mfa - Pomoc informatyczna

Two-factor authentication for your JU account

Using two-factor authentication keeps your account secure, even if your password is compromised. Dual authentication enables verification of the identity of the person who attempts to log in, making it significantly more difficult for criminals to access online accounts. The service configuration process requires a second authentication factor, which is exclusively available to the user (for example, the Microsoft Authenticator app on their smartphone). After setting the second factor the login procedure requires you to first sign in to the website with your account details, then authenticate the action via the app on your mobile device or by entering a code. Once the steps above are executed correctly, the account's login is authenticated.

Users who have received a notification requesting them to set up a second login factor must do so by the specified deadline. If the user does not add a second factor to their account, the procedure will be enforced by the administrator. The following instructions contain information on how to proceed in the event of enforcement of the procedure.

Procedure to be followed if the administrator enforces two-factor authentication- Android

Procedure to be followed if the administrator enforces two-factor authentication - iOS

 

If users would like to set up a second login factor before the deadline, they should use the instructions below.

Setting up dual authentication (MFA) for Android mobile devices

Setting up dual authentication (MFA) for iOS mobile devices

 

Devices that do not support the Play Store and AppStore and, therefore, cannot have the Microsoft Authenticator app installed can act as a second authentication factor as the device that will receive the SMS code during login confirmation.

To set up SMS notifications on your device, follow the steps below.

Using a computer, open a web browser and log in to office.com using your university login ID. Then click on the profile icon (with your initials or photo) in the top right corner and select View account.

Then select Security info from the menu on the left.

On the Security info website, select Add sign-in method.

Next, select Phone and then click the Add button.

In the next view, select the country and enter the phone number. Then select Receive a code (SMS) and confirm by clicking Next.

You will receive a 6-digit code sent to the phone number you provided. Please enter it in the next window and click Next.

You will receive a confirmation window that your phone number has been registered as a second login factor. Click on Done.

 

What to do if a user loses the ability to use their phone?

If the phone is completely lost, it is necessary to report this to the relevant unit of the IT Centre to enable logging into the account and to remove the missing device from the list of devices, allowing the user to verify their identity.

In the situation of a temporary loss or failure of a mobile device and the inability to use a phone with an authentication application, it is possible to disable two-factor logins for a few hours, but this requires contact with IT services.

Employees in the Collegium Novum need to contact the IT Services Department of the IT Centre.

Other employees should contact the IT Support Team.

Deactivation of two-factor authentication is possible once the requesting person has been identified.

Can a user define alternative methods, and how can they do it?

The two-factor authentication service is activated by the IT Support Team. When it is active, users can define alternative login methods after logging in to the page https://www.office.com/ with the JU account identifier.
In the upper right corner of the screen, select the circle with the initials or photo in it and choose the View account option. From the panel on the left side of the screen, select the Security Info, then Add sign-in method.

Can a user have the Authenticator app on two phones?

Yes, it's possible to add the Microsoft Authenticator app to two mobile devices. Adding a second device is done in the same way as adding the first device. The app then works on both devices simultaneously.

At which points will it be necessary to provide the second factor? Is it required every time I log in to my mailbox?

Providing the second factor is necessary each time you log in to your account via a web browser. For logging in with the Outlook app or another mail client, the second factor will only be required during the first login to the application on your device.

What to do if the user does not have a smartphone or other mobile device (tablet)? 

If the user does not have a smartphone or other mobile device (on which the Microsoft Authenticator application could be installed), they should configure SMS messages as the second authentication factor. In this case, the user should follow the steps described above in the "Devices not supporting the Play Store and App Store (SMS codes)" section.

What to do if the user does not have a phone?

If the user does not have a mobile phone, they should contact the IT Center to receive an additional authentication device - a so-called TOTP token. It will allow multi-factor authentication only if a user has it when logging in. In such circumstances, the user will need to carry the device with them, as only with its help will they be able to authenticate correctly in the JU systems. The user becomes responsible for the token after receipt and shall inform the IT Centre immediately if it is lost or destroyed.

Contact information:

If you have any questions, please do not hesitate to contact the IT Support Team at pomocit@uj.edu.pl or by phone at 12 663 50 70.
Collegium Novum employees should contact the IT Services Department. Contact is possible at dui@uj.edu.pl or by phone at 12 663 12 90, 12 663 12 19.

Two-factor authentication (MFA) introduces an additional level of security when accessing university IT systems using accounts in the uj.edu.pl domain. It provides additional protection against unauthorized access.

Information collected by the University during MFA authentication is collected solely to implement this process and is only available to persons administering or monitoring the login system.
The University uses Microsoft Authenticator and Microsoft Azure MFA to implement the two-factor login process.

Access to university services and resources (e.g. email, Office 365 services, extranet, EZD) will require an authenticator application running on a business or private mobile device. By using the Microsoft Authenticator application running on the user's device, the University collects the following personal data:
first and last name
login identifier (email address)
device name
device type
In order to detect attempts at unauthorized access, the application provides the login system with information about the device's location, but only the country name is registered. The exact coordinates of the device's location are not registered.

Personal data collected by the Microsoft Authenticator application will be processed by the Microsoft Azure MFA login system on behalf of the University and could be processed off-site as a result. In the scope of personal data processing, Microsoft, bound by a personal data entrustment agreement, may use personal data only to provide services to the University.

Providing the above personal data by installing, registering and using the Microsoft Authenticator application on a business or private device is voluntary. Without such consent, the user has to use an alternative method of two-factor login to access MFA-protected resources and services.