Multi-Factor Authentication Guide

Even the strongest password can be stolen through phishing or malware. Multi-Factor Authentication (MFA) adds a critical second layer of defense. It requires something you know (your password) and something you have (your phone or a security key) to log in. 

MFA is especially important at Clark College for keeping your school email, classwork, and personal info safe. It’s quick to set up, easy to use, and one of the best ways to stop hackers in their tracks since if a hacker steals your password, they still cannot access your account without the second factor.  

 

Choosing an MFA Method 

Clark College supports the following MFA methods: 

If you aren't sure where to start, we recommend the Okta Verify app, as it is free, reliable, and user-friendly. When you sign in with your username and password, Okta Verify, like Google Authenticator, prompts you to confirm your identity by either sending a push notification to your phone or allowing you to enter a code generated by the app. 

If you do not have a phone or have accessibility challenges, YubiKeys are available as an alternative. However, this option is not recommended for most users due to other considerations, such as cost. Please contact the Tech Hub to discuss your options. 

 

Setting Up MFA 

Okta Verify or Google Authenticator for Clark College 

    1. Download the Okta Verify or Google Authenticator app onto your primary mobile device.

    2. On a computer, open a web browser and navigate to https://clark.okta.com.

      Note: If a Windows Security prompt appears saying "Sign in to access this site," click “Cancel” to proceed.

    3. Enter your Clark College credentials and click “Sign In”.

    4. If this is your first time setting up MFA for your Clark College account, skip to step 7.

    5. If you are adding an additional MFA factor, verify your account with one of the listed security methods.

    6. Click the down arrow next to your name in the top-right corner of the site.

    7. From the dropdown menu, select “Settings”.

    8. Under “Security Methods”, locate the MFA method you chose in the previous section and click “Set Up”.

    9. If prompted, re-enter your password.

    10. For Okta Verify, scan the QR code displayed on your browser using your primary mobile device, then skip the remaining steps below.

    11. For Google Authenticator click “Set up” near the bottom of the dialog box.

    12. Scan the QR code displayed on your browser using your primary mobile device, then click “Next”.

    13. Open your authenticator app on your mobile device and view the generated code.

    14. Enter the generated code into the dialog box and click “Verify”.

Alternatively, you can follow one of these video walkthroughs, though the screens shown may differ from yours: 

If you run into any issues or want to set up a different MFA method, reach out to the Tech Hub, and they can make sure Okta is configured correctly. 

 

Okta Verify or Google Authenticator for CtcLink 

To set up Okta Verify or Google Authenticator for your ctcLink account, which we highly recommend, follow the steps above for your Clark College account. However, instead of navigating to clark.okta.com, go to ctclink.okta.com

Please note that ctcLink also allows verification via SMS. Although this option is convenient, it is not recommended. Using Okta Verify, Google Authenticator, or a security key is a much stronger method of verification and is less susceptible to attacks. 

Additionally, here are some helpful resources from ctcLink on setting up Okta: 

 

MFA FAQs 

Is MFA really necessary for all my accounts? 

Prioritize accounts that hold sensitive data or serve as gateways to others: email, banking, cloud storage, etc. Email is especially critical since if compromised, attackers can reset passwords for all your other accounts. Start with these high-value targets, then expand to other accounts as you become comfortable. 

Won't MFA slow me down every time I log in?

A little bit, but authenticator apps generate codes instantly, and hardware keys can be as simple as tapping a button. The few extra seconds are worth the protection against unauthorized access. 

What happens if I lose my phone or can't access my authenticator app? 

If you lose access to your MFA device, please contact the Tech Hub. They can assist you in verifying your identity and resetting your MFA settings. Once verified, you will be able to set up a new device and regain access to your account. 

Do authenticator apps use phone data? 

Okta Verify, Microsoft Authenticator, and Google Authenticator are free to download. While receiving push notifications may consume data depending on your mobile plan, connecting to student Wi-Fi while on campus can avoid this. However, authenticator apps can also work offline; they generate codes locally on your device without needing an internet connection. Just ensure your device's time is synchronized correctly. 

Do authenticator apps allow me to be tracked? 

No, trusted authenticator apps only generate authentication codes. They do not collect or share your personal data. Installing an authenticator app also does not give Bark College access to any personal information on your phone, since it works independently of your photos, contacts, other apps, and personal information. 

Is SMS/text message MFA secure enough? 

Although not allowed for Clark College accounts, SMS MFA is better than nothing, but it's not the most secure option. Attackers can use SIM-swapping attacks to intercept text messages. For higher-security accounts use an authenticator app (like Okta Verify, Microsoft Authenticator, Google Authenticator) or a hardware security key (YubiKey 5 or equivalent). Reserve SMS for lower-risk accounts where no other option exists. 

Can hackers still bypass MFA? 

While no system is 100% foolproof, MFA blocks the vast majority of automated attacks and credential theft. Advanced attacks exist but are rare. Using phishing-resistant methods like hardware keys or push-notification MFA further reduces this risk. 

 

Contact Us 

General Inquiries: For non-urgent questions, email infosec@clark.edu

Report an Incident: To report an information security incident, please visit the Report an Incident page

 

Additional Resources

Report an Incident

Free InfoSec Resources

Changing Your Password

Secure Passwords Guide

Email Safety Guide

Phone, Zoom & Teams Safety Guide

Internet Safety Guide

Physical Threats Safety Guide