Microsoft has been gradually enforcing Multi-Factor Authentication (MFA) across the Microsoft 365 cloud environment worldwide since 15 October 2024. NWU user IDs (@nwu.ac.za, @mynwu.ac.za, and @mysis-nwu.ac.za) will be required to do multi-factor authentication. This initiative aims to enhance cybersecurity by providing an additional layer of protection for Microsoft 365 accounts, helping safeguard users and organizational data against unauthorized access and cyber threats.
This change is part of the Secure Future Initiative, which aims to strengthen security and prevent data breaches.
MFA is a security method commonly required among cloud service providers and requires users to provide two or more pieces of evidence to verify your NWU MS 365 account. It adds an extra layer of protection to the standard username and password authentication.
Currently the NWU user community only use a password to authenticate to access the MS 365 environment and it leaves an insecure vector for attack. If the password is weak or has been exposed elsewhere, an attacker could be using it to gain access. When you require a second form of authentication, security is increased because this additional factor isn't something that's easy for an attacker to obtain or duplicate.