Protecting your GCU account Multi-Factor Authentication (MFA) provides an extra layer of security for your GCU account.
Your password is the first factor used to verify your identity. MFA adds a second factor. This helps protect your personal information, University data, and online services even if your password is compromised. Setting up MFA is required to access GCU services securely and helps protect both your account and the wider University community from unauthorised access.
MFA transition: September to November Glasgow Caledonian University is currently moving from GCU MFA to Microsoft MFA. During the transition period during Trimester A, some services will continue to use GCU MFA while others will use Microsoft MFA. To ensure uninterrupted access to all University systems, you'll need to register for both MFA services. The good news is that you can use the Microsoft Authenticator app for both.
What do I need to do?
New students
arrow_forward
New students will need to sign up for both methods of authentication.
Once you have set this up, you will then be able to access all GCU IT systems and services securely.
We recommend using Microsoft Authenticator for both GCU MFA and Microsoft MFA.
Returning students
arrow_forward
Returning students should only need to sign up for Microsoft MFA as you would have previously signed up for GCU MFA.
However, not all students set up MFA in their registration. If you are one of those, please follow the instructions below.
We recommend using Microsoft Authenticator for both GCU MFA and Microsoft MFA.
Staff
arrow_forward
Staff should only need to sign up for Microsoft MFA as you would have signed up for GCU MFA already. Please follow the instructions below on your laptop and have your mobile phone to hand. Some of the screens you see may differ slightly from the instructions, particularly if you have used the Microsoft Authenticator app before. However, this should not prevent you from completing the process.
We recommend using Microsoft Authenticator.
To help you get started, please watch this brief
video guide and then follow the instructions on your laptop. You'll need to have your mobile phone to hand, as you will need to download the Microsoft Authenticator app as part of the process.
Multi-Factor Authentication FAQs
What is Multi-Factor Authentication?
arrow_forward
MFA is an approach to online security that requires you to provide more than one form of verification detail to access an account, log in or complete a transaction online.
MFA adds an extra layer of security by requiring two or more verification methods: something you know (password), something you have (phone/app), or something you are (biometrics). It protects your account and according to Microsoft, it can block over 99.9% of phishing attacks.
Why are we moving to Microsoft MFA?
arrow_forward
It improves security, aligns with Microsoft standards, provides a unified login experience, reduces reliance on third-party identity tools and provides better value for GCU.
Is MFA registration and use mandatory?
arrow_forward
Yes. You must register at least one Microsoft multi factor authentication option to securely access GCU systems. This will also be required for you to perform self-service password resets.
Will I be prompted for MFA every time I log in?
arrow_forward
Not always. There are a number of factors considered before issuing a prompt to MFA. These include device, location, and risk level. For example, if you're working on campus, with GCU-managed equipment, you'll not generally be asked to MFA.
Accessing web applications from outside the University on non-University equipment will likely require regular sign-in and MFA.
What if I lose my smartphone?
arrow_forward
Contact IT support immediately. The IT Helpdesk will verify your identity and can help reset your registered MFA factors.
What happens if I get a new smartphone?
arrow_forward
Add your new device in advance via My Security Info, before removing your old device. If you no longer have access to your old device - contact the IT Helpdesk who will verify your identity and can help to reset your registered MFA factors.
What if I don’t have a smartphone?
arrow_forward
You can use other options such as PassKeys (hardware USB devices such as YubiKeys, etc). You can also use other standard time-based one-time (OATH TOTP) generation apps.
These can be configured via:- Add sign-in method -> Authenticator App -> I want to use a different authenticator app. Then scanning the QR code if applicable or entering the key displayed on the TOTP generation app. Please follow the specific guidance supplied by the apps developers.
Examples available for non-smartphones include:
authenticator.cc https://authenticator.cc is a free browser extension compatible with Chrome, Edge and Firefox that can be used as a verification method for Multi-Factor Authentication for services that require it.
Open source KeePassXC https://keepassxc.org Available for Windows, MacOS and Linux
Please note that these applications are provided by third parties, not supported by the IT Helpdesk and are subject to change. Also, be aware that compatibility within the Microsoft Entra environment may be withdrawn at any time.
Why can't I use text messages (SMS)?
arrow_forward
Text messages (SMS) are now seen as a legacy authentication method which is much less secure than other options and more vulnerable to phishing attacks. Microsoft is removing its SMS service, so it's not an option GCU can use going forward.
If you have previously added phone/SMS as an authentication option within Entra, we strongly recommend you download, install and register Microsoft Authenticator, then remove the legacy phone/SMS option from your account. Phone/SMS will stop functioning in the near future and will be automatically removed.
What if I get an MFA prompt/challenge I didn’t request?
arrow_forward
Reject it, change your password, and report it to the IT Helpdesk immediately.
What MFA methods can I use?
arrow_forward
The Microsoft Authenticator app is the recommended authentication method and is fully supported by the IT Helpdesk.
Other methods are available (such as third-party authenticators like Google Authenticator or passkeys (for example, YubiKey ). Microsoft Authenticator is recommended as it is secure, convenient to use, the app is available on most smartphones and can work even if you don't have a phone signal.