Skip to main content
Skip to main content

MFA comes to the University of Siegen

The University of Siegen is getting MFA!
MFA stands for multi-factor authentication. Find out what it is all about and why MFA is being introduced on this information page.

Hände vor einem Laptop mit einer Login-Maske. Neben der Tastatur schwebt ein Verteidigungsschild mit der Überschrift "MFA" und einem grünen Haken.

What is MFA?

Multi-factor authentication (MFA) is a security procedure that makes access to an account or system more secure.
In addition to the password, at least one other factor, known as a token, is required. This factor can be, for example, a unique code from an app or text message, a fingerprint or a special USB stick.

The combination of several factors prevents unauthorized persons from gaining access to an account or system with the password alone. This makes common phishing attempts considerably more difficult.

Who is affected and when?

  • ZIMT employees (from 2025)
  • Central administration and executives (from the end of 2025)
  • Employees (from 2026)
  • Students (from 2026)

 

Which services should MFA receive?

Services that are connected via single sign-on (SSO) will mainly be affected. Some services are listed below as examples.

shield
Shibboleth
graduation-cap-neon
eduVPN

The new VPN client eduVPN will only be usable with a configured MFA.

Icon Bücher
UB services

University Library services based on ZIMT services (e.g. UB account).

Haus
USI website

The login on the Uni-Siegen website.

Icon Datei Abzeichen
X-Moodle

In contrast to the teaching Moodle, X-Moodle ("Exam-Moodle") is a separate instance with restricted usage scenarios for examinations.

shield-user
NetScaler
Icon Mail
Outlook WebAccess (OWA)

Also known as webmail.

folder-tree-neon
SharePoint

SharePoint supports collaboration in project teams and departments with the help of dynamic and efficient team websites.

headset-neon
Cisco Webex

Webex is a comprehensive suite for video conferencing, online meetings, webinars, file sharing and team collaboration.

Icon Schule
Citrix Workspace

Citrix Workspace is an integrated platform that enables employees to securely deploy and manage applications, data and desktops.

The path to the second factor

1

Register with the portal

Go to the eduMFA portal (mfa.uni-siegen.de) and log in with your ZIMT or ZV account data.

2

Roll out token

After successfully logging in to the eduMFA portal, you can click on Roll out tokens or Assign tokens (only YubiKeys of the ZV) in the menu bar on the left and then roll out the tokens of your choice. It is strongly recommended to set up at least two token types.

3

MFA is activated

You've done it!

From now on, you will also be asked for one of your rolled-out tokens when you log in.

Roll out a new token

Video coming soon...

ZV - YubiKey and TAN list

Video coming soon...

Install and set up eduVPN

Video coming soon...

Don't have a second factor yet? Click here to go directly to the eduMFA portal.

The most important information at a glance

Multi-factor authentication (MFA) is a security procedure that makes access to an account or system more secure.
In addition to the password, at least one other factor, known as a token, is required. This factor can be, for example, a unique code from an app or text message, a fingerprint or a special USB stick.

The combination of several factors prevents unauthorized persons from gaining access to an account or system with the password alone.

A token is a type of digital key. It is used to log in securely to a system or an app. A token can be a small device, a smartphone app or a special code, for example. One common type of token is a one-time numerical code that is only valid for a short period of time. In addition to the password, these codes are used to confirm that you are really authorized to log in.

You can think of it like the door of a safe. The safe has a combination lock and a key. For the combination lock, you need to know the corresponding combination, such as a password. The token, i.e. the second factor, is a physical key in this case, i.e. something you must have. You can only open the safe door if you have both.

This is also how it works digitally: you log in as usual with your ID and password and confirm the login with a YubiKey or a TOTP app installed on your smartphone. This makes your access much more secure.

The introduction of MFA at the University of Siegen is based on the legal requirements of the Cyber Security Agreement of the Ministry of Culture and Science (MKW). This agreement requires universities in NRW to implement appropriate security measures to protect the integrity and confidentiality of data.

With the introduction of multi-factor authentication (MFA), the login process for various systems and services (see above) at the university will change. Instead of just entering a password, you will also have to provide a second authentication factor.

Yes, all employees, students and external users must activate MFA for their account sooner or later. This is the only way to ensure effective protection for all members of the university. The target times can be found further up on this page in the blue box.

Supported are:

  • Time-based one-time password (TOTP, Authenticator app)
  • One-time password (OTP) via YubiKey (special USB stick)
  • Push notification (eduMFA app)
  • TAN list

Note: Two tokens per token type can be active .

The following authenticator apps were tested for their supported parameters.

Please note: The apps are backwards compatible - an app that supports 60-second time steps also offers 30-second steps; an app with SHA512 support also allows SHA256 and SHA1.

App Maximum time step Maximum algorithm
2FA Authenticator 60s SHA512
Aegis Authenticator 60s SHA512
Bitwarden Authenticator 60s SHA512
Duo Mobile 30s SHA1
Duck Auth 60s SHA512
FreeOTP 60s SHA512
Google Authenticator 30s SHA1
LastPass Authenticator 60s SHA512
Microsoft Authenticator 30s SHA1
Proton Authenticator 60s SHA512
Yubico Authenticator 60s SHA512

Yes, there are alternative options.

Note: If possible, we recommend setting up a TOTP and/or push token on a smartphone or using a YubiKey.

Here you will find alternative hardware and software if you cannot or do not want to use any of the above options.
However, we do not offer support for these!

Hardware:

Software:

Various services, such as the EU procurement portal, have now also introduced mandatory MFA. If supported and available, you can also use your YubiKey or your Authenticator app for this.

You can find more information here:

If you have any further questions, please contact the ZIMT SupportDesk, either

  • by e-mail to: support@zimt.uni-siegen.de
  • or by phone: (0271) 740 - 4777 
    (Mon. - Fri. 08:00 - 15:30)
  • In person in room H-D 2203
    (opening hours: Mon. - Fri. from 8:00 - 16:00, by telephone until 15:30)
Service facility

Center for Information and Media Technology (ZIMT)

ZIMT is the central science-related IT facility of the University of Siegen and is responsible for modern, innovative and economical IT and media services to meet the requirements of users in administration, studies, research and teaching.

zimt_logo