Multi-Factor Authentication (MFA)
Santa Barbara City College uses Multi-Factor Authentication (MFA) for remote access to systems and services.
Starting Monday, October 26th, Santa Barbara City College will require Multi-Factor Authentication (MFA) for all users on all non-SBCC, untrusted networks. If you have already set up your MFA options, your existing authentication methods will continue to work without any changes. If you have not set up your MFA options, please do so before Monday, October 26th, when you will be required to set up MFA before you can access any systems from non-SBCC networks.
MFA Setup Instructions:
Frequently Asked Questions
Multi-Factor Authentication (MFA) adds a second level of security during the login process to help prevent anyone other than you from accessing systems storing sensitive data. This is accomplished using two layers of security to verify your identity when logging into a system:
1. Enter your username (your campus email address) with your password.
2. Use a physical device such as your cell phone, tablet or external email address
to confirm your identity.
The device that is most convenient for this purpose is a cell phone or tablet with the Microsoft Authenticator app installed on it. Alternatively, a text message can be sent with a One-Time Passcode (OTP) for you to type in.
Passwords may be stolen and used without your knowledge. Multi-factor authentication provides an additional layer of security. It prevents unauthorized account access by using your phone or other device to confirm your identity when logging into campus applications and systems.
SBCC has decided to implement MFA in response to multiple recent phishing scams and other vulnerabilities faced by the College and other organizations worldwide. MFA provides much stronger insurance that information is only accessible to the intended people, and that the systems remain highly available. MFA will be used in the future by an increasing number of SBCC services, or by designated users of a given service such as VPN.
Currently, over 300 higher education institutions have implemented the same multi-factor system throughout the nation with SBCC joining the security movement. Microsoft will soon require all users to enable MFA for their accounts. By rolling out MFA, we are pushing our account security to the next level and protecting the data of the College and our students, faculty and staff.
MFA is currently available for all SBCC faculty, staff, and students.
It is highly recommended that ALL faculty, staff, and students enroll in Multi-Factor Authentication. Enrollment in MFA is mandatory for all employees as of August 22, 2023, and will become mandatory for students as of October 26th, 2026.
Currently, all faculty, staff, and students who wish to access our Virtual Desktop Infrastructure (VDI) from off-campus are required to use Multi-Factor Authentication to connect to the service from off-campus. Enrollment in MFA is mandatory for all employees.
Effective October 26th, MFA will be required whenever you log into campus systems and applications from any non-SBCC, untrusted network, which includes most off-campus connections:
- Home Wi-Fi
- Public Wi-Fi
- Mobile hotspots
-
“SBCC-Guest” Wi-Fi network
"Campus systems" includes Gmail, Google Drive, Canvas, Virtual Desktop Infrastructure (VDI), and any other online SBCC resource that requires an SBCC account login.
What will not require MFA?
- On-Campus Networks: Accessing campus systems via SBCC computers or a personal device logged into the "SBCC" or "eduroam" Wi-Fi networks at Cliff campus, Wake Center, Schott Center, Cosmetology, and the Early Learning Center.
-
High School Networks: The networks of local high schools participating in the dual-enrollment program will be trusted, allowing access to campus systems without additional MFA prompts.
After entering your usual password information, you can authenticate your login through one of these options:
- Text message: Receive a code via text (SMS) message on your phone
- Mobile App: Enter a passcode from the Microsoft Authenticator mobile app on your phone or tablet
MFA Setup Instructions:
Although the Microsoft Authenticator app is the most convenient multi-factor option, you are not required to install it on your device.
Microsoft Authenticator is a very small application, taking up little room on your phone, and it is meant for individual consumer use. It is free, and its use does not result in any charges if you use the passcode options from the app itself.
Microsoft Authenticator can also be installed on a tablet if you do not have a phone.
You can also use a hardware token such as a Yubikey. The Yubikey is a small token that can fit on your keychain. You can plug the Yubikey into your computer or mobile device and press a button, and the YubiKey sends a unique code that can use to confirm your identity. Students can purchase a Yubikey from https://www.yubico.com.
We recommend that you use the Microsoft Authenticator mobile app as your MFA method, especially if you are in an area with no internet connectivity or cellular service. You do not need an internet connection or a cellular signal to generate passcodes in Microsoft Authenticator. Microsoft Authenticator can also be installed on a tablet if you do not have a phone.
You can also use a hardware token such as a Yubikey. The Yubikey is a small token that can fit on your keychain. You can plug the Yubikey into your computer or mobile device and press a button, and the YubiKey sends a unique code that can use to confirm your identity. Students can purchase a Yubikey from https://www.yubico.com.
Please contact the IT Support Desk for assistance.