Skip to content Skip to main navigation Report an accessibility issue
Information Security

MFA + Strong Passwords: Your Best Defense Against Account Attacks


Service navigation


Multi-factor authentication (MFA) adds an extra layer of protection to your accounts by requiring more than just a password to sign in. Even if a password is stolen through phishing, malware, or a data breach, MFA can still prevent an attacker from accessing your account. This additional safeguard is especially important because passwords can be guessed, reused, or exposed. MFA makes it much harder for someone else to log in as you.

For students, faculty, and staff, enabling MFA is one of the simplest and most effective steps you can take to protect University and personal information. To further protect your accounts once MFA is in place, only approve sign-in requests you expect, deny any unexpected prompts, and report suspicious activity right away. A strong password, paired with MFA, greatly reduces the risk of unauthorized access.

A hand holding a cell phone with text, "Is that you?, a green checkmark, and and X. The second phone screen shows the Duo logo.