Overview
Multi-Factor Authentication (MFA) adds an extra layer of security to your My.Westcliff (Okta) account by requiring a second form of verification beyond your password. You may need to update your MFA methods when you get a new phone, change phone numbers, lose your authentication device, or want to add alternative verification methods. This article provides step-by-step instructions for adding, removing, and managing your MFA methods in My.Westcliff.
Instructions
How to Access MFA Settings
	- Sign in to your My.Westcliff account via https://my.westcliff.edu/
- Click on your name in the top-right corner
- Select Settings from the dropdown menu 
- You will see the list of your current MFA methods under Security Methods 
- Note: before making changes to your Security Methods, you will be asked to verify your account by the methods that you have configured.
How to Set Up extra MFA methods
You should have at least one MFA method configured during activating the account. To add another one, follow Step 4 in the How to Set Up Your Student My.Westcliff Account article.
How to Update an Existing Phone Number
	- Navigate to your Security Methods settings
- Remove the old phone number
- Verify your account if needed
- Once you old phone number is removed, click Set up
- Verify your account again (if needed)
- Follow SMS Authentication to complete the rest of the configuration
Notes
	- You should always maintain at least two MFA methods in case your primary device is unavailable
- Okta Verify is the recommended MFA method as it works without cellular service and provides the fastest authentication
- When traveling internationally, SMS authentication may not work reliably - use Okta Verify instead
- Before removing your only MFA method, ensure you have added at least one replacement method
- If you lose access to all your MFA methods, contact the IT Help Desk immediately for account recovery
- If your phone is lost or stolen, remove its MFA methods immediately and set up new ones
- If you receive an unexpected MFA prompt that you didn't initiate, deny it immediately and change your password - this may indicate someone has your password
Reference