Service Portal

Multi-Factor Authentication - FAQ for employees

The requirements for processing sensitive personal data have been increased with the General Data Protection Regulation (GDPR). Sensitive personal data are, of course, sensitive by nature and enjoy extra protection under the GDPR. Using only a user name and password to log in no longer suffices. The UT uses several applications that process sensitive personal data. On the basis of the GDPR, the UT must provide additional security for these applications via authentication in multiple steps: MFA. 

  • Description

    Multi-Factor Authentication

    Passwords can be easily compromised. MFA immediately increases your account security by requiring multiple forms of verification to prove your identity when signing into an application.

  • Requests

    MFA does not need to be requested.

  • Costs

    There are no costs.

  • Conditions

    To make use of MFA you need a:

    • UT ICT-account
    • Smartphone
  • Support

    For support, please refer to the manual, FAQ (below) or contact the Service Desk ICT.

FAQ

Explanation MFA application

  • Why is Multi-Factor Authentication necessary?

    In the General Data Protection Regulation (GDPR), the criteria set for processing special personal data have been tightened. Special personal data is highly sensitive and therefore receives additional protection under the GDPR. Logging in with a username and password is no longer sufficient.
    The UT utilises multiple applications within which personal data is processed. The GDPR stipulates that these applications are additionally secured by means of authentication in two steps: MFA.

  • Why is logging in with only my account and password insufficiently secure?

    Programmes may contain data to which others are not permitted access. This may include research data, examination results, or bank account numbers. Passwords can be found out with relative ease, for example when you:

    • use the same password for multiple websites;
    • download malicious software from the internet;
    • accidentally activate incorrect links in a phishing email;
    • provide your password to others.

    Thanks to additional authentication, the university can exclude information from unwanted individuals, even when they possess your password. For this reason, your additional authentication is for personal use only.

  • What is the risk of others knowing my password?

    An individual in possession of your password can block access to your account and:

    • view or even delete your emails, contacts, and educational or research data;
    • masquerade as you and send unsolicited or malicious emails to your contacts;
    • use your account to reset the passwords for your other accounts;
    • gain access to all information accessible to you, such as student data.
  • Will all of the university's systems have additional authentication?

    Eventually all systems will use MFA. First it will be activated for employees. It is expected that in 2021 it will be activated for students also. 

Install and ACtivate

  • Installing and activating MFA application

    You can find the manual here.

Mobile Telephone

  • Is it necessary to provide the UT with my mobile telephone number?

    The UT does not require your mobile telephone number, and this will not be requested and/or registered.

  • My mobile telephone doesn't support apps. What should I do?

    A smartphone is required to log in with the MFA.

  • I don't want to use my private telephone for work. How can I log in with MFA?

    If the UT has not provided you with a smartphone and you don't wish to use a private smartphone for the MFA, you can obtain a low-budget smartphone via the LISA self-service portal. The charges will be covered by the faculty/service department. You will require an OFI number from your organisation for ordering a low-budget telephone.

  • I don't have internet on my mobile telephone, will the app still work?

    An internet connection (WiFi/3G/4G) is only required for app installation/activation. Once it's set you can also use the time-based, one-time passcode in the app.

  • Why does the MFA app request access to the camera? 

    The app requires camera access to scan a code during installation and use of additional authentication. The app only activates the camera for these purposes.

  • Why am I unable to scan the QR code? 

    Tips for successful QR code scanning: 

    • Zoom level of PC browser set to minimum 100%
    • While scanning:  do not hold the device too close to the screen! Make sure that the QR code fills approx. 25% of the screen. Hold the device still!
    • Hold your smartphone very still while scanning. Your smartphone may need a few moments for scanning, as the camera must first zoom in on the QR code.
    • Ensure that only the QR code is in the frame when scanning.
    • Keep any objects, such as your finger, from obstructing the camera during scanning.
    • Increase the brightness of your computer screen. This increases the contrast of the QR code, making it easier for your camera to scan.
  • I have a new smartphone | My current smartphone is stolen or reset | I have colleted a spare smartphone. What should I do? 

    If you have a new smartphone due to replacement, loss or theft, you must reconfigure the MFA app. There are two possibilities:

    • Deactivate the authenticator on your old device and activate the authenticator on your new device.
    • Delete the registerd device and activate the authenticator on your new device.
    • Contact the Service Desk ICT.
  • My smartphone is at home and I cannot log in to additionally secured systems now. What should I do?
    • Collect your smartphone, if possible.
    • In case the organisation has a spare smartphone, activate it using an already set up second verification method or contact the Service Desk ICT

Authentication, verification, etc.

  • Is it, next to app notifications, also possible to receive text messages (sms) for FMA?

    You can add an extra method here.

  • How does offline use of additional authentication work?

    During offline use, the Microsoft Authenticator app automatically create an offline code which can be entered on your screen. This allows you to use the additional authentication offline at all times.

  • Can I authorise someone else to log in on my behalf?

    No, this is not possible. MFA is for personal use only and cannot be transferred.

Further Questions

  • Who can I contact if I have further questions?

    Please contact the Service Desk ICT.

My bookmarks

Manage

Please wait a moment...