What is Microsoft 365 Multi-Factor Authentication (MFA or 2FA)?
Multi-factor authentication (MFA) is a process by which, during a service session initiation (VPN, Microsoft 365, Teams, etc.), additional identification is requested by the user. For example, you can enter a code into your phone or approve it in a mobile app. To require a second form of authentication, security increases, because this additional factor is not easy to obtain or duplicate for an attacker.
For multi-factor authentication (MFA), we opted for a configuration with a double factor authentication (2FA).
What is necessary for its operation?
To use multifactor authentication, it is necessary:
- Enable multifactor authentication.
- Configure the authentication methods to allow second validation on your other device.
- A mobile device will perform this validation.
- RECOMMENDED OPTION: The recommended option for your convenience is installing the Microsoft Authenticator app on your mobile. Furthermore, it is recommended to use the alternate method of the telephone call.
How to enable Multi-factor authentication?
The double factor authentication is activated by fault for various colectivos, between which the ALUMNOS colectivo is displayed.
You can check if it is activated on the intranet, (depending on the colectivo you have, if you encounter other Herramientas or apartado Services, in the block of "Office 365" on your intranet.
Only in the case you have not been activated, you must activate it.
It will be necessary to activate multifactor authentication on your intranet:
How to configure Multi-Factor authentication?
The first thing we need to configure is the authentication options available to us to allow second validation. To do this, please access the following links https://www.upv.es/id/373 and follow the following steps:
Introducing our new user: usuario@upv.edu.es
- We will see a window, which will redirect us to the new intranet to identify us.
- We log in on the intranet with our credencials
- We can select that you maintain the initial session.
- Click on "Siguiente" (next):
At this point, configure the options for validation. Of the available session initiation methods, the most recommended option is to use notifications in the mobile application , to make it more convenient and one of the most secure. This option requires installing an app on our new mobile phone, available for iOS and Android in the App Store and Google Play respectively: https://www.microsoft.com/es-es/security/mobile-authenticator-app
Please ensure that we have installed the authentic Microsoft application, there are applications with the same number and icons. The most secure format to download the authentic application is accessed via previous https://www.microsoft.com/es-es/security/mobile-authenticator-app , and scan the QR code that appears, where we will access the authentic application directly.
- Please note, if we have decided on the previously recommended option, select "mobile application" and "Receive notifications for verification", we must install the Microsoft Authenticator application on the mobile, if it is not installed.
https://www.microsoft.com/es-es/security/mobile-authenticator-app - Once you have installed the application, you can continue, press the configure button, to access the mobile and launch the Microsoft Authenticator app, configure the cue to receive notifications.
- To configure, in the previous step, we will send a QR code, necessary to scan in a later step from the Microsoft Authenticator mobile application.
- When you install the application on your mobile (if you don't have it installed), you must configure it again.
We can use the QR code scan of the device owner, and in this case, we can switch directly to point 11, without the need to carry out the steps from point 10. Only the cue will be configured directly.
If we do not use the QR code scan of the device owner, we must follow the following steps:- Open the app:
- Press the menu “Agregar cuenta” (add acount)
- We choose "Cuenta profesional o educativa". (professional or educational):
- Select the option to scan a QR code and insert the camera onto the screen.
- Open the app:
- If everything is working correctly, the cue will be registered on the new mobile app, we will request approval via a notification on the screen if you want to initiate the session.
- Once you have added the cue to the Microsoft Authenticator app, you can continue with the team to add alternate validation in case you lose access to the mobile app.
NOTA
At any time, you can access the configuration, add other validation alternatives or modify the current configuration, access via https://www.upv.es/id/373
How to initiate a session with one of the available services (teams, o365...) with double factor?
Once you have activated multifactor authentication on the intranet and carried out the configuration steps, every session you initiate activates the mechanism to request the double factor, there is a notification in the Microsoft Authenticator app or a telephone call . To use the key only you must hold the key and press "#"
On some mobile devices, if in the configuration of the Microsoft Authenticator application, the application blocker (digital or pin) is configured, you may receive a notification of an error denying access. In this case, we must deactivate the application blocker.
- Access the configuration of the Microsoft Authenticator application
- Disable the application block and we will turn it on.
Example of accessing the Office 365 web page
This example is a valid series for access to O365, such as any of its applications, such as Teams, OneDrive, etc.
- Enter into o365.upv.es
- We identiy ourselves with our UPV credentials.
- We will see a message like this:
- In this case, the preferred option is the one from the Microsoft Authenticator app, but if you do not have it available at the moment, you can change it to another method that you have configured when you press it into the screen.
- Please note that the option (recommended) to "approve a request in the Microsoft Authenticator application" means that, on the mobile, we receive a notification that must be approved.
- If there is no pulse at the moment, you can access notifications and download the notification to be approved.
Example of VPN connection
Screen captures for connection to VPN are available on Windows 10.
How to configure VPN following the VPN guide in Windows 10/11
- We introduce the upvnet credentials ( usuario@upvnet.upv.es in the case of the UPVNET dominion or usuario@alumno.upv.es in the case of the ALUMNO dominion)
- Once you enter the credentials, indicate "comprobation of the initial information", it will be pending to approve the request on the mobile device.
- On your mobile, if you install the Microsoft Authenticator app, you will receive a notification that must be approved.
- Si no pulsamos en el momento, podemos acceder a 'notificaciones' y desplegar la notificación para aprobarla.
- If there is no pulse at the moment, you can access 'notifications' and download the notification to be confirmed.
What if we changed or lost our device on which we configured the Microsoft Authenticator app?
In this case, we must deactivate this device beforehand to avoid it being used by other people.
To do this, start your session using an alternative method (to validate with your mobile life in case of change and if the key is available) and go to the MFA configuration page ( https://www.upv.es/id/373 ) to remove the device from the list.
If you cannot initiate a session, we do not have another alternative method, as you can use your mobile or telephone, we can contact the CAU ( https://cau.upv.es) to request that our configuration be restored.
Every mobile device with the Microsoft Authenticator installed will appear on the previously cited page, which in reality will redirect it to the following web page:
https://mysignins.microsoft.com/security-info
In this case, the user has configured mobile phones, so if one of them is lost, you can use the other device to authenticate with Microsoft services.
Sin embargo, en la parte de base, wemos very móviles registrados dos los siguientes de modelo de móvil: M2101K6G, 23053RN02Y y SM-J415FN.
You have decided that the user has installed and configured the Microsoft Authenticator app on your mobile at the moment, but some of them have been physically destroyed, or the factory values have been restored, or there is nothing in it.
Sería conveniente pulsar sobre el enlace "Eliminar" para anular el móvil que ya ne utilizando.
If we do not know what to do, we will deactivate the mobile model identifier (on the mobile phones that we are using), so we only have activated the mobile phones that we have available and for so many, the rest of the identifiers can be eliminated as devices Validated authentication.
In the case of Android 13, for example, we can see the mobile model that we have:
Settings:
Select to adjust the option named: "about the phone"
Elegimos "Detailed and specific information"
Y accedemos a la información del modelo.
I don't receive the verification call (2FA)
The numbers used by Microsoft for verification llamadas may be misconceived or have a normal format. If you have initiated a session with a service that has configured step-by-step verification (2FA), a call of this type may be part of the authentication process. If you have any questions regarding the legitimacy of the complaint, we will not respond or ask you to initiate a session on the service. If the claimant has received your request coincident with the new request for access, you can confirm that this is part of the verification process.
If you do not receive the message to complete the verification process, review the list of blocked numbers on your mobile phone .
In some cases, the number used by Microsoft to carry out the authentication call has been blocked beforehand by the user, believing that it is a spam or fraudulent call, which is why the call is based on the device.
Recommendation: Access the configuration of your phone's calls and dial it if the number you want to carry out verification is found in the list of blocked numbers. If so, eliminate the list and request the verification request.





























