Info
Frequently asked questions about the Two-Factor-Authentication (=2FA).
General
Why does the University of Augsburg protect its account & services with 2FA?
All university accounts have access to sensitive information! Not only personal data such as name, date of birth and addresses deserve appropriate protection - for example to prevent identity theft - but also data to which the account has access: Research data, course content, examination results, ...
Not to forget: Attackers can use stolen credentials to cause damage to university systems, for example by sending SPAM (viruses, phishing, etc.), arbitrarily destroying data or disrupting exams.
And this is precisely where 2FA comes in: it provides effective protection against phishing attempts. Even if the password has been disclosed unnoticed, an attacker cannot use the account: they lack the second factor. 2FA also protects against data leaks. So in general even if the account/password combination is leaked, the requirement for the second factor prevents unauthorized access.
Which 2FA methods can I use?
If you use the easy log in via the university Microsoft account (i.e. with the @uni-a.de address), you can choose between OTP (one-time PINs via app), Hello for Business or a call to the work telephone number, depending on the user group (employees/students). We recommend using the Microsoft Authenticator here, supplemented by Hello for Business on work devices.
Alternatively, if you do not want to use the Microsoft account, you can also set up passkeys for passwordless login or set up a local OTP application for the RZ-Kennung. However, a (initial) login with the Microsoft account is required for the first setup.
Can I transfer my 2nd factors from one smartphone to another?
This depends on the app you are using: you can either export the stored accounts - or transfer them directly to the new device when you move to the new device. Alternatively, you can simply add the new device as an additional device and then remove the old device from the account.
I don't have a smartphone, can I still use 2FA?
Of course - you have several options to choose from: For example you can use the free software KeePassXC on your PC (Windows / macOS / Linux) as an authenticator app to generate the OTP codes (both for the Microsoft account and for the RZ-Kennung / Keycloak) or you can use a passkey. Employees can also register a telephone number with Microsoft if necessary. The use of a FIDO2 security key - e.g. a YubiKey or Swissbit iShield is a particularly convenient option which is also possible.
I don't have my own computer or smartphone, what can I do?
In this case, please come to our support and service center (ZEBRA) in person during opening hours to find a solution for your case.
Microsoft Account
I do not see a QR code when registering / registration fails in some other way.
Simply visit the support and service center (ZEBRA) with a (valid) ID and we will reset the registration methods for you. You can then set up the authenticator again.
If you are unable to reach us during our opening hours, please contact us (if access is still possible, e.g. via ‘Hello for Business’) via our customer portal https://support.rz.uni-augsburg.de/servicedesk or alternatively by mail to service@rz.uni-augsburg.de. Please scan (or photograph) your ID (front and back) - and if possible your CampusCard for easier identification - and upload it to the ticket or attach it to the mail.
I want to register my 2nd factor, but I am already prompted to enter a checking digit
As Microsoft has required 2-factor login for some time now, you have probably already set it up in the past for the installation of Office 365. If there is still an entry for the university account in the Microsoft Authenticator on your device, it is possible that only the authorisation for the notification is missing. In this case, simply follow the instructions here: https://collab.dvb.bayern/x/ryfca
If you no longer have access to the previously used device / app or if there is no longer an account stored, you can also reset the login; the same applies here as for: I do not see a QR code when registering
My login always gets rejected on my Apple device: I am in a login loop!
This is usually a problem with the Apple password manager if you have the password filled in automatically. The password manager replaces the user name (@uni-a.de) with the RZ-Kennung - even if this field is no longer displayed. Try entering the password manually - this can also be displayed in the ‘Passwords’ app if you can not remember it.
Passkeys
What is that and what is the benefit of it?
Passkeys (also known as WebAuthN or FIDO2 keys) are cryptographic keys that are much more secure than passwords. In a nutshell, when you log in, the service presents your device with a complicated ‘task’ that can only be solved with the existing passkey. The passkey can be protected by a (short) PIN or with biometrics, and is therefore a 2-factor login. A passkey can also be stored on an dedicated security key (e.g. YubiKey) so that you don't have to create multiple passkeys for each device - a bit like a centralized key for office doors.
So instead of always having to remember longer and more complicated passwords (and possibly having to use an authenticator app), logging in to Digicampus, for example, can now be ‘passwordless’ and only requires a PIN, fingerprint or facial recognition on the smartphone or laptop/PC.
What Passkey methods are currently supported?
At the moment official support is limited to handling passkeys via KeePassXC (or KeePassium on iOS/iPadOS) as well as physical FIDO2 security keys like YubiKeys, SoloKeys or SwissBit iShields. The built-in solutions offered by the manufacturers like the iCloud-Keychain or Google Passwords are predominately cloud based offerings and thus are restricted by data protection regulations which is why we can not support them officially for now.
How do I setup Passkeys?
For the initial setup, login with the university Microsoft account to our login portal https://auth.rz.uni-augsburg.de. You can then set up your desired passkey method there to be used alternatively to the Microsoft account. See our overview & instructions on the sub pages of https://collab.dvb.bayern/x/bKuqXQ
RZ-Kennung, Password and Authenticator
I am already using another authenticator (Google Authenticator, iCloud etc.) can I keep using this one?
In gerneral, all TOTP applications can be used. But you will receive support through guidance & the service desk / IT support only for the Microsoft Authenticator, 2FAS, FreeOTP and KeePassXC apps described.