Multifactor authentication

In order to further enhance IT security at the university, multi-factor authentication (MFA) will be introduced for logging into central IT services. This procedure offers additional protection against unauthorized access and data misuse by requiring at least one second security component in addition to the password.
Ziel dieser Anleitung:
Einrichten der Multi-FaktorAuthentifizierung mit 2 Faktoren: YubiKey und Microsoft Authenticator Smartphone App
Voraussetzungen:
Sie besitzen einen YubiKey und ein Smartphone. Idealerweise sind Sie im Büro an einem Windows Dienstrechner mit ZIM-Installation.
- Go to the Microsoft website https://aka.ms/mysecurityinfo to manage your authentication factors.
- Log in with your ZIM ID in the following format: ZIM ID@ads.uni-passau.de and use your regular password.
- The "Security Information" menu item on the left is pre-selected.
2. Activate the "Microsoft Authenticator" factor
- After completing step 1 and logging in, click "Add sign-in method."
- Select Microsoft Authenticator.
- Scan the QR code on the monitor using the Microsoft Authenticator app, which you installed from your smartphone's app store.
3. Activate Yubi Key authentication factor:
- Your YubiKey is correctly inserted in the computer; the logo on the key is illuminated.
- After step 1, select "Add login method" again. Select security key, type USB device.
- Assign a PIN to your YubiKey – remember it! YubiKey setup is now complete.
- Note: Multi-factor authentication (MFA) will be active starting the next business day. Every employee should have at least two authentication factors set up.
![[Translate to Englisch:] Ansicht MFA Security](/fileadmin/_processed_/e/f/csm_MFA_Methoden_3d02754e5e.png)
![[Translate to Englisch:] MFA Authentifikator](/fileadmin/_processed_/e/e/csm_MFA_Auth_2408d89915.jpg)
Procedure for students
- The following authentication methods are available to students:
- Authenticator app: e.g., from any third-party provider.
- SMS TAN procedure.
- Effective immediately: Start of the activation phase: You can set up an MFA method yourself—once set up, MFA will be active from the next working day and must be used.
- From the end of January 2026: Multi-factor authentication becomes mandatory.
Quick Start for first-year students or students who haven't yet set up multi-factor authentication (MFA):
- Upon your first login, for example to the campus portal, you will be prompted to set up an MFA method. Important: Log in with your new ZIM ID (muster06@ads.uni-passau.de).
- After entering your username and password, the message "Let's protect your account" will appear. You can choose from the following methods: Register your mobile phone number Log in via SMS TAN or phone call Microsoft Authenticator App Authentication via the official Microsoft app
- Third-party authenticator app e.g., Google Authenticator, FreeOTP, or other compatible apps Click "Next": By default, setting up Microsoft Authenticator will be suggested. You can start this directly by clicking "Next."
- Then follow the on-screen instructions. Managing your configured MFA methods: Open https://aka.ms/mysecurityinfo Here you can delete methods or add new ones.
- If you lose your configured MFA methods, you can restore them via "MFA Recovery/Loss".
What safety factors can be used?
All employees must have registered a security key by the end of January 2026.
To register the security key, you must already have set up one of the authentication methods for MFA described in more detail below (authenticator app, TOTP, or Hello for Business). If you have already installed an authentication app (e.g., Google Authenticator, etc.), you can also use this and link it to your Microsoft Uni account. This will not affect the accounts already linked in your existing authenticator app.
In addition to the security key, set up at least one authentication app on a smartphone. It is also recommended that you set up and link an authentication app on two different devices. This ensures that you will always have access to your account even if you lose one of your devices.







