By setting up Multifactor Authentication (MFA), you add an extra layer of security to your Microsoft 365 account sign-in. For example, you first enter your password and, when prompted, you also type a dynamically generated verification code provided by an authenticator app or sent to your phone via text. You will not have to authenticate everytime you sign in, but you will need to authenticate when using a new device.
A guide on How to set up MFA & SSPR can be found below.
Self-Service Password Reset (SSPR) is a feature of Microsoft 365 that enables users to reset their passwords without contacting IT staff for help. Once you have provided the required information you will be responsible for reseting your own password.
Example of using SSPR to reset your password
Before the 4th of July 2022
To set up MFA please click the link to your security information and follow the steps below.
Click on the link above to access the security information page of your account and click "Add sign-in method"
Select the sign-in method you would like to use from the drop down menu. For this guide we will be using the Authenticator app.
This is the recommended method for security and usability. Other methods are available however Office Phone is not an option as we use Teams Telephony for our office phones.
Select Authenticator app and click next.
You will then be prompted to download the authenticator app on your mobile phone.
Follow the prompt on the app to add an account and select "Work or school" account.
When prompted to do so scan the QR code on screen.
Once you ahve scanned the QR your account will connect to the app. You will then receive a prompt on the phone screen to authenticate. Click approve on the phone screen, Once this has been approved you will be able to click next.
Once you have completed this process you will be returned to the Security information screen.
After the 4th of July 2022
Head to office.com on your preferred browser and sign in, as you sign in you will be prompted to provide "more information". Follow the on screens guidance to set up your Microsoft Authenticator App and provide your verification information.
More information from Microsoft.
If you are already signed into Microsoft 365 you can reset your password from your web browser. From your Microsoft 365 Home page or any 365 online application click on your intitals (or profile picture) in the top right hand corner.
From the My Account window you will have the option to "Change Password".
This will open a new window where you will need to enter your current password and provide a new password. Finaly click submit.
If you need to reset your password because you can't sign in, open office.com in a browser and, click to sign-in and then click on "can't access your account?" and follow the wizard which will use MFA to authenticate your identity and allow you to reset your password.
Alternatively click here Microsoft Online Password Reset to go straight to the reset password wizard.
The video below demonstrates the steps taken.
Download and install the Microsoft Authenticator app from your supported AppStore on your mobile phone or mobile device. Links provided below or search Microsoft Authenticator on your mobile's AppStore.
Android: Download Authenticator for Android
Windows Phone: Download Authenticator for Windows Phone
During the set up process you can opt to have your verifications sent to you by text message or by a voice call service. You cannot choose Office Phone. We use Microsoft Teams for our office phones, this means you need to be signed into your Microsoft account to recieve calls. Alternatively you can set up an email address to recieve your verification code, follow this guide from Microsoft.
To access Office 365 you need to use Office online. Please visit office.com and sign in using your E Number@uos.ac.uk For example: E1234567@uos.ac.uk. When working off campus you will be prompted to enter your password as well.
PLEASE NOTE, If you try to log in using your name format, for example J.Smith@uos.ac.uk, you will NOT be able to log in, you must use your E Number@uos.ac.uk
Select "View Account".
Under Security info, select Update info.
Here you can remove your phone number or authenticator app and add a new method.
You will not need to authenticate everytime you sign in but you will need to authenticate each time you use a new device or a new web browser.
Multi-Factor Authentication (otherwise known as MFA or ‘two-step verification’) is a security feature included with Office 365 that protects your Office 365 account. MFA effectively makes it far more difficult for unauthorised users to access your account, thus providing a further layer of protection for your data. MFA differs from using only a traditional username and password in that it also requires confirmation of the device that you are accessing your account from.
The two methods that are commonly used to prove your identity and your username and password are correct via a unique item that you have(e.g mobile phone).
When logging in with MFA, you must supply your username/password AND additionally prove that you are in possession of that unique, trusted device.
Due to the ongoing threat of internet based data breaches, it is a requirement that MFA is enabled when accessing Office 365 enabled applications to protect Staff and Student Office 365 linked user accounts. This means that you will be required to set up MFA if you are accessing Office 365.
Self-Service Password Reset (SSPR) is a feature of Microsoft 365 that enables users to reset their passwords without contacting IT staff for help. Once you have provided the required information YOU will be responsible for reseting your own password.