Table of Contents
Introduction
This article is for anyone using SMS or a hardware token as an MFA method and what options are available with the retirement for SMS for MFA by Microsoft.
What is Time-Based One-Time Password (TOTP)?
- TOTP is a multi-factor method which generates a short 6-digit code locally on your device. Both SMS and Hardware tokens use TOTP but deliver the code either via text message or special device. With TOTP your mobile/device will generate the code for you.
- The code is generated by an app on your phone and changes every 30 seconds
- The app does not need internet or mobile signal to generate codes — it works offline at all times.
Microsoft's SMS retirement for MFA
Microsoft are retiring SMS and promoting passkeys as an alternative. Please see the Microsoft SMS retirement information linked here for further information.
TOTP is a good alternative for SMS users as it behaves in the same way except offline.
Passkeys provide enhanced protection from phishing. If you would like to set one up please see the Microsoft Passkey setup instructions linked here for further information.
How Does it Differ from SMS or Hardware Tokens?
TOTP is basically the same as using the SMS method except the code is not sent by a text message but is generated offline on your device. Hardware tokens also generate the same style of one time code but with TOTP you don't need to carry an additional device which can be lost or stolen or the battery can go flat. Getting replacements for hardware tokens takes time.
I Have an Old Phone — Can I Still Use This?
Yes, as TOTP apps can support very old phone versions. See below for recommendations.
- For Android phones the following TOTP apps support older phones;
- FreeOTP Authenticator - requires Android 6.0 (Marshmallow) or higher (Opensource project)
- Aegis Authenticator - requires Android 6.0 (Marshmallow) or higher (Opensource project)
- For Apple phones and tablet the following TOTP apps support older devices;
- FreeOTP Authenticator - Requires iOS 11 or later
- OTP Auth - Requires iOS 12 or later
There are many TOTP apps available so it's up to you which one you choose. The guide below is using FreeOTP Authenticator.
TOTP Setup Instructions for MFA
Go to www.deakin.edu.au/mfasetup and login
Add a TOTP device for MFA...
Step 1 - Click Add sign-in method
Step 2 - Click the Microsoft Authenticator option
Step 3 - Click on the link "Set up a different authentication app"
Step 4 - Click "Next"
Step 5 - Open the TOTP app on your device and scan the QR code. Click "Next" after this is done.
Note: if you cannot scan the QR code you can click "Can't scan the QR code?" and this will give you the secret values you can copy and paste into some of the mobile apps.
Open the app FreeOTP App
Select the QR code Option and scan the code when presented using Setup Instructions above.
| Note: You may get a warning that contains "Token is unsafe!". This can be safely ignored. Microsoft will be improving the TOTP standards soon |
Once added it will give you a rotating code.
Step 6 - Enter the code from your TOTP mobile app.
Step 7 - You should receive the success message