Multifactor authentication - FAQ
I've already enabled two-factor authentication, but it's not working. What do I do?
What should I do if I get a new phone?
When I try to log in to TUNI services, I am offered my O365 account from another organisation. What shall I do?
How do I register the Microsoft Authenticator app for my use if I already have text message authentication?
How do I set up MFA in another phone?
Reading the QR code does not work in the application. What do I do?
Can I set up only SMS-based authentication method because I do not have a smartphone?
How do I set up USB security key for my use if I already have SMS-based authentication?
How can I change the PIN code of the USB security key? Or what if I don't remember it?
How do I turn off usage data collection from the phone app?
What do I do if my phone breaks?
I unexpectedly received a request to accept multifactor authentication, even though I'm not logging into anything. Do I still accept the request?
I've already enabled two-factor authentication, but it's not working. What do I do?
If the multifactor verification method you have enabled in the past is not available, you can log in to the Security info page (aka.ms/mfasetup) with a temporary access pass. You can get a temporary access pass from the password.tuni.fi service. The function requires strong identification in the Suomi.fi service. Read more about identification methods.
- Go to password.tuni.fi with your browser.
- Click Start by authenticating button to create a temporary access pass for you.
- Identify yourself by choosing an identification method on e-identification page.
- Finnish means of identification: online banking ID, mobile certificate, or Citizen Certificate card.
- If you do not have a Finnish means of identification: click Identification methods for foreigners at the bottom of the e-identification page. Choose an identification method you can use. Read more on e-identification methods.
- On the screen that appears after identification, select Reset multi-factor authentication (MFA) by clicking Reset MFA.
- Click the Continue button under the Set a temporary access pass heading to create a temporary access pass.
- The temporary access pass appears on the screen in the box with the green background. The temporary access pass is only valid for a limited period of time. Complete the MFA settings immediately after setting the temporary access pass.
- Copy the code in the box with the green background and press Continue.
- The Continue button redirects you to the login screen. In the Sign in box, type your TUNI email address.
- Use the temporary access pass that you copied to log in.
- After logging in, you will be able to remove the non-functional authentication method and to set a new authentication method on the Security Info page.
What should I do if I get a new phone?
- Enable multifactor authentication on your new phone according to the instructions Setting up multifactor authentication.
- Only after this, remove the old phone from the authentication service at https://aka.ms/mfasetup
When I try to log in to TUNI services, I am offered my O365 account from another organisation. What shall I do?
You can use another browser or the browser's private mode and then log in to TUNI services with your TUNI email address. However, the option to use another browser is not always possible for an application that uses a (default) browser to log in, such as eduVPN or Zoom.
In this case, you can go to the address https://www.tuni.fi/hakalogout, which will log you out from the session. Then close the browser. Log in again, select Use another account and this way you should be able to log in with your TUNI email address.
How do I register the Microsoft Authenticator app for my use if I already have text message authentication?
When text message identification has already been activated, the setting up of Microsoft Authenticator app involves two phases. You will need an Android/Apple smartphone and a computer equipped with a browser, such as Edge or Google Chrome.
The TUNI staff computer no longer needs to be in the TUNI-STAFF network or with TUNI VPN turned on when working remotely. It is sufficient that the machine is used from Finland. When using from Finland, your own personal device does not require eduVPN either. You only need to use a VPN connection when registering multi-factor authentication from abroad.
Read the instructions on how to get a VPN connection on your personal computer (Windows, Linux tai macOS).
1. Install the Microsoft Authenticator app on your phone
- Download and install the Microsoft Authenticator app on your phone from the app store.
- Open the Microsoft Authenticator app after downloading.
- The first time you log in, allow the collection of anonymised data when prompted to do so. You can turn off data collection later.
- If prompted, select Allow to allow notifications.
- Select Add a new account, Work- or school account
- Select Scan QR code.
- Allow the authenticator app access to your camera to take a picture of the QR code in the next phase.
- The app waits for a QR code to add your TUNI account to the Microsoft Authenticator app on your phone.
- Put your phone aside for a moment and go to phase 2.
NOTE! If the authentication application indicates that it is locked and asks you to enter the lock code, then use the same code that you use to unlock your phone screen/display.
2. Add your TUNI account to the Microsoft Authenticator app
- With your computer, go to the web address https://aka.ms/mfasetup
- Log in with your TUNI email address and password.
- On Security info -page click + Add a method.
- In the drop-down menu, select Authenticator app.
- The browser displays information about using the Microsoft Authenticator app.
- In your browser, click Next, and a QR code appears on screen.
- Take your phone and scan the provided QR code with the QR code reader of the Microsoft Authenticator app. If the authenticator application asks for a lock code, this is the lock code of the phone display.
- After the Microsoft Authenticator app has scanned the QR code, click Next in the browser window.
- The app will send a notification to your phone as a test.
- Select Approve.
- In your browser window, click Next.
- Then click Done.
- Your TUNI account has now been added to the Microsoft Authenticator app on your phone.
How do I set up MFA in another phone?
It is convenient to set up MFA also in another phone especially if you have enabled MFA on your work phone and happen to forget the phone in the workplace.
- Complete the steps described in phase 1 with your other phone. (Install the Microsoft Authenticator app on your phone).
- After you have completed the phase 1, the app will wait for a QR code.
- Use your browser to go to the web address https://aka.ms/mfasetup
- If necessary, log in with your TUNI email address and password.
- On Security info -page click + Add a method.
- In the drop-down menu, select Authenticator app.
- The browser displays information about using the Microsoft Authenticator app.
- In your browser, click Next, and a QR code appears on screen.
- Take your phone and scan the provided QR code with the QR code reader of the Microsoft Authenticator app. If the authenticator application asks for a lock code, this is the lock code of the phone display.
- After the Microsoft Authenticator app has scanned the QR code, click Next in the browser window.
- The app will send a notification to your phone as a test.
- Select Approve.
- In your browser window, click Next.
- Then click Done.
- Your TUNI account has now been added to the Microsoft Authenticator app on your phone.
Reading the QR code does not work in the application. What do I do?
If you cannot read the QR code in the application, you can link your account and authentication manually.
- Open the following address in your computer browser https://aka.ms/mfasetup
- When necessary, sign in by using your TUNI email and password.
- On Security info -page click the + Add a method button.
- Choose the Authenticator app from the drop-down menu.
- Next, the browser introduces you to using Microsoft Authenticator.
- Move forward in the browser by clicking Next in the place where the QR code will appear.
- Click the link below the QR code: Can’t scan image?
- The code and URL provided in the Microsoft Authenticator app will appear on the page.
- Leave the browser open, pick up the phone, and open the Microsoft Authenticator application.
- Press the plus button (add account) in the top bar of the application.
- Select Work or school account and the QR code reader will open.
- Below the reader you will see the link Or enter code manually, press the link.
- The application will ask for the connection code as well as the website address.
- Check the required information in the browser, add it to the required text fields in the application and press the Finish button in the application.
- Click the Next button in the computer browser.
- You will receive a test authentication request on your phone.
- Click Approve to confirm the authentication.
- Click Next in the computer browser to move forward.
- Click the Done button in your browser.
- The connection between the TUNI account and the phone application is now complete.
Can I set up only SMS-based authentication method because I do not have a smartphone?
SMS-based authentication method is no longer sufficient, as it is vulnerable to data security attacks (e.g. phishing and network traffic capture). This is why you need to use stronger authentication. We recommend using a more secure USB security key.
See the instructions: Setting up TUNI multifactor authentication if you don't have a smartphone
How do I set up USB security key for my use if I already have SMS-based authentication?
If you already have SMS-based authentication, you can set up the USB security key using the instructions below. To get started, you will need a USB security key and a computer with a browser installed, e.g. Edge or Google Chrome. The instructions are based on the Yubikey Security Key U2F FIDO2 NFC key produced by Yubico. You can also use security keys from other manufacturers, but we do not provide support for their use.
The TUNI staff computer no longer needs to be in the TUNI-STAFF network or with TUNI VPN turned on when working remotely. It is sufficient that the machine is used from Finland. When using from Finland, your own personal device does not require eduVPN either. You only need to use a VPN connection when registering multi-factor authentication from abroad.
Read the instructions on how to get a VPN connection on your personal computer (Windows, Linux tai macOS).
- Open the address: https://aka.ms/mfasetup in your computer browser.
- Log in using your TUNI email address password.
- On the Security info page, click the + Add method button.
- Select Security key from the drop-down menu and click the Add button.
- Select USB device as the type of USB security key (access key) you own.
- You will be prompted to insert your security key into your USB port when you select next. So put the USB security key into your computer's USB port.
- Click the Next button in the Security Key notification window on your computer.
- You can close the QR code that appeared on your screen by selecting Use a different device
- In the Create a passkey window that opens, select Windows Hello or external security key
- Select Ok in the Security key setup window.
- The browser opens a new small window where you can set a PIN code for the USB road safety key. The PIN code must be at least four digits long.
- After you have set the PIN code, click the OK button.
- The USB security key light will flash. Press the flashing light.
- The browser opens a new window where you can name your security key. Once I have named your key, click the Next button.
- The USB security key is now ready to use.
How can I change the PIN code of the USB security key? Or what if I don't remember it?
To change the PIN code of the USB security key, you need a computer and your USB security key.
- Insert your USB security key into a USB port on your computer.
- On a Windows computer, click the Search icon next to the Start button.
- In the field that opens, write Sign-in options and select Sign-in options (System settings).
- Select Security Key from the menu and click Manage.
- After this, you will receive the notification "Touch your security key". Touch the security key button on the computer's USB port with your finger.
- A window opens on your computer screen from which you can change the PIN code of the security key (Security Key PIN) or reset its settings (Reset Security Key).
- If you have forgotten the PIN code of your security key, select Reset Security Key, then the settings and rights of your security key will be deleted and you can use the security key again.
How do I turn off usage data collection from the phone app?
- Open the Microsoft Authenticator application.
- Press the main menu button in the top bar.
- Click Settings.
- Deselect the slider under the Usage data heading.
What do I do if my phone breaks?
Multifactor authentication does not send authentication queries continuously, so if your phone breaks, TUNI electronic services will not be blocked immediately. It is recommended that everyone use SMS authentication as a secondary authentication method. In this case, if the phone is broken, you can transfer the SIM card from your broken phone to just any old phone that can receive text messages.
However, if this is not possible, we recommend contacting the IT Helpdesk.
I unexpectedly received a request to accept multifactor authentication, even though I'm not logging into anything. Do I still accept the request?
Glad you were careful! Do not accept the request on your phone if you receive an authentication request and you are not logging into the service yourself. The request for approval may be related to a scam where someone has phished your password. Contact the IT Helpdesk if the situation recurs.
IT Helpdesk
0294 520 500
it-helpdesk [at] tuni.fi (it-helpdesk[at]tuni[dot]fi)
helpdesk.tuni.fi