mfa_students - Pomoc informatyczna

Launching the MFA

We would like to inform you that it is possible to enable two-factor authentication earlier. To do this, you must first log in to the Personal Identity Profile page at UJ - opt.uj.edu.pl. After logging in, a message should appear on the main page stating "Activation of multi-factor authentication (MFA) on the student account." Select the option "Activate MFA." After activation, two-factor authentication will be enabled on the account after approximately 12 hours. At that time, during the first login attempt, you will need to follow the steps outlined in the instructions.

We recommend downloading the application to your mobile device in advance and familiarizing yourself with the instructions. The configuration page has a session duration of several minutes. Therefore, if the application is installed only during the first login after MFA activation, the configuration time may be extended, which may result in incorrect addition of the method to the account.

The introduction of multi-factor authentication (MFA) for student accounts is based on Rector’s Order No. 108 of the Jagiellonian University, issued on 28 October 2025 to enhance the security of data and information processing.

Installing the Microsoft Authenticator App

The first step in configuring two-factor authentication is to install the Microsoft Authenticator app on your mobile device. You can download it from the App Store for iOS devices or from Google Play for Android devices.

When searching for the app, make sure to select the correct one. Search results may include apps that look very similar to the Microsoft Authenticator app, with similar icons or names. Verify the app by checking the publisher, which should be Microsoft Corporation.

After downloading and launching the app, a data privacy information screen will appear. Accept it by selecting the "Accept" option. On the next screen, choose the "Continue" option. There is no need to consent to the collection of additional data by the app.

After selecting "Continue," a window will appear asking you to add your first account. Skip this step for now and remain on the app's main page. You may see information about app lock, which you can enable or disable in the settings. At this point, the app installation on your device is complete.

 

Configuring the App with Your UJ Account

The next step is to configure the authentication method for your UJ account in Office 365. To do this, log in to office.com (or directly to the Security Info website mysignins.microsoft.com/security-info) using your UJ domain email address and password. If authentication has already been enforced by the administrator, a message "More information required" will appear. Click the "Next" button.

Since the app has already been downloaded on your device, select "Next" when the "Start by getting the app" information appears. In the next window, choose the option "Pair your account with the app" by clicking the link and allowing the Microsoft Authenticator app to open.

After launching the app, a message will appear asking for permission to send notifications. Accept it. If you do not accept, the authentication configuration will not be possible.

After a moment, the added account should appear in the app. A correctly added account should be displayed on a white bar. If the account is displayed on a gray bar, it means it is not configured with the app.

Once the account appears in the app, return to the browser and select the "Next" option. A two-digit code will be displayed, which you need to enter in the app.

After entering the code in the app, return to the browser and select the "Next" option.

A message at the top of the screen should indicate that the app has been successfully registered. Select the "Done" option.

If you are already using another application and would like to configure authentication for your account using it, please follow the instructions below. The configuration has been demonstrated here using the Google Authenticator app.

First, log in to office.com (or directly to the Security Info website mysignins.microsoft.com/security-info) using your UJ domain email address and password. If authentication has already been enforced by the administrator, a message "More information required" will appear. Click the "Next" button.

When the "Secure your account" window appears, select the option "I want to use a different authentication app." Information about adding a new account in the app will appear. Select the "Next" option.

In the next step, data will be generated that needs to be copied and pasted into the application. After launching the application, select the option "Add code."

Next, choose the option "Enter setup key." A window will appear where you can enter the data from the browser. Copy and paste the Account Name and Secret Key. Leave the key type unchanged. After entering the required data, select the "Add" option.

If the entered data is correct, the added account should appear in the application. Return to the browser window and select the "Next" option.

A window will appear where you need to enter the code displayed in the application. The code is regenerated every 30 seconds, so make sure it is current before entering it. After entering the code, select the "Next" option. A message at the top of the screen should indicate that the application has been successfully registered. Select the "Done" option.

1. Go to the website office.com (or directly to the Security Info website mysignins.microsoft.com/security-info).

2. Log in using your login identifier, which is the same as your email address in the uj.edu.pl domain.

3. You will receive a message, "More information required. Your organization needs more information to secure your account." Click the "Next" button.

4. In the next window, a message "Secure your account" will appear, suggesting the Microsoft Authenticator app. At the bottom left corner, there is a link "I want to set up a different method."

5. Click this link and then select the "Phone" method.

6. In the next window titled "Phone," select the country (Poland +48) and enter your smartphone number in the field below. Then, select to receive the code (if you want to receive SMS messages on your phone) and click the "Next" button.

7. In the next window, enter the verification code randomly generated in the app. If it is not clear, you can regenerate it using the refresh button located to the right of the image. Proceed by clicking the "Next" button.

8. The next message informs you that a 6-digit code has been sent to the previously indicated phone number. Enter it in the application window and click the "Next" button.

9. The penultimate window informs you that the verification has been completed and your phone has been registered. The "Next" button takes you to the final screen, where you are informed about the successful addition of the phone login method.

Installation and configuration instructions for the Microsoft Authenticator application

What if the user forgets their phone?

If you do not have your phone with you and cannot use the authentication app, you can temporarily disable two-factor authentication without contacting technical support.
To use this option:

  • Go to https://bypass.uj.edu.pl/.
  • Log in using your UJ account details and enter the CAPTCHA code.
  • A verification code will be sent to your private email address (other than an address in the student.uj.edu.pl or doctoral.uj.edu.pl domain). 
  • Enter the code on the website to complete the process.
Important: Your private email address must be accessible at the time of the procedure, as the verification code will be sent to it. You can check the private email address currently provided in the system by logging in to your JU Personal Identity Profile page (it is visible in the upper right corner of the screen).

After entering the code correctly, MFA authentication will be disabled for 3 hours, allowing you to log in to the systems without using MFA during that time. You can work until you close your browser session or log out.
If you need to log in again after 3 hours, repeat the procedure.

What should you do if you lose access to your phone?

If you completely lose access to your phone, you should immediately report this to the relevant IT Centre unit. This will allow you to restore access to your account and remove the lost device from the list of devices used for identity verification.

Deactivation of two-factor authentication is possible once the requesting person has been identified.

What to do if you get the error message ‘Verification method limit reached’?

When logging in to the system, the following message may appear:
„The verification method limit has been reached. Please try logging in again shortly.”
This situation most often occurs when the ‘Log in’ button has been clicked several times in quick succession. This can happen, for example, when the browser automatically fills in the login details (the system starts the authentication process) and the user additionally clicks the ‘Log in’ button.

What should you do in this situation?
It is possible to use a different method of providing the second login component than the default one.

After selecting Use another verification option, the methods available to the user will be displayed. These may include:

  • Send a notification to my mobile app
  • Use the verification code from the mobile app (...)
  • Send me a text message:+xx xxxxxxxxx
  • Call me:+xx xxxxxxxxx

If you use the Microsoft Authenticator app, you can use the verification code method. This method does not require a mobile network or internet connection. To do this, you need to:

1. Open the app and click on your account.

2. The 6-digit code should be displayed, which you can use in the ’Use verification code’ option in the mobile app (...). The code is single-use and changes every 30 seconds. You can use it without internet or mobile network access on your phone.

Can a user define alternative methods, and how can they do it?

The two-factor authentication service is activated by the IT Support Team. When it is active, users can define alternative login methods after logging in to the Security Info website mysignins.microsoft.com/security-info with the JU account identifier, and then select Add sign-in method.

Can a user have the Authenticator app on two phones?

Yes, it's possible to add the Microsoft Authenticator app to two mobile devices. Adding a second device is done in the same way as adding the first device. The app then works on both devices simultaneously.

At which points will it be necessary to provide the second factor? Is it required every time I log in to my mailbox?

Providing the second factor is necessary each time you log in to your account via a web browser. For logging in with the Outlook app or another mail client, the second factor will only be required during the first login to the application on your device.

What to do if the user does not have a smartphone or other mobile device (tablet)? 

If the user does not have a smartphone or other mobile device (on which the Microsoft Authenticator application could be installed), they should configure SMS messages as the second authentication factor. In this case, the user should follow the steps described above in the "MFA configuration using a phone number (SMS)" section.

Contact information:

If you have any questions, please do not hesitate to contact the IT Support Team at pomocit@uj.edu.pl or by phone at 12 663 50 70.

Two-factor authentication applies to Microsoft 365 cloud systems (including e-mail), USOSWeb, APD, VPN, and eLearning platforms.