Skip to main content
Skip to main content

MFA is coming to the University of Siegen

The University of Siegen is introducing MFA!
MFA stands for multi-factor authentication. This information page explains what MFA is and why it is being introduced.
 

Hände vor einem Laptop mit einer Login-Maske. Neben der Tastatur schwebt ein Verteidigungsschild mit der Überschrift "MFA" und einem grünen Haken.

What is MFA?

Multi-factor authentication (MFA) is a security procedure that enhances the security of accessing an account or system.
In addition to a password, at least one other factor, known as a "token," is required. This factor can be a one-time code from an app or text message, a fingerprint, or a special USB drive, for example.

Using multiple factors prevents unauthorized users from accessing an account or system with only a password. This makes common phishing attempts significantly more difficult.

Who is affected, and starting when?

  • ZIMT employees (mandatory starting in 2025)
  • Central administration and management (mandatory starting in 2025)
  • Employees (mandatory starting in 2027)
  • Students (mandatory starting in 2027)

 

Types of Tokens

Choose the method that works best for you to log in.

Smartphone, das in einer Hand liegt und auf dem Bildschirm eine Push-Nachricht der eduMFA-App zeigt
For Android and iOS

PUSH

Log in via smartphone app confirmation
Just tap "Accept" or "Decline"
Ideal for quick confirmations in everyday work life
TOTP Token
App or hardware token

TOTP

Six-digit one-time code
Many authenticator apps offer support
Best Practices for Using Time-Limited, One-Time Codes
YubiKey 5 NFC und YubiKey 5C NFC
Hardware Key

YubiKey AES

Authentication via USB or NFC
No need to type in codes
High level of security is achieved through physical possession of the key.
Hardware-Token
Event-Based Hardware Token

HOTP

Generates a OTP code with the push of a button
Alternative to a YubiKey or a smartphone app
Convenient for people who don't want to use a smartphone
TAN-Liste
Paper-Based Emergency Solution

TAN List

Pre-generated one-time codes on a TAN list
Suitable as a backup or temporary solution
Store securely and protect from unauthorized access

The Path to the Second Factor

1

Sign in
to the portal

Go to the eduMFA portal (mfa.uni-siegen.de) and log in using your ZIMT account credentials.

 

Go to the eduMFA portal

2

Roll out
tokens

After successfully logging in to the eduMFA portal, click "Roll out Tokens" in the menu bar on the left to create tokens. It is strongly recommended that you set up at least two types of tokens.

3

MFA is
enabled

All done!

From now on, you will also be asked to provide one of your allocated tokens when logging in.

FAQ

Services connected via single sign-on (SSO) will be primarily affected. 

The following is a list of some examples of these services:

  • eduVPN,
  • Outlook Web Access (OWA), also known as Webmail,
  • UB services,
  • SharePoint,
  • Login to the University of Siegen website,
  • Cisco Webex,
  • Downloading Microsoft Office 365,
  • Citrix Workspace

Yes, all employees, students and external users must activate MFA for their account sooner or later. This is the only way to ensure effective protection for all members of the university. The targeted times can be found further up on this page in the blue box. Starting from January 1, 2027, MFA will also become technically mandatory for employees outside the central administration as well as for students, meaning that logging in without two-factor authentication will no longer be possible.

With the introduction of multi-factor authentication (MFA), the login process for various systems and services (see above) at the university will change. Instead of just entering a password, you will also have to provide a second authentication factor.

The introduction of MFA at the University of Siegen is based on the legal regulations from the agreement on cyber security of the Ministry of Culture and Science (MKW). This agreement requires universities in NRW to implement appropriate security measures to protect the integrity and confidentiality of data.

A token is a type of digital key. It is used to log in securely to a system or an app. A token can be a small device, a smartphone app or a special code, for example. One common type of token is a one-time numeric code that is only valid for a short period of time. In addition to the password, these codes are used to confirm that you are really authorized to log in.

You can think of it like the door of a safe. The safe has a combination lock and a key. For the combination lock, you need to know the corresponding combination, such as a password. The token, i.e. the second factor, is a physical key in this case, i.e. something you must have. You can only open the safe door if you have both.

This is also how it works digitally: you log in as usual with your username and password and confirm the login with a YubiKey or a TOTP authenticator app installed on your mobile device. This makes your access much more secure.

Multi-factor authentication (MFA) is a security procedure that makes access to an account or system more secure.
In addition to the password, at least one other factor, known as a token, is required. This factor can be, for example, a unique code from an app or text message, a fingerprint or a special USB stick.

The combination of several factors prevents unauthorized persons from gaining access to an account or system with the password alone.

Frau mit Headset im Support

ZIMT Support Desk

The central point of contact for accessing ZIMT's services.