ÌýÌýMFAÌýMFA InstructionsÌýVPNÌýFrequently Asked Questions
Multifactor Authentication (MFA)
Cybercriminals increasingly use phishing attacks, password theft, and social engineering to gain
access to accounts. Multifactor authentication (MFA) helps protect your University
of Toledo account by requiring an additional verification method beyond your password.
Recommended: Phishing-Resistant Authentication
For the highest level of account protection, the University recommends phishing-resistant authentication methods such as Passkeys, Windows Hello for Business, and FIDO2 security keys (YubiKey). These methods provide stronger protection against phishing attacks, credential theft, and MFA fatigue attacks. Microsoft Authenticator remains a supported authentication option and can be used when phishing-resistant methods are not available.
Preferred Authentication Methods
- Passkeys
Use cryptographic credentials tied to a supported device. Passkeys can support passwordless sign-in and are designed to resist phishing. - FIDO2 Security Keys (YubiKey)
Hardware security keys provide strong, phishing-resistant authentication. They are useful for individuals who need enhanced protection or prefer not to use a mobile device. - Windows Hello for Business
Use facial recognition, a fingerprint, or a device PIN on a supported Windows device. The sign-in credential remains bound to the device.
Authentication Method Overview
| Ìý | Authentication Method | Recommended Position |
| 2. | Passkeys | Preferred |
| 3. | FIDO2 security keys (YubiKey) | Preferred |
| 4. | Windows Hello for Business | Preferred |
| 5. | Microsoft Authenticator | Supported alternative |
Microsoft Authenticator
- Available for supported iOS and Android devices
- Can be used for sign-in approvals and verification codes
- May be configured as an additional or backup authentication method, based on University policy
Security Key Options
- YubiKey 5 NFC
- YubiKey 5C NFC
- YubiKey 5Ci
The following are recommended Yubikeys for purchase.Ìý Note that any YubiKey 5 Series devices shouldÌý be compatible, but the ones listed below are the ones that have been tested and approved.Ìý Also note that you do not necessarily need to purchase these devices from the links below.
Need Assistance?
After Reviewing the MFA instructions linked above, please contact theÌýUniversity IT HelpDeskÌýatÌý(419) 530‑2400Ìýif you need assistance.
Important Support Information for Alumni and Retirees
For alumni and retirees, the Microsoft Authenticator app is the only supported MFA method for accessing a university email mailbox. Other authentication methods are not supported for these accounts.Ìý This requirement differs from faculty and staff, who may have access to additional MFA options based on their role and licensing.
To retain uninterrupted access to your university email, please complete the following stepsÌýbefore June 1st:
- Review the University's MFA configuration information and instructions. Ìý
- Download and configure theÌýMicrosoft Authenticator app on your smartphone or tablet by following the instructions on the MFA website.
Once MFA is enabled, access to your email will require both your password and approval through the Microsoft Authenticator app.