MFA | How to configure MFA on your Cobleskill account

Table of Contents

This article contains different sections as listed below. If you would like to skip around the article and know where you would like to go, you can click on any of the contents of this article listed below and you will be direct to the section of your choosing.

Overview

Multi-Factor Authentication (MFA), 2-Factor(2FA), or 2-Step Verification (2-Step) adds a second layer of security to your SUNY Cobleskill account by requiring you to approve sign-ins from an external source such as your mobile device using the Microsoft authenticator app, passkeys on your mobile device, a FIDO security key, or Windows Hello for Business on your personal or state device. Every Cobleskill account must have MFA enabled and configured regardless if you are a student, faculty, staff, emeritus, retiree, volunteer, etc.

Background - Various MFA Methods

Currently there are five supported multi-factor authentication methods you can configure on your Cobleskill account:

  • Method #1 Microsoft Authenticator App Push (number matching)
  • Method #2 Passkey
  • Method #3 Windows Hello for Business
  • Method #4 Passwordless Sign-in with the Microsoft Authenticator App
  • Method #5 FIDO Security Key

 

Important:

To ensure that you are always able to access your account, It is highly recommended that you configure at a minimum 2 of the above authentication methods, ideally 3. One should be configured as a primary authentication method on one device and another should be configured as a backup on a separate device different than you primary. Should the device that you have a primary authentication method no longer function you have a backup saved on a different device.

When you are configuring your MFA methods majority of the time you will be navigating to the Security Info page(opens in new tab) under your account

Tip:

If you already know how to configure the various authentication methods and would simply like to change them you can do so by visiting the security Info page(opens in new tab)

Prerequisites Before Configuring MFA

Depending on what MFA method you are considering to configure on your Cobleskill account, there are prerequisites that you must fulfill before proceeding with the instructions in this knowledge base article:

  • Access to your Cobleskill account
  • A smartphone device that is running Android version 14 or later or running iOS version 17 or later.
  • Microsoft Authenticator App installed on your Android or IOS device to configure passkeys, Passwordless Sign-in with the Microsoft Authenticator App, or Microsoft Authenticator App Push (number matching)
  • A personal or state laptop or desktop computer to configure Windows Hello for Business.
  • A FIDO security key to configure as an MFA method

Again not everything listed above is something that you will need but the more that you have checked off the list above the better.

Incoming Students - Configuring MFA While Activating your Student Account

Tip:

This section is intended for those who are just logging into their Cobleskill account for the first time. If this is not the first time you have logged into your Cobleskill account you can skip this section.

If you are activating your Cobleskill account for the first time, you may be prompted to configure the authenticator app after you enter your password. The steps in this section will walk you through what you will need to do to successfully configure Multi-factor authentication.

  1. After you have reset your password using Microsoft SSPR to claim your account and you begin to log into your Cobleskill account on Outlook - you will see a message that says More information is required. Select Next to continue.
The More information required prompt begins the MFA setup.
 
The More information required prompt begins the MFA setup.
  1. The next pop up will tell you to begin installing the Microsoft Authenticator app, which is available on the Google play store or the Apple App Store. If you click on the Google Play or App Store buttons as shown in the image below you can confirm what the app look like on Android or Apple respectively.
The image directs you to install the Microsoft Authenticator app to proceed.
 
The image directs you to install the Microsoft Authenticator app to proceed.
  1. Once you have downloaded the Microsoft Authenticator app on your mobile device, on the computer click on next and you will be prompted to set up your Cobleskill account on the authenticator app before proceeding
The image directs you to add your Cobleskill account on the authenticator app after you have installed it on your mobile device.
 
The image directs you to add your Cobleskill account on the authenticator app after you have installed it on your mobile device.
  1. on the computer, click next and you will be presented with a QR code on the computer screen that you will scan with your phone in the Microsoft Authenticator app.
The image displays a QR code to be scanned from the authenticator app on your phone.
 
The image displays a QR code to be scanned from the authenticator app on your phone.
  1. On your mobile device, when you open the authenticator app for the first time you will prompted with several options, select the option, scan a QR code.
The image displays what you would see when you open the authenticator app for the first time.
 
The image displays what you would see when you open the authenticator app for the first time.
  1. After selecting scan a QR code, you will be prompted to adjust your phone permissions to allow the authenticator app to access your camera in order to scan the QR code presented on your computer screen. Select Allow or OK. See the image below for what you might see.

The image displays a prompt stating that the authenticator app would like permissions to access your devices camera to scan the QR code on your computer screen
The image displays a prompt stating that the authenticator app would like permissions to access your devices camera to scan the QR code on your computer screen
  1. Once you have allow the authenticator app access to your devices camera, you can use your phone's camera in the app to scan the QR code on the computer
The image displays the phone camera being used on the authenticator app to scan the QR code on the computer screen
The image displays the phone camera being used on the authenticator app to scan the QR code on the computer screen
  1. After scanning the code you may get a prompt stating if you would like to allow the authenticator app to send you notifications on your phone. Select Allow
The image displays a prompt indicating if you would like to allow the authenticator app to send you notifications.
 
The image displays a prompt indicating if you would like to allow the authenticator app to send you notifications.
  1. After approving the notification permission, you should see the following image below on the computer screen, this will test the authenticator app to ensure that it functioning as intended and that you understand what you will see when you log into your Cobleskill account using the authenticator app.
The image displays a message that is testing the authenticator app functionality and is showing a number that will need to be typed into the authenticator app on your mobile device. 

The image displays a message that is testing the authenticator app functionality and

is showing a number that will need to be typed into the authenticator app on your mobile device.

  1. The number you see on your computer screen will need to be typed into the authenticator app on your mobile device.
The image displays the authenticator prompt that prompts you to put in the number you see on your computer screen as seen in the previous step.
 

The image displays the authenticator prompt that prompts you to put in the number

you see on your computer screen as seen in the previous step.

  1. After the authenticator app is tested and successful you should see the following image that confirms it was successful.
 The image displays a message indicating that the authenticator app has been added successfully.
The image displays a message indicating that the authenticator app has been added successfully.
  1. Click done and it should bring you into your Cobleskill email Inbox.
  2. If configuring the authenticator app was successful, you can confirm this by opening the Microsoft authenticator app on your phone and one of the entries listed should be your SUNY Cobleskill account, similar to the image below:
The image displays how the Microsoft authenticator app looks like after successful configuration, with an entry that says State University of New York and your Cobleskill email address below it. 

The image displays how the Microsoft authenticator app looks like after successful configuration,

with an entry that says State University of New York and your Cobleskill email address below it.

Important:

Once you have successfully installed and configured the authenticator app it is highly recommended to install another multi-factor authentication method so that you always have access to your cobleskill account and you do not get locked out of your Cobleskill account. You can either continue below and configure one of the other MFA methods or you can scroll to the table of contents and select one of the methods supported links to be take to that section in this article.

MFA Method #1 Microsoft Authenticator App Push (number matching)

Similar to the section before but this is assuming that this is not your first time logging into your cobleskill account.

Install the Microsoft Authenticator App

  1. Download the Microsoft Authenticator app on your phone from the appropriate store:
  2. Open the app after it finishes installing.

Once the app is installed, choose one of the two methods below to connect it to your account.

Which method should I use?

Method 1 (web browser) is recommended — it gives you more control, walks you through each step on-screen, and makes scanning the QR code straightforward. Method 2 (app) is quicker but requires you to already have a way to sign in.

Method 1 — Set Up Through a Web Browser (Recommended)

  1. On your computer, go to the Microsoft Security Info page (opens in new tab) and sign in with your Cobleskill username and password.
  2. Click Update info under the tile labeled Security info.
    The Security info tile on the My Account page.
    The Security info tile on the My Account page.
  3. Click + Add sign-in method.
    Uploaded Image (Thumbnail)
    The Add sign-in method button on the Security info page.
  4. Select Microsoft Authenticator App from the list
  5. Click Add.
    Click Add to confirm the Authenticator app selection.
    Click Add to confirm the Authenticator app selection.
  6. Click Next twice to proceed to the QR code screen.
  7. On your phone, open the Authenticator app, accept the privacy agreement, and select Scan a QR code.
  8. Use your phone’s camera to scan the QR code displayed on your computer screen.
  9. Once scanned, the browser will send a test approval request to the app. Approve it on your phone.

Once the test approval is complete, MFA is set up. You will be prompted to approve sign-ins on your phone going forward.

Method 2 — Set Up Through the App Directly

  1. Open the Microsoft Authenticator app on your phone.
  2. Accept the privacy agreement terms.
  3. Select Add work or school account.
  4. Sign in with your Cobleskill account (username@cobleskill.edu).
  5. Complete any authentication prompt (text, call, or existing session).
  6. Once signed in, test the setup by opening your campus email (opens in new tab) in a browser and approving the MFA prompt.

Once the test approval is complete, MFA is set up. You will be prompted to approve sign-ins on your phone going forward.

MFA Method #2 Configuring a Passkey

If you have the authenticator app configured as per the previous section, you would just need to navigate to the authenticator app on your mobile device to configure the passkey.

Configure your Passkey

1. Navigate to the Microsoft Authenticator app and select the SUNY Cobleskill account.

SUNY Cobleskill account on Authenticator app
SUNY Cobleskill account on Authenticator app

2. Choose the "Create a passkey" option

Create a passkey option on the Authenticator app
Create a passkey option on the Authenticator app

3. You would be prompted to sign in to create a passkey

Prompt to sign in
Prompt to sign in

4. Once you sign in, the passkey will be created and added to the authenticator app.

Prompt to sign in
Prompt to sign in

5. To confirm if your passkey is configured properly, select your SUNY Cobleskill account on the Microsoft Authenticator App and passkey should be under "Ways to sign in or verify". If you click on Passkey, you should see your account information.

Passkey configured correctly
Passkey configured correctly

6. If you click on Passkey, you should see your account information.

Configured passkey
Configured passkey

Sign-in with your passkey

1. Enter your username and click on "use your face, fingerprint, PIN, or security key"

Sign in Options
Sign in Options

2. Choose iphone, ipad or Android device

Passkey Options
Passkey Options

3. Scan the QR code with your mobile device to sign in.

Scan QR code with mobile device
Scan QR code with mobile device

MFA Method #3. Configuring Windows Hello for Business

1. Go to the settings app on your device and navigate to Accounts

Accounts page in settings
Accounts page in settings

2. Click on sign-in options

Sign-in options in Accounts
Sign-in options in Accounts

3. Select PIN, fingerprint or facial recognition option based on the method you want to configure. For setting up a PIN, select PIN (Windows Hello) option and click set up.

PIN Set up for Windows hello
PIN Set up for Windows hello

4. You will see a pop-up to set up Windows Hello with your account. Click on "OK". Authenticate if prompted.

PIN Set up for Windows hello
PIN Set up for Windows hello

5. Set up a new PIN. The PIN needs to be at least 6-digits long.

PIN Set up for Windows hello
PIN Set up for Windows hello

5. When signing in, choose the windows hello option.

Sign in page
Sign in page

6. Enter your PIN to login.

Enter the PIN to login.
Enter the PIN to login.

MFA Method #4. Configuring Passwordless Sign-in with the Microsoft Authenticator App

1. Navigate to the Microsoft Authenticator app and select the SUNY Cobleskill account.

SUNY Cobleskill account on Authenticator app
SUNY Cobleskill account on Authenticator app

2. Choose the "Set up passwordless sign-in requests" option

Create a passwordless sign-in option on the Authenticator app
Create a passwordless sign-in option on the Authenticator app

3. You will get a prompt to register your device so that you can sign-in without a password on your device. Click on continue.

Passwordless sign-in option
Passwordless sign-in option

4. You will be prompted to verify your identity and Authenticate

Authentication prompt
Authentication prompt

Wait for the device to register.

MFA Method #5. Configuring a FIDO Security Key

Prerequisites

  • A smartphone (Android or iOS) with internet access or a laptop or desktop computer
  • An existing way to authenticate (authenticator app, passkey or an active session) if you are current Student/Faculty/Staff
Important:

Both setup methods below require you to already have a working authentication method (phone call, text, or active session). If you have no existing method, contact the IT Service Desk for assistance.

Method 1 - Set up FIDO key using USB option (for desktops or laptops)

1.  Access the following site with your Cobleskill username/password: Microsoft Security Info page (opens in new tab)

2.  Click on "Update info" under "Security Info"

The Security info tile on the My Account Page

The Security info tile on the My Account Page

3.  Click on "Add sign-in Method"

The Add Sign-in Method button
The Add Sign-in Method button

4.  Select the "Security key / Passkey" option from the drop-down list.

Selecting passkey from the list
Selecting passkey from the list

5. Click on try using another device option if you see this pop-up

Windows Hello prompt
Windows Hello prompt

6. Click on USB Device

Select USB device option
Select USB device option

7. You will be redirected to a new page. Choose Security key option in the next prompt.

Prompt to Select Security Key
Prompt to Select Security Key

8. Once you choose the security key option, insert the FIDO key in the USB-A port when prompted.

Prompt to insert YubiKey
Prompt to insert FIDO key

9. Enter a PIN for the key, confirm it and click on OK

Create a PIN for YubiKey
Create a PIN for FIDO key

10. When prompted, touch the small yellow circle in the middle of the key.

Prompt to touch yubiKey
Prompt to touch FIDO key

11. Once the process is complete, you will be asked to give a name to your security key. Enter an identifiable name to the key and save.

Method 2 - Set up FIDO Key using the NFC Option (for mobile devices)

Follow Steps 1–4 from the "Set up FIDO Key using USB" section above, then continue with Step 5 below

5. Click on NFC Device

Select NFC device option
Select NFC device option

6. On a new window, you will see a pop up:

Prompt to hold the YubiKey near the top of the device
Prompt to hold the FIDO key near the top of the device

7. Bring the FIDO key near the top of the phone.

Prompt to insert YubiKey
Prompt to insert FIDO key

8. A pop up will appear asking you to set up a PIN for the key. Enter a PIN for the key, confirm it and click on OK.

Create a PIN for YubiKey
Create a PIN for FIDO key

9. Place the FIDO key near the top of the phone again if asked.

10. Once the process is done, you will be asked to give a name to your security key. Enter any identifiable name to the key and save.

To Use FIDO key for Authentication

Important:

Once you have set up the FIDO key, you will be able to use it as both a USB and a NFC device when required.

1. Login to your account using your username and password.

2. Insert the FIDO key in the USB port of the device or bring it near the top of the phone.

3. Enter your PIN and touch the small yellow circle in the middle of the key (touching the key only applies if you inserted your FIDO key into the device you are using to authenticate).

Enter the PIN
Enter the PIN

To Use FIDO Key for Password less login

1. Go to webmail.cobleskill.edu and click on sign-in options at the bottom of the page

Select Sign-in Options on the Login Page
Select Sign-in Options on the Login Page

2. Click on Face, Fingerprint, PIN or Security key option

Select face, fingerprint, PIN or security key option
Select face, fingerprint, PIN or security key option

3. Select Security Key on the next 

Select the Security Key option
Select the Security Key option

4. Insert the FIDO key in the USB port of the device or bring it near the top of the phone., enter PIN and touch the key when prompted (touching the key only applies if you inserted your FIDO key into the device you are using to authenticate).

To remove this method of Authentication

1. Access the following site with your Cobleskill username/password: Microsoft Security Info page (opens in new tab)

2.  Click on "Update info" under "Security Info"

The Security info tile on the My Account Page

The Security info tile on the My Account Page

3. Click on the delete button for the passkey.

Delete passkey button
Delete passkey button

Potential Issues You May Encounter

Scenario 1 – You only have one authentication method

If you only have one authentication method and the following applies to you:

  • You forgot your phone at home that has the Microsoft authenticator app installed
  • you forgot your FIDO key at home
  • You forgot your laptop with Windows Hello for Business at home
  • You get a new phone. and wiped your old phone which had the Microsoft authenticator app configured with your account
  • You reset your phone to factory settings which had the Microsoft authenticator app configured
  • You delete the Microsoft authenticator app which had your cobleskill account configured
  • You wipe or clear the Microsoft authenticator app's data which had your cobleskill account configured

you will be locked out of your account and become unable to authenticate or complete the multi-factor authentication challenge in any of the situations above.

How to prevent it: add a second authentication method during initial MFA setup or by visiting the Security Info page. If you already lost access, you will need to contact the IT Service Desk at 518-255-5800 to recover your account or you can submit a ticket using the Login, Password & MFA Help (opens in new tab) service request.

How to fix it after the fact: If you have an alternate method, sign in at the Security Info page (opens in new tab) and set up the Authenticator app again on your current device. Or you will need to contact the IT Service Desk at 518-255-5800 to recover your account or you can submit a ticket using the Login, Password & MFA Help (opens in new tab) service request.

Scenario 2 – You were unsuccessful in configuring the authenticator app

If for some reason you run into an error message when configuring the authenticator app or when you attempt to configure an MFA method, you can try re-installing the authenticator app and try the process from the beginning and see if that clears up any errors you may get.

Scenario 3 – You receive an error when attempting to configure a passkey

When configuring a passkey you have a relatively short window to setup the passkey, if for some reason during the configuration process you get distracted by something and you come back to what you were doing 5-10 minutes later you will see an error that the passkey configuration was not successful. Simply try again and you should not have that error.

Additionally, ensure that you are not on a VPN as this may interfere with the passkey registration process

Need Help?

If you need assistance or require this information in an alternate format, contact the IT Service Desk:

Location
Warner 016
Phone
(518) 255-5800
TDX Portal
Submit an MFA Support Request (opens in new tab)

This article has been adjusted for EIT standards – 08/21/26 | Wren Rowan