Secure Your SUNY Oswego Account with Multi-Factor Authentication (MFA)
Your Laker NetID is now protected with Multi-Factor Authentication (MFA), adding a crucial second layer of security beyond just your password. This helps safeguard your digital identity and university resources from unauthorized access. Just like online banking uses a code sent to your phone, MFA verifies it's truly you logging in.
MFA is required for all SUNY Oswego Laker NetID accounts. To ensure comprehensive protection, we utilize two distinct MFA methods:
- Google MFA (2-Step Verification): For securing your Google Workspace services (Gmail, Drive, Docs, etc.), aka LakerApps.
- Microsoft MFA: For securing various other university digital services, including but not limited to, Brightspace, myOswego, Adobe, and Office 365.
Each method requires its own one-time setup. Please use the dedicated sections below for detailed configuration instructions.
Google MFA Enrollment
Recommended Setup: Google Prompts or the Microsoft Authenticator app (push notifications or verification codes) with backup phone number(s).
How to Enroll:
- Follow the instructions for how to Turn on 2-step verification using a computer and a phone. Google has a Guidebook for how to Set Up 2-Step Verification, as well.
- Sign into the Gmail app (available in the Apple or Google Play stores) and select your profile icon, then Security to locate the 2-Step Verification section or navigate to Account Tools page on a browser and select Change your Google MFA options.
- If you have a personal Gmail account already signed in, click your profile icon in the upper right and choose “Add another account” and then “Google” to sign in with your SUNY Oswego credentials.
- Choose your methods:
- Google Prompts: Follow the on-screen instructions to confirm your smartphone. This sends a "Yes/No" notification for quick approval.
- Phone number: Receive a call or text message with a one-time code.
- Optional: Add a backup phone number such as an office phone number for recovery.
- Authenticator App*: Download the Microsoft Authenticator app (available in the Apple or Google Play stores). Scan the QR code displayed on your computer using the app to generate push notifications or time-based one-time passwords (TOTP).
- Backup Codes: Generate 10 8-digit backup codes and save securely for account recovery.
- Turn on 2-step verification: Click “Turn on 2-step verification” at the top of the screen before exiting the 2-step verification page.
Note: 3rd-party email services such as Apple Mail, Thunderbird, Outlook, Yahoo, etc., do not allow Google MFA account management. You will need to sign in using the Gmail app or use a computer browser at oswego.edu/mail for managing your 2-step verification options.
Note: Passkeys are currently unavailable. The security key option is available but not managed by SUNY Oswego. Please contact CTS if you are having trouble setting up your MFA methods.
*Note: Enrolling only on a smartphone or tablet may create a feedback loop for password or MFA verification. We recommend adding at least one phone number instead if you do not have a computer.
Microsoft MFA Enrollment
Recommended Setup: the Microsoft Authenticator app (push notifications or verification codes) with backup phone number(s).
How to enroll on a computer with a smartphone:
- Initiate MFA Setup: Navigate to the Account Tools page on a browser and select Change your other MFA options. Log in using your SUNY Oswego credentials. You'll be prompted with "More information is required." Click "Next."
-
Choose your methods: You will be prompted to set up the Microsoft Authenticator app on your mobile device. Alternatively, you may select “I want to set up a different method” to choose other methods.
-
Microsoft Authenticator App*: push notifications or time-based one-time password (TOTP) in the app.
-
Download and Install: Get the Microsoft Authenticator app (available in the Apple or Google Play stores).
-
Connect Account: If prompted in the app, allow notifications and do not sign in. Click to “Skip” sign in when prompted. Tap "+" in the upper right, and select "Work or school account," then "Scan a QR code" from your computer screen.
-
If you cannot scan the QR code, choose the “Can’t scan image?” option on the enrollment screen to manually add the account. On the app, select “Scan a QR Code”, then “Enter Code Manually”.
-
Test and Confirm: Approve the push notification on your phone or enter the 6-digit code from the app to complete setup.
-
Phone Number(s): Add phone number(s) for call or text options.
-
Browser Authentication: Although Google and Microsoft do not currently have a browser extension, you may find one available for Chrome, Firefox, or Edge to work on your computer.
- Add Additional Verification (Recommended): Set up a backup phone number for SMS codes/call or a different authenticator, such as a browser extension authenticator, for recovery.
- Select your Default Method: Once you have more than one verification method, you may select which method you would like offered first upon signing in to SUNY Oswego services.
*Note: Enrolling only on a smartphone or tablet may create a feedback loop for password or MFA verification. We recommend adding at least one phone number instead if you do not have a computer.
Common Questions
What are the preferred options for MFA?
We recommend setting up at least two options that are not both tied to your smartphone. The Microsoft Authenticator app offers excellent security and ease of use. As a backup, consider using your phone number(s).
I get an error saying, “My sign-in settings don’t meet my organization’s 2-Step Verification policy”. What do I do?
2-step verification will need to be turned on for email and other LakerApps services within a month of signing in for the first time. Trying to sign in after one month without 2-step verification turned on will produce this error message.
If you are using an email service other than the Gmail app on a mobile device and cannot use oswego.edu/mail on a computer to sign in, you will need to download and use the Gmail app to complete the MFA process. Follow the instructions for turning on 2-step verification for Android or iPhone & iPad. Contact CTS if you are still having trouble signing in.
Can I access my Google account from a computer lab or a common area computer on campus?
Yes, you can sign into Google Chrome, Gmail and other LakerApps services from shared computers on campus, but they will require entering your MFA credentials. The computers are reset at regular intervals and will not remember your previous login.
What should I use for MFA while traveling?
While traveling, we recommend using the Microsoft Authenticator app. It's the most reliable and secure option, especially when you may not have access to your regular phone number or stable cell service for text messages or calls. The app can generate verification codes even without an internet connection, making it ideal for travel. It is best to download and set up the app before you travel.
I live in an area with a poor cellular signal. What can I do?
The Microsoft Authenticator app does not require an internet or cellular connection to generate codes, making it ideal. You can also set your home phone number as an alternative for calls.
Why am I unable to add my phone number?
- Phone number may already be in use with another Google account. If you have other Google accounts, check if the number is already registered for 2-step verification on one of them. If so, you might need to use a different number for the new account, or consider using alternative verification methods like Google Prompts, an Authenticator app or backup codes.
- Virtual or VoIP Numbers: To prevent spam, Google's system may flag virtual phone numbers or those from certain free text apps. This is because these numbers can be less secure. Use a phone number from a reputable carrier for 2-step verification.
- "Something Went Wrong. Try Again" Error: This is a generic message that may relate to issues with the phone number or temporary system glitches. Solution:
- Wait and retry: Sometimes, it's a temporary issue. Wait a few hours or even a day and try again.
- Try a different browser or device: Clear your browser's cache and cookies, or try adding the number from a different browser or device.
- Check internet connection: Ensure you have a stable internet connection.
Not receiving verification codes (SMS/Voice Call)?
- Verify your phone plan and signal: Make sure you have a good mobile network connection. There might be temporary network issues with your mobile carrier’s network. Moving to a different location may improve delivery.
- Blocked/Spam Numbers: Verify the numbers sending the verification codes are not being blocked or treated as spam.
- Restart your phone: This refreshes the connection to your provider's cellular network.
- Use Backup Methods: Select “Sign in Another Way” or “Try Another Way” to display all of your MFA options at sign-in.
What if I set up MFA on my authenticator app and lose access or cannot receive the codes?
- Use Backup Methods: You may use the prompt to “Sign in Another Way” or “Try Another Way” to view all of your MFA options. Make sure you have set up alternative MFA methods, such as your office phone or tablet/computer.
- Authenticator App Sign-in Issue: If you sign into authenticator apps with the SUNY Oswego email, remove the authenticator app, or get a new phone, the authentication link is no longer usable. If you have no other way of authenticating, you can contact CTS for assistance.
What if my MFA device is stolen/lost?
- Sign out of the lost or stolen device: (Google and Microsoft)
- Review Recent Sign-in Activity and connected apps/sessions: (Google and Microsoft).
- Use Backup Methods: You may use the prompt to “Sign in Another Way” or “Try Another Way” to view all of your MFA options. Make sure you have set up alternative MFA methods, such as your office phone or tablet/computer.
What if I get a new MFA device (phone/phone number, tablet, or computer)?
- Add New Method: Use trusted devices to sign into your accounts and add the new MFA method for Google and Microsoft.
- Sign out of the devices you no longer use: (Google and Microsoft)
If you only have one method set up for MFA and cannot access it, please contact the CTS Help Desk for assistance.
What if I left my phone at home for the day?
If you left your phone at home and have other sign-in methods set up, please select the 'I want to use a different method”, “Sign in Another Way”, or “Try Another Way” options to view other ways to sign in.
If you only have one method set up for MFA and cannot access it, please contact the CTS Help Desk for assistance.
I have already set up MFA, but I need to change my verification options. How do I do that?
For Google, navigate to Account Tools page on a browser and select Change your Google MFA options. Alternatively, on your Gmail app, navigate to your profile icon, then Security and select 2-Step Verification.
For other services using Microsoft login, navigate to Account Tools page on a browser and select Change your other MFA options.
Available To
Employees and students
Cost
Depending on your method of configuration, some cell phone texting/calling costs may apply.