StarID Password and Multi-Factor Authentication (MFA) Requirements

Overview

Minnesota State is implementing updates to StarID password requirements and future changes to Multi-Factor Authentication (MFA) methods. These changes are intended to improve account security while reducing the need for routine password changes. Existing passwords will remain valid, and no immediate action is required unless you are changing your password or updating your authentication methods.


StarID Password Requirements

Current Password Changes

Beginning on or shortly after September 15, 2026, Minnesota State will implement updated StarID password requirements. Existing StarID passwords will continue to work and users will not be required to change their passwords immediately. Users will encounter the new requirements only when changing or resetting their password.

New Password Requirements

When changing or resetting a StarID password, the password must:

  • Be at least 15 characters long
  • Contain characters from at least three of the following four categories:
    • Uppercase letters (A-Z)
    • Lowercase letters (a-z)
    • Numbers (0-9)
    • Special characters (!, @, #, $, etc.)
  • Not contain your StarID username
  • Not match a previously used password

Password Examples

Example Meets Requirements

GreenTreesGrow2026!

Yes

MyDogRunsFast#98

Yes

password123

Too short and lacks complexity

xx1234xxJohn89!

Contains StarID and/or Name


Services Affected by StarID Password Changes

The updated password requirements apply to services that use your StarID credentials, including:

  • Microsoft 365 (Outlook, Teams, OneDrive, Word, Excel, PowerPoint, CoPilot, SharePoint)
  • D2L Brightspace
  • eServices
  • Workday
  • Zoom
  • TeamDynamix (TDX)
  • Other Minnesota State services that use StarID authentication

Accounts Not Affected

The following account types are not impacted by these password requirement changes:

  • Local (non-StarID) Active Directory accounts
  • Local application accounts
  • Shared mailboxes
  • Service accounts
  • Database accounts
  • Network equipment accounts
  • Third-party systems not integrated with StarID authentication

Frequently Asked Questions

Do I need to change my password right away?

No. Existing StarID passwords remain valid. Users will only encounter the new requirements when they voluntarily change their password or perform a password reset.

Will there be any outages when the new password requirements take effect?

No outages or service interruptions are expected as a result of this change.

Will I still be required to change my password every 180 days?

Initially, your account may still show an expiration date after updating your password. During the transition period, Minnesota State plans to remove routine password expiration requirements for compliant StarID accounts.

What happens if Help Desk staff reset my password?

Passwords reset through Help Desk or account recovery processes will be configured to meet the new minimum password requirements.


Multi-Factor Authentication (MFA) Changes

Important Changes Coming February 1, 2027

Microsoft is retiring SMS text message and voice call authentication methods for Microsoft organizational accounts effective February 1, 2027. Users currently relying on text messages or phone calls for MFA must enroll in an alternative authentication method before that date.

Why is this changing?

Microsoft is retiring these methods to improve account security and encourage the adoption of stronger authentication options such as authenticator apps, passkeys, and security keys.


Supported MFA Methods After February 1, 2027

The following authentication methods will continue to be supported:

Authentication Method Description

Microsoft Authenticator (Recommended)

Approve sign-in requests using number matching

Passkey in Microsoft Authenticator

Use PIN, fingerprint, or facial recognition

Physical Security Key (YubiKey, Feitian, etc.)

USB, NFC, or Bluetooth security key

Microsoft Authenticator Verification Code

Six-digit code generated in the app

Other Authenticator App Verification Codes

Google Authenticator, Duo Mobile, and other supported apps

Hardware Token/Fob Verification Codes

Physical device displaying rotating authentication codes


Manage Your Authentication Methods

Users can manage sign-in methods through the Microsoft Security Info portal:

Microsoft Security Info

Using this portal you can:

  • Add authentication methods
  • Remove authentication methods
  • Change your default sign-in method
  • Register a new device
  • Remove old devices

MFA Frequently Asked Questions

Will users be prompted to update their MFA settings?

Yes. Users will begin receiving prompts encouraging them to switch from SMS and voice authentication to supported methods. Users will initially be able to skip these prompts. Beginning January 19, 2027, users will only have three remaining skips before a change becomes mandatory. Starting February 1, 2027, users must complete the change to access Microsoft 365-enabled services.

What happens if I get a new phone?

If possible, configure Microsoft Authenticator on the new phone before erasing or trading in the old device. After confirming the new device works correctly, remove the old device registration from the Security Info page.

What if I lose my phone?

If you have another registered authentication method, use it to sign in and update your security settings. If no other authentication method is available, contact the MSUM IT Help Desk for assistance with an MFA reset.

Should I back up Microsoft Authenticator?

Yes. Microsoft recommends enabling backup and recovery features to simplify account recovery when replacing or restoring a mobile device. Backup procedures differ between Android and Apple devices.

I do not use a smartphone. What are my options?

Users who do not use smart phones may use:

  • Physical security keys
  • Hardware authentication tokens/fobs
  • Compatible passkey-enabled devices

These authentication options do not require a smartphone.

What should I do before traveling?

Minnesota State recommends configuring at least two MFA methods before travel and testing both methods before departure. Users relying on Microsoft Authenticator should consider adding verification codes as a backup method.

If more assistance is needed

Incident Request: If you still need help with something not working as it should or have questions, please contact the IT Help Desk or create a ticket using the "Incident Request" button on this page, or if there isn't one included then you can initiate it from the home page.

Service Request: A formal request from a user for something to be provided, information, advice, a standard change or access to an IT service, navigate to the Service Catalog to find the service you specifically would like to request.