Multi Factor Authentication (MFA) policy regarding access to RCCD systems

Tags mfa

Multi-factor authentication (MFA) is required for access to all SSO web applications by both students and employees.

 

Previous to May 2026, MFA was only required for certain web applications. As of June 2026 users will need to verify their identity (password and MFA) when signing into any browser application via RCCD's SSO (a.k.a. single sign-on or applications through https://myapplications.microsoft.com/)

 

Users will only need to complete MFA once per browser session. Once users have verified their identity in one browser app, that carries over to all other apps--no need to re-verify every time you switch tools. (You may need to refresh open browser tabs.) MFA will only be prompted again when your browser session ends (e.g. you close your browser, your app session times out, or you explicitly sign out).

 

2. Your browser will no longer stay logged in between sessions

 

You may have noticed that after logging in once, your browser remembered you and skipped the MFA prompt next time. That behavior is going away. Each new session will require a fresh sign-in.

 

Why? When a browser "remembers" you, it stores a small file called a session cookie — essentially a temporary digital pass that proves you already logged in. The problem is that cybercriminals have found ways to steal these passes without ever needing your password or MFA code:

 

  • Fake login pages: Attackers set up convincing lookalike websites that sit invisibly between you and the real site. When you log in and complete MFA, the fake site grabs your session cookie in real time and uses it to access your account as if they were you.

 

  • Malware on your device: If your computer is infected with malicious software, attackers can quietly scoop up all the session cookies stored in your browser and use them to hijack your accounts.

 

By ending sessions after each use, we make stolen cookies worthless.