Info
If no second factor has yet been configured for sign-in with your university Microsoft account, you will be prompted to set one up during the sign-in process. The following options are available:
- Students/Guests: Use a TOTP-capable client (recommended: Microsoft Authenticator).
- Employees: Use a TOTP-capable client (recommended: Microsoft Authenticator) or use passkeys.
Tipp
To sign in, use your UPN (i.e., the short @uni-a.de email address) together with the password associated with your RZ account. You can look up your correct UPN, for example, in the global "People" address book via Webmail.
FAQ
Bekannte Probleme und (Fehler-)Meldungen finden Sie in folgendem FAQ: Entra-ID Known Issues and FAQs
Setup dialog during the first sign-in
Upon your first sign-in—for example at https://myaccount.microsoft.com—you will be prompted to add a second authentication factor.
- "Next"
Depending on which method you would like to set up, proceed with the corresponding section of the guide.
Microsoft Authenticator-App (TOTP/Push)
The app is permanently required for sign-in after it has been set up and should therefore not be uninstalled, as doing so will result in the loss of its configuration.
When replacing your device, please ensure that the app has been successfully set up and tested on the new device before resetting, handing over, or disposing of the old one. This helps ensure uninterrupted access to your account.
The app is required permanently for sign-in after it has been set up and therefore should not be uninstalled, as doing so will result in the loss of its configuration. Likewise, before switching devices, you should first verify that the setup works on the new device before resetting the old device for transfer or disposal.
Confirm the use of the Microsoft Authenticator app by selecting "Next."
- "QR-Code Anzeigen"
Download the Microsoft Authenticator app (published by Microsoft Corporation) to your smartphone from the Apple App Store (Download) or the Google Play Store (Download).
→ Tip: On university-managed iOS/iPadOS devices that have already been enrolled in the Basic Management service or were issued by the IT Center, the app is pre-installed.Open the app and, if prompted, accept the privacy-related requests. Do not allow the sharing of usage data.
If you are using the app for the first time, we recommend selecting the "Scan QR Code" option right away.
→ Already using Microsoft Authenticator? Simply tap the plus (+) icon in the top-right corner, add a new "Work or school account," and select "Scan QR Code."Allow the app to access and use the camera.
Scan the displayed QR code using your smartphone's camera.
If prompted, allow the app to display notifications.
Once the account has been added, click "Next" on the website to continue.
A number will be displayed on the website. Enter this number into the notification prompt in the Microsoft Authenticator app on your smartphone and confirm by selecting "Yes."
Click "Next" to confirm. The setup is now complete.
Passkeys
Through the Microsoft account settings, University of Augsburg employees can register a security key (FIDO2 key) as a second authentication factor.
Only hardware bound security keys (such as YubiKeys, Swissbit iShield, NitroKey) are supported for this purpose.
Yubikeys
Hardware security keys are additional peripheral devices. Employees who wish to use YubiKeys should contact their responsible IT support team (DV-Betreuung), they can provide the necessary hardware as well as assistance with setup and later support.
- "Security Info"
"Add sign-in method"
Select "Security key" as the desired method from the pop-up menu.
- Select "USB-device"
- "Next"
If prompted, confirm the Windows security message by selecting "Security Key" and then clicking "Next."
- Confirm both dialogs with "OK"
If it's the first time using the key, create a PIN for the security key (you will later need it every time you use the key)
→ This PIN is not recoverable - If you forget your PIN, you would need to reset the key fully, thus loosing all stored Secrets/Passkeys not your PIN/Password somwhere safe!
If you already used the key before and already have a PIN just enter the pin now- "OK"
Enter a descriptive name for the security key and click "Next."
- "Finish"
KeePassXC Passwordmanager (TOTP)
KeePassXC is a free and open-source password manager that provides many useful features for the secure and convenient storage of passwords and other credentials. The software is also capable of generating one-time passwords (TOTP), which can be used as a second authentication factor for a university Microsoft account. In this scenario, KeePassXC acts as an authenticator application.
Select the "I want to use a different authenticator app" link.
- "Next"
Select "Can't scan the image?"
Copy the displayed secret key.
Open and unlock your existing KeePassXC database.
→ For workstations provided by the University Computing Center (e.g., Central Administration, Faculty of Medicine, Presidential Office, CCR, etc.), instructions for creating and using such a database can be found in the IT Center Service Portal.Create a new entry for the Microsoft account by clicking the "+" (Add Entry) icon.
Only the title is required. The username and password fields can be left blank.
Click "OK" to save the entry.
Right-click the new entry to open the context menu.
Expand the "TOTP" menu item.
Select "Set up TOTP"
Paste the previously copied secret key into the input field.
- "OK"
On the website, confirm the setup by clicking "Next."
You will now be asked to enter a one-time password (OTP) code to verify the setup.
This code can be displayed in KeePassXC either by clicking the clock icon for the selected entry or copied directly via the context menu.
→ The displayed space is for formatting purposes only and is not part of the code.After entering the code, click "Next" once again to confirm and complete the setup.
The setup is complete.
(Work) Phonecall
Telefon 2-Faktor-Anmeldung abgekündigt
Microsoft has announced the retirement of two-factor authentication via phone call (and SMS) effective February 1, 2027.
Users who are still using this method after September 1, 2026, will automatically be prompted to register an alternative two-factor authentication method. The University Computing Center (RZ) recommends using the Microsoft Authenticator app (see above).
Employees have the option of using a phone number as the destination for the second authentication factor—either as the sole method or as a backup to an OTP authenticator app.
Note: If a phone number is configured as the only second-factor method, additional sign-in prompts may appear when accessing services, encouraging the use of the Microsoft Authenticator app. For more information, see the FAQ: Known Messages and Errors.
Select the Germany (+49) country code and enter the phone number.
- "Next"
The entered phone number will now receive a verification call to confirm the registration.
The call must be answered, and after listening to the automated message, confirmation must be provided by pressing the hash (#) key on the phone keypad
The phone authentication method has now been successfully configured.
Notes on Additional TOTP Clients
Info
In principle, any TOTP-compatible authenticator client can be used with a Microsoft account, including FreeOTP, Ente Auth, Yubico Authenticator, Google Authenticator, and others.
If you require assistance, please contact your responsible IT support team (DV-Betreuung) to find out which additional TOTP clients are supported in your environment.





































