TRU offers several MFA methods. Choose the strongest option from the list below that you can comfortably deploy. Methods are available for all students, faculty, and staff with a few exceptions.
/w exceptions #1: certain departments (such as IT), individuals, and roles are considered high-value targets for attackers. As a result, these users have been issued FIDO2 security keys (YubiKeys) by the Information Security department and are restricted to phishing-resistant MFA methods.
/w exceptions #2: Synced keys are not available on Windows 10 (Final Version: 22H2 October 2025 - no further feature updates). Those wishing to use synced keys should upgrade to Windows 11.
|
Rating
|
Availability
|
Primary Method
|
Comments
|
|
F
|
None
|
SMS/Voice
strength: weak
|
Discontinued as of Februrary 1, 2027. Microsoft is no longer allowing sms/voice as an MFA option. All users must have at least MS Authenticator before this date.
|
|
B / B+
|
All /w exceptions #(1)
|
MS Authenticator
strength: strong
|
Minimum MFA. Various options available (ex: push notifications). Might still be susceptible to human error allowing MFA bypass through phishing.
|
|
B+ / A-
|
All /w exceptions #(1,2)
|
Synced keys
strength: (near) phishing resistant
|
Convenient option. Can be a good choice If configured properly. Unlikely success of a phishing attack and especially useful to prevent "account lock-out". See related articles section for instructions on creating and using synced passkeys.
|
|
A-
|
All
|
MS Authenticator /w Passkey
strength: phishing-resistant
|
Offers phishing resistant protection via a registered smartphone. However, can only log into devices with Bluetooth (mobile devices). Consequently, may make a better secondary MFA method in the event primary method is unavailable as you can still log into your smartphone and change your MFA settings if you need to.
|
|
A
|
All
|
FIDO2
strength: phishing-resistant
|
Best phishing resistant option. Works with any hardware device capable of FIDO2.
https://www.amazon.ca/s?k=fido2
|