Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) is an effective way to protect your university account and data from unauthorized access. Unlike traditional password-only sign-in, MFA requires a combination of at least two independent authentication factors. This significantly reduces the risk of account compromise caused by phishing, malware, or password leaks.
Starting from 1 November 2025, MFA is mandatory for all CTU users (students, employees, partners, and alumni). It is recommended to configure at least two authentication methods so that a backup sign-in method is always available. MFA applies to all CTU systems and also to some FIT systems that use CTU account authentication.
Setup
- Microsoft Authenticator – the recommended primary authentication method. The mobile application can be used to approve sign-ins using a verification code or to configure passwordless sign-in.
- TOTP (time-based code) – applications such as KeePassXC or Google Authenticator generate time-limited verification codes. This is an alternative to the Microsoft Authenticator mobile application.
- Windows Hello for Business – sign in without entering a traditional password using biometric authentication (such as a fingerprint or facial recognition) or a PIN.
- FIDO2 security key – authentication using a USB/NFC security key, verified by PIN or fingerprint.
Usage Scenarios
- Smartphone
- Microsoft Authenticator mobile application or any TOTP application.
- Alternatively, you can also configure:
- Linux
- TOTP application
- Alternatively, you can also configure:
- FIDO2 security key
- Himmelblau (Experimental)
- Windows
- Windows Hello for Business
- Alternatively, you can also configure:
- TOTP application
- FIDO2 security key
Known Issues
- Mozilla Thunderbird does not support signing in to a university e-mail account using a security key. Only the mobile application or TOTP can be used.
- If both TOTP and a security key are configured, the security key is always requested first and this order cannot be changed. If the user prefers a different method, they must cancel the security key authentication and select another option. Follow the instructions in TOTP Sign-In with a Registered Security Key.
Help and MFA Reset
To regain access using MFA, select Sign in another way during authentication and use your CTU password to sign in and complete the MFA reset form.