Stronger sign-ins. Better protection for you and Penn.
Your PennKey provides access to many of the systems, services, and information you use at Penn. And as cyberattacks and attempts to compromise user accounts become more sophisticated, protecting that access is increasingly important.
Penn is strengthening authentication and access controls across the University to help keep your account – and Penn’s data and systems – more secure.
Here’s what’s changing—and what you need to know.
PennKey Security Improvements
Text/SMS & Phone Call for Two-Step Ending Moving to stronger ways to verify it's really you. | On February 23, 2027, Penn will retire Text/SMS and Phone Call login methods for Two-Step Verification. Choose a more secure method before the deadline. | |
Update to Two-Step for Microsoft Services Modernizing authentication for Penn's Microsoft services. | On March 31, 2027, Penn is updating how Two-Step connects with Microsoft services to strengthen protection and detect and respond to identity-based threats. | |
Passwordless Login A simpler, more secure way to sign in. | Penn is moving toward authentication that reduces reliance on passwords and uses stronger ways to verify your identity. | |
Stronger Protection for High-Risk Apps Adding safeguards where they matter most. | Penn is strengthening access to applications with sensitive data or critical functions through centralized sign-in and additional access controls. |
What's Changing When?
PennKey security improvements will roll out in phases. See the timeline below (click to enlarge):[timeline being updated]

Completed Projects
For completed projects, see the IAM 2026 Security Program website.




