Applies to: All users with a company Microsoft 365 account
Time required: About 5 minutes
What you'll need: Your smartphone and a computer
Why you're being asked to do this
Multi-factor authentication (MFA) adds a second step when you sign in — a quick tap on your phone — so that a stolen password alone can't be used to access your email or files. MFA is required on all Microsoft 365 accounts we manage. Setting it up takes a few minutes and only has to be done once.
Step 1: Install the Microsoft Authenticator app on your phone
- Open the App Store (iPhone) or Google Play Store (Android) on your phone.
- Search for Microsoft Authenticator.
- Install the app. It's free, and the publisher should show as Microsoft Corporation.
⚠️ Watch out for look-alike apps. Only install the one published by Microsoft Corporation.
Don't open the app yet — the next steps start on your computer.
Step 2: Start enrollment on your computer
- On your computer, open a web browser and go to: https://aka.ms/mfasetup
- Sign in with your work email address and your usual password.
- If you see a message that says "More information required," click Next. Otherwise, you'll land on your Security Info page — click + Add sign-in method and choose Authenticator app.
Step 3: Link your phone to your account
- On the computer screen, click Next until a QR code appears.
On your phone, open the Microsoft Authenticator app.
- If asked, allow notifications — you'll need them for sign-in approvals.
- Tap + (or Add account) → choose Work or school account → Scan a QR code.
- Point your phone's camera at the QR code on your computer screen.
- Your work account will appear in the app. Click Next on your computer.
Step 4: Approve the test notification
- Your computer will display a two-digit number and send a test notification to your phone.
- On your phone, tap the notification, enter the two-digit number shown on your computer, and tap Yes/Approve.
- Your computer will confirm the notification was approved. Click Next, then Done.
That's it — you're enrolled. ✅
Step 5 (recommended): Add a backup method
If your phone is ever lost, dead, or replaced, a backup method lets you still sign in.
- While you're still on the Security Info page (https://aka.ms/mfasetup), click + Add sign-in method.
- Choose Phone, enter your mobile number, and select Receive a code via text.
- Enter the code that's texted to you to confirm.
What to expect after setup
- Most of the time, signing in works exactly like before.
- Occasionally — on a new device, after a password change, or periodically for security — you'll get a notification on your phone asking you to approve the sign-in. Enter the number shown on your screen and tap Approve.
- If you get an approval request you didn't trigger, tap "No, it's not me" / Deny and report it to the service desk right away. That can be a sign someone else has your password.
Troubleshooting
The QR code won't scan.
Increase your computer screen's brightness, or click "Can't scan the QR code?" on your computer for a code you can type into the app manually.
I didn't get the notification on my phone.
Make sure notifications are enabled for the Authenticator app and that your phone has an internet connection. In the app, pull down on the account list to refresh.
I got a new phone.
Install Microsoft Authenticator on the new phone, then go to https://aka.ms/mfasetup on your computer and add it as a new sign-in method. If you no longer have access to your old phone or your backup method, contact the service desk and we'll reset your enrollment.
I'm stuck or locked out.
Contact the service desk — see below.
Need help?
Submit a ticket through this help center or email your organization's designated service desk address — these are the fastest ways to reach us and the only channels we can guarantee response times on.
- Support portal: use the Submit a Ticket option in this help center
- Email: your organization's designated service desk address (provided during onboarding)
- Hours: Monday–Friday, 9:00 a.m.–5:00 p.m. Central
Please don't text or direct-message individual technicians — requests sent that way aren't tracked in our ticketing system and may be missed.