MFA: VCCS Multi-factor Authentication Setup

Overview

Multi-factor authentication (MFA) adds a second verification step to your VCCS account sign-in. Instead of a password alone, you confirm your identity with two things: something you know (your password) and something you have with you (usually your phone). If someone steals your password, they still cannot sign in without your device.

You register your method once. After that, you approve a prompt when signing in from a new device, browser, or location.

Links to other pages in this article open in a new tab, so these instructions stay open while you work.

Assumption

You are a VCCS faculty or staff member with an active account, and you have your phone or another device with you.

Register your method

  1. Open the Microsoft security info page. If that address does not load, go to mysignins.microsoft.com/security-info instead.
  2. Enter your VCCS email address.

    Microsoft sign-in page with the email address field

  3. Enter your password.

    Microsoft sign-in page with the password field

  4. Answer the prompt asking whether to stay signed in. Either answer works.

    Prompt asking whether to stay signed in, with Yes and No buttons

  5. When the page says more information is required, select Next.

    Notice that more information is required to keep the account secure, with a Next button

  6. You land on the Keep your account secure page. Pick one of the two options below and follow that section.
    Keep your account secure page showing the Microsoft Authenticator setup prompt

Choose your method

Option 1: Microsoft Authenticator app (recommended)

This is the VCCS recommended method. You install the Microsoft Authenticator app, normally on your smartphone, and approve a prompt when you sign in. VCCS IT and Microsoft both fully support this method.

  1. Install Microsoft Authenticator on your phone from the App Store or Google Play, then select Next.

    Start by getting the app screen with a Next button

  2. Open Microsoft Authenticator, add a new account, and select Work or school account. Allow the camera permission when the app asks. You need the camera to scan the QR code in a later step.

    Microsoft Authenticator add account screen with the Work or school account option

    Microsoft Authenticator requesting permission to use the camera

  3. Back in your browser, select Next.

    Set up your account screen with a Next button

  4. Scan the QR code on your screen with the app, then select Next.

    Scan the QR code screen with a QR code and a Next button

  5. Your browser shows a two-digit number and your phone shows a notification. Open the notification and type that number into the app. This is called number matching, and it confirms the request came from you.

    Browser displaying a two-digit number to enter in the Authenticator app

    Microsoft Authenticator notification prompting for the number shown in the browser

  6. Once the browser confirms the notification was approved, select Next.

    Notification approved confirmation with a Next button

  7. Select Done. Your account is registered.

    Success message confirming registration, with a Done button

Option 2: A different authenticator app

Use a third-party authenticator app already on your device. Instead of approving a prompt, you enter a rotating 6-digit code when you sign in. VCCS IT supports this method on a best-effort basis, since the apps vary.

  1. Select I want to use a different authenticator app.

    Keep your account secure page with the option to use a different authenticator app

  2. Add a new account in your authenticator app, then select Next. Steps differ by app, so check that app's own documentation if you need help.

    Set up your account screen for a third-party authenticator app

  3. Scan the QR code with your app, then select Next.

    QR code to scan with a third-party authenticator app

  4. Enter the 6-digit code from your app, then select Next. The code rotates every 30 seconds, so if it expires while you are typing, use the next one.

    Field for entering the 6-digit code from the authenticator app

  5. Select Done. Your account is registered.

    Success message confirming registration, with a Done button

Add a backup method

Register a second method after you finish. If you lose your phone or replace it with only one method registered, you cannot sign in and will need help from IT to recover access. Return to the security info page and select Add sign-in method.

Related article

Troubleshooting

  • The setup page will not load or keeps returning you to sign-in. Try a private or incognito window, or clear your browser cookies. Old sessions interfere with the page.
  • The QR code will not scan. Check that the app has camera permission in your phone settings, then retry.
  • Your 6-digit code is rejected. Codes expire every 30 seconds. Wait for a fresh code and enter it right away.
  • You never receive the notification. Confirm the device has signal or network access, then start the step over.
  • You no longer have the device you registered. Contact the VCCS IT Help Desk. Do not delete a registered method until a replacement is confirmed working.