.
(h): The pop-up on the desktop will show that the notification is approved, click “Next”.
(i): You will see the Authenticator app added as a method.
Please note that deleting the Authenticator app from your device will break the setup and will prevent you from logging in with it, even if it is re-installed.
Here are the security keys that we recommend:
(a): Add another method, "Email", then click "Add".
(b): Enter your personal email address, then click “Next”.
(c): Enter the code that was sent to your email, it may take a few minutes to show up, then click "Next".
(d): You will see that your email address was added to the list of authentication methods.
Passkeys









Authenticator App
Alternative - Manual Authenticator Setup
Using a Security Key
Looking for a Security Key?
Setting up your Security Key
Using the Security Key to log in
Recovery Email
Issues logging in
If you are having issues logging in, for example, if you are unable to access or use the MFA method you are prompted for, please follow these steps:
- On the page where you are prompted for your MFA method, select the button that says "I can't use my Microsoft Authenticator app right now" (or similar).
- You will be shown a list of MFA methods that you have set up. Choose an alternate method that you have access to in order to complete logging in.
If you do not have an alternate method set up, or are unable to access or use any of your alternate methods, please contact the IT Service Desk.
Backup and Restore
If you are getting a new phone or just want a backup in case your phone is damaged follow these steps to backup and restore your MFA
Apple iOS - Backup
- Log into your security portal Make sure you have a non-authenticator method added to your account like an up-to-date phone number and/or USB Security Key
- If you use the Microsoft Authenticator it will automatically backup your MFA to your iCloud account
Apple iOS - Restore
- Once you redownload the Microsoft Authenticator it will sync your MFA but by default you won't be able to authenticate with Conestoga just yet
- Open Microsoft Authenticator and tap on your Conestoga account, it will prompt you to log in and ask for a code from the Microsoft Authenticator , instead tap on "I can't use my Microsoft Authenticator app right now"
- Select your secondary MFA method (phone number and/or USB Security Key) and continue authenticating
- Once you completed authenticating you will be able to use the Microsoft Authenticator again
Android - Backup
- Log into your security portal Make sure you have a non-authenticator method added to your account like an up-to-date phone number and/or USB Security Key
- From the Microsoft Authenticator home screen, tap on the 3 dots in the top right -> settings -> scroll down to "cloud backup" and enable the toggle switch
- You will be asked to log into a Microsoft account, you should be using a personal account and NOT your Conestoga account
- If you have an existing Microsoft account (From Windows, Xbox, or an @outlook, @hotmail, @live, etc email) then simply log in
- If you do not have a Microsoft account then you can tap on "create one" and follow the on screen steps
- Once you are logged in you will get a confirmation prompt that the backup has been created
Android - Restore
- Once you redownload the Microsoft Authenticator it will sync your MFA but by default you won't be able to authenticate with Conestoga just yet
- Open Microsoft Authenticator and tap on your Conestoga account, it will prompt you to log in and ask for a code from the Microsoft Authenticator , instead tap on "I can't use my Microsoft Authenticator app right now"
- Select your secondary MFA method (phone number and/or USB Security Key) and continue authenticating
- Once you completed authenticating you will be able to use the Microsoft Authenticator again
Frequently Asked Questions
MFA supported Applications include but are not limited to: What is multi-factor authentication (MFA)?
Do I have to use MFA?
What if I do not use MFA?
What services support MFA Protection?
What methods of MFA can I use?
What devices are supported for MFA?
Isn't my password enough?
Is there any cost to MFA?
How often will I have to complete an MFA login?
Will MFA slow down my devices or software?
How does an MFA login work?
What should I do if I receive an MFA request and I did not initiate it?
- Do not approve any MFA request that you did not start yourself. Also do not pass any MFA codes for your account to another person.
- No other person should have access to your MFA devices or account.
Can I use Microsoft Authenticator on multiple devices?
Yes, you can set up and use the Microsoft Authenticator app on multiple devices simultaneously. If you don't want to use an app, you can also authenticate using a browser passkey or a security key.
Only one method will be selected as the default authentication method, if that method is unavailable then it is possible to select a backup method to be used to authenticate.
I've switched devices and/or need to reactivate Microsoft Authenticator
- You can always add new devices, passkeys, and security keys by going to https://mysignins.microsoft.com/security-info and selecting Add Method. We highly recommend that you have multiple methods on your account in case one of those methods is unavailable.
- If you have lost all MFA methods and devices you can always contact IT to help you register a new method or device and sign-in to your account to set up methods again.
What if I can't or don't want to use the Microsoft Authenticator app?
- The College's system is authenticated by Microsoft, and it is a Microsoft based server that is validating who you are and what you can access. Because of this, the College highly recommends using the Microsoft Authenticator app or passkeys. If you do not want to use the app, you can add a browser passkey, or you can use a security key. Any of these methods can be added by navigating to https://mysignins.microsoft.com/security-info.
What if I don't have a cellphone, or don't want to use my personal phone?
- You can use a Security Key if you don't want to use your cellphone to authenticate. Security keys come in many different types but the most common is a USB key that you can connect to your computer to authenticate along with a pin.
What is a security key?
- A Security Key (or security token) is a device that facilitates access, or stronger authentication, into other devices, online systems, and applications.
- These devices are generally USB key size that plug into your laptop or desktop but can also be used with phones through Near Field Communication (NFC). They generally have a button or contact sensor on them to prevent misuse when a user is not present.
Does Conestoga provide me with a security key?
- No, Conestoga will not provide security keys.
- Keys may be available for purchase from the on-campus bookstore or other local vendors near campus as well as online suppliers
Where can I buy a security key? How much do they cost?
- There are many different security keys, but the two online options are:
https://pages.yubico.com/solutions-industries-education https://www.amazon.ca/HyperFIDO-Pro-Security-Value-Pack/dp/B08KVJ98M4/. - For more options, Microsoft security key partners can be found here - https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-fido2-hardware-vendor#current-partners
- There may be a local shop in your area that provides them as well, ensure that they are a supported vendor before purchasing one.
How do I use a security key?
- To log in with your Security Key when accessing your Conestoga College account, enter your full email address as normal, then on the password prompt page, select the option "Sign in with Security Key". Alternatively, if you have previously selected to sign in with a security key, you will be sent directly to the page asking you to touch the contact on your security key. You can also select another option if needed, such as a text message or app notification.
- Enter the security key pin
- Touch the contact on your key
- You will be prompted if you want to stay signed in, just as if you had signed in with a password and second factor
What happens if I lose my default MFA method?
- If you lose the phone method you setup, you can use a backup method that does not involve either the phone. Once you are in your account again you should remove the lost phone as an authentication method until it can be found again. If you do not have access to a backup method, you should contact IT.
- If you lose your Security Key, you can use other backup methods (the Authenticator app or printed one-time recovery codes) you setup when setting up multifactor authentication, to get into your account. You can also setup more than one Security Key on your account and keep it in a safe place.
Where can I learn more about MFA and how to secure my account?
How will MFA impact generic accounts?
- For things like shared mailboxes, MFA will not have any impact. If you have questions about any specific accounts, please contact IT.
As a service owner, will Conestoga provide MFA for my service/application?
- We want to protect all Conestoga applications and services with MFA, for more details on specific services or applications, please contact IT.