Skip to main content
Protect PennKey Banner3

Stronger sign-ins. Better protection for you and Penn.

Your PennKey provides access to many of the systems, services, and information you use at Penn. And as cyberattacks and attempts to compromise user accounts become more sophisticated, protecting that access is increasingly important.

Penn is strengthening authentication and access controls across the University to help keep your account – and Penn’s data and systems – more secure. 

Here’s what’s changing—and what you need to know.

PennKey Security Improvements

Image
Text/SMS & Phone

Text/SMS & Phone Call for Two-Step Ending

Moving to stronger ways to verify it's really you.

On February 23, 2027, Penn will retire Text/SMS and Phone Call login methods for Two-Step Verification. Choose a more secure method before the deadline.

Learn about the change ->

Image
Microsoft

Update to Two-Step for Microsoft Services

Modernizing authentication for Penn's Microsoft services.

On March 31, 2027, Penn is updating how Two-Step connects with Microsoft services to strengthen protection and detect and respond to identity-based threats.

Learn about the Microsoft update ->

Image
Passwordless

Passwordless Login

A simpler, more secure way to sign in.

Penn is moving toward authentication that reduces reliance on passwords and uses stronger ways to verify your identity.

Learn about passwordless login ->

Image
High-Risk Apps

Stronger Protection for High-Risk Apps

Adding safeguards where they matter most.

Penn is strengthening access to applications with sensitive data or critical functions through centralized sign-in and additional access controls.

Learn about security improvements for high-risk apps ->

What's Changing When?

PennKey security improvements will roll out in phases. See the timeline below (click to enlarge):[timeline being updated]

Image
IAM Timeline

Completed Projects

For completed projects, see the IAM 2026 Security Program website.