TABLE OF CONTENTS
- What Is a TOTP Code
- Which Authenticator Apps Can You Use?
- Step-by-Step: Setting Up TOTP for Your Microsoft Account
- Frequently Asked Questions
This article will give a comprehensive explanation on setting up MFA (Multi-Factor Authentication) for your Microsoft account.
Click Here for additional documentation on how to login with MFA
Click Here for additional documentation on how to use the Microsoft Authenticator App
To access your email and all your Microsoft Apps that comes with your Western Seminary account you can get there with these URLs:
What Is a TOTP Code
TOTP stands for Time-based One-Time Password. Here’s how it works in plain terms:
When you set up TOTP for an account, a shared secret key is exchanged between Microsoft’s servers and an authenticator app on your phone. This happens once, typically by scanning a QR code.
Both sides independently use that secret — combined with the current time — to calculate a 6-digit numeric code.
The code changes every 30 seconds and is only valid during that brief window. It can never be reused, and it can’t be predicted without the secret key.
When you sign in, you simply open your authenticator app, read the current 6-digit code, and type it in.
Because the secret never leaves your device after the initial setup, and the code rotates constantly, TOTP is far more resistant to interception than an SMS message sent over a telecom network.
Which Authenticator Apps Can You Use?
Any app that supports the TOTP standard (RFC 6238) will work. Here are the most popular and trusted options:
- Microsoft Authenticator
- Google Authenticator
- Bitwarden Authenticator
- Proton Authenticator
- Authy
- 2FAS
- Raivo OTP
- Aegis Authenticator
Recommendation: Microsoft Authenticator offers the smoothest experience for Microsoft accounts and includes push-notification approval alongside TOTP codes. However, I personally recommend Proton Authenticator as there is no login needed and you simply scan the QR code and will generate valid TOTP codes for your account.
Step-by-Step: Setting Up TOTP for Your Microsoft Account
Follow these steps to switch from SMS (If you have this enabled) to TOTP:
Step 1: Install an Authenticator App
- Download your chosen authenticator app from the App Store (iPhone) or Google Play (Android). Create an account or open the app — no sign-up is required for most basic TOTP apps.
Step 2: Go to Your Microsoft Security Settings
- Visit https://aka.ms/mysecurityinfo and sign in.
- Select My Account.
- Select Security info
Step 3: Add Your Authenticator as a Sign-In Method
- On the Security info page, select Add sign-in method (the + icon).
- Choose Microsoft Authenticator from the dropdown and select Add.
- If you’re using Microsoft Authenticator, follow the on-screen prompts. If you’re using a different app, select “Set up a different authenticator app.” a QR code will appear on your screen.
Step 4: Scan the QR Code
- Open your authenticator app on your phone.
- Tap the + (add) icon to add a new account.
- Select Scan a QR code and point your phone’s camera at the QR code on your computer screen.
- If your app doesn’t support scanning, you can manually enter the alphanumeric secret key displayed below the QR code.
Step 5: Verify and Confirm
- Your authenticator app will now display a rotating 6-digit code.
- Enter the current code on the Microsoft security page to confirm the enrollment.
- Once confirmed, your authenticator app is linked to your account.
Step 6: Add a Backup Method
- Even with TOTP set up, it’s wise to configure a backup verification method — such as enrolling a 2nd device, buying a FIDO2 hardware key (Yubikey 5), utilizing password managers that support TOTP codes, or using synced passkeys— in case your phone is lost, stolen, or damaged. You can do this on the same Security info page under Add sign-in method.
Step 7: Remove SMS (Optional but Recommended)
- Once TOTP is working, go back to your sign-in methods and remove the SMS/phone option to eliminate the less secure method from your account entirely.
Frequently Asked Questions
Q: Will I still be able to receive SMS codes after February 1, 2027?
No. Microsoft-provided SMS and voice authentication will stop working entirely on that date.
Q: What happens if I don’t switch before the deadline?
After February 1, 2027, users whose only MFA method is SMS or voice will be prompted to register a new authentication method (such as a passkey) during sign-in. This could cause delays or temporary access disruptions, especially for users signing in from new devices.
Q: Do I need an internet connection to use TOTP codes?
No! Once the shared secret is stored on your device, the authenticator app generates codes entirely offline. This is a major advantage over SMS — you’ll have codes even with no cellular signal.
Q: What if I lose my phone?
This is why backup methods matter. Before removing SMS, set up a secondary authenticator app on a separate device, use a FIDO2 hardware security key (Yubikey 5), or utilize password managers that allow TOTP codes.
Q: Can I use TOTP for a work or school account too?
Yes. Work and school accounts managed through Microsoft Entra ID (formerly Azure AD) support TOTP via the same authenticator apps.
If you did not setup a backup method and you locked yourself out, you will have to contact support@westernseminary.edu from your personal email account or call the main Western Seminary line 503-517-1800 to get in contact with the IT department to reset your MFA.