How to register a multi-factor authentication method for your VCCS account using an authenticator app.
Overview
Multi-factor authentication (MFA) adds a second verification step to your VCCS account sign-in. Instead of a password alone, you confirm your identity with two things: something you know (your password) and something you have with you (usually your phone). If someone steals your password, they still cannot sign in without your device.
You register your method once. After that, you approve a prompt when signing in from a new device, browser, or location.
Links to other pages in this article open in a new tab, so these instructions stay open while you work.
Phone call and text message verification are not covered here. Microsoft is retiring phone-based verification for Microsoft 365 accounts, and it stops working after February 1, 2027. Use one of the app-based methods below. If phone verification is the only method currently registered on your account, add an app method now so you are not locked out later.
Assumption
You are a VCCS faculty or staff member with an active account, and you have your phone or another device with you.
Register your method
- Open the Microsoft security info page. If that address does not load, go to mysignins.microsoft.com/security-info instead.
- Enter your VCCS email address.

- Enter your password.

- Answer the prompt asking whether to stay signed in. Either answer works.

- When the page says more information is required, select Next.

-
You land on the Keep your account secure page. Pick one of the two options below and follow that section.

Choose your method
This is the VCCS recommended method. You install the Microsoft Authenticator app, normally on your smartphone, and approve a prompt when you sign in. VCCS IT and Microsoft both fully support this method.
- Install Microsoft Authenticator on your phone from the App Store or Google Play, then select Next.

- Open Microsoft Authenticator, add a new account, and select Work or school account. Allow the camera permission when the app asks. You need the camera to scan the QR code in a later step.


- Back in your browser, select Next.

- Scan the QR code on your screen with the app, then select Next.

- Your browser shows a two-digit number and your phone shows a notification. Open the notification and type that number into the app. This is called number matching, and it confirms the request came from you.


- Once the browser confirms the notification was approved, select Next.

- Select Done. Your account is registered.

Use a third-party authenticator app already on your device. Instead of approving a prompt, you enter a rotating 6-digit code when you sign in. VCCS IT supports this method on a best-effort basis, since the apps vary.
- Select I want to use a different authenticator app.

- Add a new account in your authenticator app, then select Next. Steps differ by app, so check that app's own documentation if you need help.

- Scan the QR code with your app, then select Next.

- Enter the 6-digit code from your app, then select Next. The code rotates every 30 seconds, so if it expires while you are typing, use the next one.

- Select Done. Your account is registered.

Add a backup method
Register a second method after you finish. If you lose your phone or replace it with only one method registered, you cannot sign in and will need help from IT to recover access. Return to the security info page and select Add sign-in method.
Related article
Troubleshooting
- The setup page will not load or keeps returning you to sign-in. Try a private or incognito window, or clear your browser cookies. Old sessions interfere with the page.
- The QR code will not scan. Check that the app has camera permission in your phone settings, then retry.
- Your 6-digit code is rejected. Codes expire every 30 seconds. Wait for a fresh code and enter it right away.
- You never receive the notification. Confirm the device has signal or network access, then start the step over.
- You no longer have the device you registered. Contact the VCCS IT Help Desk. Do not delete a registered method until a replacement is confirmed working.