MFA is the single biggest thing you can do to keep attackers out of your Microsoft 365 account. Here’s how to check what’s registered on yours, remove old devices, and add a modern passkey.
Prerequisites
- A Microsoft 365 work or school account (this is different from a personal Microsoft account)
- Your current phone or laptop with the Microsoft Authenticator app installed (if you already have MFA set up) OR your admin’s help to re-register
- About 10 minutes
Why this matters
Password-only accounts are stolen at scale — usually via phishing or credential-stuffing attacks. Multi-factor authentication (MFA) means an attacker needs your password AND a second factor (a code, a phone prompt, or increasingly a passkey) to sign in. Microsoft’s own data says MFA blocks over 99% of automated attacks on Microsoft 365 accounts.
In 2026 the next step is passkeys — a phishing-resistant replacement for the six-digit code that lives in your phone’s secure enclave. Both are worth having, and IT Live turns both on as standard across the Microsoft 365 tenants we manage.
Step 1 — Open your security info page
Sign in at mysignins.microsoft.com/security-info.
You’ll see a list of all the sign-in methods currently registered on your account: your phone number, the Microsoft Authenticator app, any hardware security keys, and any passkeys.
Step 2 — Remove old devices you no longer have
Look through the list. Anything ending in “iPhone” or “Android” that’s your old phone? Remove it. Any phone numbers you no longer use? Remove them. Any authenticator app installations you don’t recognise? Definitely remove them.
Click the Delete button next to each old entry. If it asks you to confirm, do.
Step 3 — Add a passkey (recommended for 2026)
Click + Add sign-in method → Passkey in Microsoft Authenticator (or Passkey for Windows Hello / Passkey for iCloud Keychain if you prefer).
Follow the prompts on your phone or device. The passkey is stored in your device’s secure enclave — nothing typed, nothing copied, nothing to phish.
Step 4 — Set your default sign-in method
Back at the security info page, look for “Default sign-in method”. Set this to the most convenient method you’ll actually use. For most people that’s Microsoft Authenticator — notification or Passkey. Avoid SMS as a default — it’s the weakest MFA method and can be intercepted.
Step 5 — Test it
Open a private browser window and sign in fresh. Make sure your chosen default method works. Nothing worse than losing access at the worst possible moment.
Common mistakes to avoid
These are the four IT Live sees most often on Microsoft 365 accounts across New Zealand.
- Only having one MFA method registered. If your phone drowns in a pool, you need a second way in. Register at least two — passkey + authenticator app is a good combo.
- Using SMS as your only method. SMS can be intercepted via SIM-swap attacks. Move away from it if you can.
- Sharing MFA codes with anyone who asks. Even IT. A legitimate IT person will never ask you to read out an MFA code.
- Approving push notifications you didn’t trigger. If a push appears when you’re not signing in, it means someone else is. Deny and change your password immediately.
What if I’ve lost my phone?
If your only MFA method is on a lost phone, contact your IT admin (or IT Live if we look after your tenant). We can reset your MFA methods on your behalf — normally within 15 minutes during business hours.
Related quick wins
- Set up Self Password Reset Programme (SPRP) — so you can reset your password without a helpdesk ticket
- Set up Windows Hello facial recognition — a hardware passkey for signing into your laptop
MFA is one of the 27 SMB1001 Gold controls, and it is one of the first things IT Live checks in a security review. If your whole team hasn’t done this, that’s a control failing. See what SMB1001 Gold is or take the free 2-minute readiness check.