The University of Massachusetts Amherst

University of Massachusetts Amherst University of Massachusetts Amherst
An illustration detailing different options for multifactor authentication
University News

Keeping UMass Secure: Changes Coming to Multifactor Authentication

UMass Amherst Information Technology is preparing resources and support for the campus community in response to Microsoft’s announcement of upcoming changes to multifactor authentication (MFA), also known as two-step log in.

Image
UMass Information Technology wordmark

Microsoft has announced they will retire SMS and phone calls as methods for MFA starting February 1, 2027, due to increasing security risks. SMS text messages and phone calls lack end-to-end encryption and are more vulnerable to increasingly sophisticated phishing attempts and scams. As Microsoft notes, “The threat environment has changed in speed, scale, and sophistication.”

To prepare for this vendor-driven transition, all students, faculty, and staff using SMS and phone calls for MFA must transition to more secure options, such as the Microsoft Authenticator app or hardware security devices, prior to February 1, 2027. A list of available MFA options for all UMass Amherst faculty, staff and students can be found here.

While current campus community members can continue to use SMS text messages and phone calls as MFA options until the February deadline, all new campus accounts will no longer have SMS and phone calls as MFA options. All students, faculty and staff are urged to transition away from SMS and phone calls for MFA as soon as possible to avoid disruption at the beginning of the spring semester and to increase security for the university.

UMass IT is launching a campus awareness campaign through the months leading up to the February deadline to help campus members transition from SMS and phone calls to more secure MFA options.

“As Microsoft retires SMS and phone call MFA, UMass IT is ready to help the university community move to stronger, more reliable MFA options that reduce risk and better protect our students, faculty and staff, " said Jake Cunningham, interim chief information security officer. "This is a great opportunity for users to move to the Microsoft Authenticator app or another available secure MFA option.”

For questions or assistance regarding MFA changes, contact the IT Service Desk at [email protected] or 413-545-9400 (option 1). More ways to get tech help can be found at https://www.umass.edu/it/get-help.