Skip to main content
Document

Using the Microsoft 365 Authenticator app

  • Last updated:

Complete Multi-Factor Authentication (MFA) using the Microsoft Authenticator app previously installed and set up on your smartphone.

To print this document, go to File and select Print (Control+P in Windows or Command+P in Mac). You can also choose to save as PDF file from there. Note: Scroll to the bottom of this page to ensure all images are printed.

Being notified

  1. When trying to use Microsoft Office 365 through a web browser, mobile app, or desktop application, you might be prompted to complete MFA before being allowed to access your account.
  2. Before the MFA prompt, you might be prompted to log in to Office365. If you are, do so as normal using your Cardiff University email address and password.
    • Those without a Cardiff University email address (and only a username) must enter the username followed by ‘@cardiff.ac.uk’.
  3. You will be notified that this sign-in attempt needs further approval through MFA and that Microsoft has sent a notification to the smartphone on which you previously set up the Microsoft Authenticator app.
  4. Your smartphone should then show a pop-up notification (or message on the lock screen) from the Microsoft Authenticator app asking you to enter the two digits displayed and click Yes. If you have not been asked for this, select No, it's not me.
Screenshot of the 'Approve sign-in request' screen showing two digits
Screenshot of the 'Approve sign-in request' screen showing two digits
Zoom inOpen expanded view
Screenshot of the 'Are you trying to sign in?' screen
Screenshot of the 'Are you trying to sign in?' screen
Zoom inOpen expanded view

  1. If the Microsoft Authenticator app lock is active, you will need to enter your smartphone unlock code, or biometric (such as fingerprint or face recognition) before your response will be accepted.
  2. If you are unable to respond to the notification in a timely manner, you will be offered another chance by clicking Send another request to my Microsoft Authenticator app.
Screenshot of the 'We didn't hear from you' screen showing the 'Send another request to my Microsoft Authenticator app' message
Screenshot of the 'We didn't hear from you' screen showing the 'Send another request to my Microsoft Authenticator app' message
Zoom inOpen expanded view

If your phone does not have an active data or phone signal connection when asked to use MFA, you can use the six-digit one-time password codes generated by the Microsoft Authenticator app:

  1. On your smartphone, open the Microsoft Authenticator app, and tap into your Cardiff University account. You will see a one-time password code displayed on screen, which is a six-digit code that is replaced every 30 seconds.
Screenshot of a one-time password code
Screenshot of a one-time password code
Zoom inOpen expanded view

  1. Go back to the login screen where you are being asked to authenticate and click I can’t use my authenticator app right now.
Screenshot of the 'We didn't hear from you' screen showing the 'Enter a security code from your Microsoft account or authenticator app instead' message
Screenshot of the 'We didn't hear from you' screen showing the 'Enter a security code from your Microsoft account or authenticator app instead' message
Zoom inOpen expanded view
Screenshot of the 'Approve sign-in request' screen showing the 'I can't use my Microsoft Authenticator app right now' message
Screenshot of the 'Approve sign-in request' screen showing the 'I can't use my Microsoft Authenticator app right now' message
Zoom inOpen expanded view

  1. Select Use a verification code.
  2. Enter the six-digit code shown on the app and click Verify.

You must enter the code and click verify before the 30 seconds shown on the Microsoft Authenticator app expire. Otherwise, the code will be invalid, and you must try again.

The Enter code message should disappear from the web browser, mobile app, or desktop application you were using, giving you access to your account.

Screenshot of the 'Verify your identity' screen showing the 'Use a verification code' option
Screenshot of the 'Verify your identity' screen showing the 'Use a verification code' option
Zoom inOpen expanded view
Screenshot of the 'Enter code' screen with the 6 digits from the one-time password code
Screenshot of the 'Enter code' screen with the 6 digits from the one-time password code
Zoom inOpen expanded view

Signing in with the Authenticator app as an alternative method

  1. If you are prompted to complete MFA using your default method (phone call or browser extension), and instead you want to use the Microsoft Authenticator app that you have previously set up, you can click on sign in another way. Or click on the left-pointing arrow found to the left of your email address.
Screenshots of the 'Approve sign-in request' screen showing the 'Having trouble? Sign in another way' message and the 'Enter code' screen showing the grey left-pointing arrow next to the email address
Screenshots of the 'Approve sign-in request' screen showing the 'Having trouble? Sign in another way' message and the 'Enter code' screen showing the grey left-pointing arrow next to the email address
Zoom inOpen expanded view

  1. You will then be presented with a set of options on how to complete MFA. The exact options will depend upon which MFA methods you have previously configured.
  2. It is highly recommended that you set up several methods of completing MFA to ensure you can still access your account should you encounter difficulties with one of the methods.

  3. To use the Microsoft Authenticator app, click on Approve a request on my Microsoft Authenticator app.
Screenshot of the 'Verify your identity' screen showing the 'Approve a request on my Microsoft Authenticator app' option
Screenshot of the 'Verify your identity' screen showing the 'Approve a request on my Microsoft Authenticator app' option
Zoom inOpen expanded view

Setting the Microsoft Authenticator app as the default method

If you have configured another MFA method (such as an automated phone call or a different authenticator application) as your default method, you can alter this to make the Microsoft Authenticator app the default.

  1. To start the process, use a web browser to navigate to https://aka.ms/mfasetup.
  2. You will be prompted to log in to Office365 using your Cardiff University email address and password. You might be challenged to complete MFA using one of the methods you have already set up.
    • Those without a Cardiff University email address (and only a username) must enter the username followed by ‘@cardiff.ac.uk’.
  3. After successfully logging in, you will be taken to the My Sign-ins page where you can review the MFA methods you have already set up so far. Next to Default sign-in method: click on Change.
Screenshot of the 'My sign-ins' screen showing the 'Change' option next to your default sign-in method
Screenshot of the 'My sign-ins' screen showing the 'Change' option next to your default sign-in method
Zoom inOpen expanded view

  1. Pick Microsoft Authenticator – notification from the list of options.
Screenshot of the 'Change default method' screen showing the 'App based authentication – notification' from the list of options
Screenshot of the 'Change default method' screen showing the 'App based authentication – notification' from the list of options
Zoom inOpen expanded view

  1. The default sign-in method will now show Microsoft Authenticator – notification.
Screenshot of the 'My sign-ins' screen showing the 'App based authentication – notification' as your default sign-in method
Screenshot of the 'My sign-ins' screen showing the 'App based authentication – notification' as your default sign-in method
Zoom inOpen expanded view

  1. If you want to rename the entry for your account within the Microsoft Authenticator app, open the app on your smartphone, tap into your Cardiff University account, and then tap on the cog icon in the top right hand corner of the screen.
Screenshot of the 'One-time password code' screen showing the cog icon in the top right hand corner
Screenshot of the 'One-time password code' screen showing the cog icon in the top right hand corner
Zoom inOpen expanded view

  1. Tap Account name to be able to enter a new description for how the app will refer to the account. Note this only affects how the Microsoft Authenticator app lists this account on your smartphone.
  2. If you need to remove this account from the Microsoft Authenticator app completely (for example because you need to undertake set up again on this or a different smartphone) tap on Remove account. If you understand the consequences of continuing (see note below), and are happy to proceed, tap as appropriate to confirm.

Before you remove your account from the app, ensure that you have set up the Microsoft Authenticator app on another smartphone and confirmed that it is functioning correctly with your account or that you have other methods of completing MFA already set up and confirmed as working. Otherwise, you will find that you cannot complete MFA and will be locked out of your account.

Screenshot of the 'Account settings' screen showing the 'Account name' option
Screenshot of the 'Account settings' screen showing the 'Account name' option
Zoom inOpen expanded view

Phone sign-in has not been configured and enabled at Cardiff University. If you accidentally activate this function, it will change your MFA experience but will not operate correctly, resulting in errors.

  1. If your MFA prompt asks you to tap a corresponding two-digit number on the Microsoft Authenticator app or if you receive an error message indicating that Your company policy requires that you use a different method to sign in, then you need to deactivate phone sign-in.
Screenshot of the 'Approve sign-in request' screen showing two digits and the 'Tap the number you see below in your Microsoft Authenticator app to sign in' message
Screenshot of the 'Approve sign-in request' screen showing two digits and the 'Tap the number you see below in your Microsoft Authenticator app to sign in' message
Zoom inOpen expanded view
Screenshot of the 'Choose a way to sign in' screen showing the 'Your company policy requires that you use a different method to sign in' message
Screenshot of the 'Choose a way to sign in' screen showing the 'Your company policy requires that you use a different method to sign in' message
Zoom inOpen expanded view

  1. Open the Microsoft Authenticator app on your smartphone and tap into your Cardiff University account. Then tap disable phone sign-in and Confirm.
  2. The app should now show enable phone sign-in, indicating that phone sign-in has been successfully disabled.
Screenshot of the 'One-time password code' screen showing the 'Enable phone sign-in' option
Screenshot of the 'One-time password code' screen showing the 'Enable phone sign-in' option
Zoom inOpen expanded view