What do you need help with?
About Multi-Factor Authentication
Multi-Factor Authentication (MFA) adds an additional layer of security to your FAU account by requiring another verification method in addition to your password. MFA is required for students, faculty, and staff accessing FAU systems.
FAU uses Microsoft Entra MFA for multi-factor authentication. Even if someone obtains your password, MFA can help prevent unauthorized access to your email, files, and other university systems.
Microsoft Authenticator is the recommended verification method and allows you to approve sign-in requests from your phone. Other supported authentication methods may include:
- SMS text message
- A supported hardware token
- Passkeys or other sign-in methods available to your account
MFA enrollment is required for your account, you may be unable to access FAU services until enrollment is completed.
Set Up Microsoft Authenticator
Microsoft Authenticator is the recommended method for approving FAU sign-in requests.
- iPhone or iPad: Download Microsoft Authenticator from the Apple App Store.
- Android: Download Microsoft Authenticator from the Google Play Store.
After installing the app, continue with the enrollment steps below.
- Open a private or incognito browser window on your computer or mobile device.
- Go to Microsoft MFA Setup.
- Sign in using your full FAU email address.
- Example: FAUNetID@fau.edu
- Health users may use FAUNetID@health.fau.edu.
- Follow the Microsoft prompts to add Microsoft Authenticator.
- Open Microsoft Authenticator on your phone when prompted and complete the pairing process.
- Complete the verification request and continue until Microsoft confirms that setup is complete.
Manage or Replace Your MFA Device
You can add or update sign-in methods through your Microsoft Security Information settings.
- Open Microsoft Authenticator on a device that is already working with your FAU account.
- Select your FAU account.
- Select Update Security Information.
- Sign in and complete your existing MFA verification.
- Open Security Info.
- Select Add sign-in method.
- Select the method you want to add and follow the prompts.

If you still have access to another working MFA method, use it to sign in and add Microsoft Authenticator on your new device.
If you cannot complete MFA because your previous device is unavailable, use a Temporary Access Pass (TAP) to regain access and register the new device.
Temporary Access Pass (TAP)
If your MFA device is unavailable or Microsoft Authenticator is no longer working, a Temporary Access Pass (TAP) can allow you to sign in and register a new authentication method.
- Go to FAU Microsoft Entra MFA Recovery.
- Enter your FAUNet ID, complete the confirmation, and select Continue.
- If recovery options are configured on your account, you will receive a Temporary Access Pass through an available recovery method such as SMS or email.
- Select Register Your Device.
- Enter the Temporary Access Pass when prompted and select Sign In.
- After signing in, open the page for managing your MFA devices.
- Select Add sign-in method and add Microsoft Authenticator or another supported method.


If you do not receive a TAP: Your account may not have working recovery options configured. Contact the FAU OIT Help Desk for assistance.
Troubleshoot MFA and Sign-In Problems
Select the issue that most closely matches what you are experiencing.
Microsoft Authenticator may no longer be correctly linked to your account. This can happen after:
- Updating or resetting your phone
- Deleting and reinstalling Microsoft Authenticator
- Restoring your phone from a backup
- Turning off notifications for Microsoft Authenticator
If the app is no longer correctly registered:
- Use another working MFA method if one is available.
- If you cannot complete MFA, obtain a Temporary Access Pass (TAP).
- Sign in to your Microsoft Security Information settings.
- Remove the old or non-working Microsoft Authenticator registration if necessary.
- Select Add sign-in method and register Microsoft Authenticator again.
If Microsoft Authenticator shows an account labeled only Fau instead of Florida Atlantic University, the account may have been added incorrectly. Remove the incorrect profile and re-register Microsoft Authenticator.
A Passkey may work on your personal device but cause problems when signing in on a lab, classroom, shared, or different computer.
Microsoft Authenticator push notifications are recommended for signing in across multiple devices.
- Open Microsoft Authenticator on the device where your existing Passkey works.
- Select your FAU account.
- Select Update Security Information.
- Sign in and approve the existing authentication request.
- Open Security Info.
- Select Add sign-in method.
- Select Microsoft Authenticator.
- Follow the Microsoft prompts to pair your account with the app and enable push notifications.

Microsoft may temporarily block an account when unusual or risky sign-in activity is detected.
This may occur after:
- Denying a Microsoft Authenticator sign-in request
- Sign-in locations changing rapidly while using a VPN
- Other sign-in behavior Microsoft identifies as risky

To reactivate the account:
- Go to FAU Account Self-Service.
- Select Forgot Your Password.
- Complete the password reset process.
- Wait approximately 5–10 minutes for the systems to synchronize.
- Try signing in again.
Important: You must complete the password reset even if you believe your current password is correct.
This message may appear when FAU detects an anonymizing VPN or proxy service while you are attempting to access university resources.

To resolve the issue:
- Disconnect from third-party or anonymizing VPN/proxy services.
- Disable services such as iCloud Private Relay if they are active.
- Try accessing the FAU service again.
If the error continues after anonymizing services have been disabled, contact the FAU OIT Help Desk.
Other Authentication Methods
Microsoft Authenticator is the recommended MFA method, but other authentication methods may be available depending on your account and circumstances.
An SMS-capable phone number may be used as an authentication or account-recovery method when available for your account.
Microsoft Authenticator is recommended when possible because it provides push approval directly through the app.
Supported hardware tokens, such as a YubiKey or FAU-provided hardware FOB, may be used in place of a smartphone in certain situations.
Employees who do not have access to a smartphone may contact the FAU OIT Help Desk to request information about obtaining a hardware FOB.
A Passkey is a valid authentication method but may be tied to a particular device.
If a Passkey prevents you from signing in on a lab, classroom, shared, or different computer, add Microsoft Authenticator as a sign-in method and use push notifications instead.
See Stuck at a Passkey Prompt under Troubleshooting for instructions.
Still Need Help?
Contact the FAU OIT Help Desk if:
- You cannot receive a Temporary Access Pass.
- You no longer have access to any MFA or recovery method.
- Your account remains blocked after completing the required password reset.
- You need assistance registering a new MFA device.
- You need information about obtaining a hardware authentication device.
Phone: 561-297-3999