<?xml version="1.0" encoding="utf-8"?><!DOCTYPE article  PUBLIC '-//OASIS//DTD DocBook XML V4.4//EN'  'http://www.docbook.org/xml/4.4/docbookx.dtd'><article><articleinfo><title>MFA/Microsoft_Authentication</title><revhistory><revision><revnumber>25</revnumber><date>2025-10-03 08:58:01</date><authorinitials>crose</authorinitials></revision><revision><revnumber>24</revnumber><date>2025-10-03 08:57:11</date><authorinitials>crose</authorinitials></revision><revision><revnumber>23</revnumber><date>2025-07-03 06:31:14</date><authorinitials>crose</authorinitials></revision><revision><revnumber>22</revnumber><date>2025-03-30 08:37:34</date><authorinitials>crose</authorinitials></revision><revision><revnumber>21</revnumber><date>2025-03-30 08:29:08</date><authorinitials>crose</authorinitials></revision><revision><revnumber>20</revnumber><date>2025-03-29 21:48:55</date><authorinitials>crose</authorinitials></revision><revision><revnumber>19</revnumber><date>2025-03-29 21:47:26</date><authorinitials>crose</authorinitials></revision><revision><revnumber>18</revnumber><date>2024-03-26 08:03:47</date><authorinitials>kputyr</authorinitials><revremark>Grouping related guides</revremark></revision><revision><revnumber>17</revnumber><date>2023-03-29 12:10:04</date><authorinitials>crose</authorinitials></revision><revision><revnumber>16</revnumber><date>2023-03-29 12:08:07</date><authorinitials>crose</authorinitials></revision><revision><revnumber>15</revnumber><date>2023-03-29 12:07:29</date><authorinitials>crose</authorinitials></revision><revision><revnumber>14</revnumber><date>2023-03-29 11:34:29</date><authorinitials>crose</authorinitials></revision><revision><revnumber>13</revnumber><date>2022-10-14 18:47:43</date><authorinitials>crose</authorinitials></revision><revision><revnumber>12</revnumber><date>2022-10-14 18:45:01</date><authorinitials>crose</authorinitials></revision><revision><revnumber>11</revnumber><date>2022-10-14 18:36:30</date><authorinitials>crose</authorinitials></revision><revision><revnumber>10</revnumber><date>2022-10-14 18:34:28</date><authorinitials>crose</authorinitials></revision><revision><revnumber>9</revnumber><date>2022-10-14 18:33:49</date><authorinitials>crose</authorinitials></revision><revision><revnumber>8</revnumber><date>2022-02-10 19:32:45</date><authorinitials>crose</authorinitials></revision><revision><revnumber>7</revnumber><date>2022-02-07 08:11:31</date><authorinitials>levmei</authorinitials></revision><revision><revnumber>6</revnumber><date>2022-02-07 08:04:51</date><authorinitials>levmei</authorinitials></revision><revision><revnumber>5</revnumber><date>2022-02-07 08:03:52</date><authorinitials>levmei</authorinitials></revision><revision><revnumber>4</revnumber><date>2022-02-07 07:44:15</date><authorinitials>levmei</authorinitials></revision><revision><revnumber>3</revnumber><date>2022-02-07 07:43:32</date><authorinitials>levmei</authorinitials></revision><revision><revnumber>2</revnumber><date>2022-02-07 07:42:52</date><authorinitials>levmei</authorinitials></revision><revision><revnumber>1</revnumber><date>2022-02-07 07:40:31</date><authorinitials>levmei</authorinitials></revision></revhistory></articleinfo><section><title>Microsoft Authentication</title><itemizedlist><listitem><para>Manage sign in options: <ulink url="https://mysignins.microsoft.com/security-info"/> </para></listitem></itemizedlist><para><inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=mfa-second.png"/></imageobject><textobject><phrase>mfa-second.png</phrase></textobject></inlinemediaobject> </para><itemizedlist><listitem><para>MFA (Multi Factor Authentification) can be configured in different ways:  </para><itemizedlist><listitem><para>a) Authenticator App, like <ulink url="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication/public/keepassx#">KeePassXC</ulink>, MS-Authenticator, Google Authenticator </para></listitem><listitem><para>b) SMS on Mobile Phone,  </para></listitem><listitem><para>c) voice computer to classical phone </para></listitem></itemizedlist></listitem><listitem><para>The default way is to use the Microsoft Authenticator App. </para><itemizedlist><listitem><para>But: After choosing 'Microsoft Authenticator App', also an alternative app can be selected (see below). </para></listitem><listitem><para>Disadvantage of Microsoft Authenticator App: it binds to one device. An app registered Office365 account can only be unlocked with the specific device (or by phone call/SMS) - what is if your phone is broken and App and phone is on the same device? </para></listitem></itemizedlist></listitem><listitem><para>To use a different method of Authentication, you can choose 'I want to set up a different method' when setting up your Microsoft Account. </para><itemizedlist><listitem override="none"><para><inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=different_method.png"/></imageobject><textobject><phrase>different_method.png</phrase></textobject></inlinemediaobject> </para></listitem></itemizedlist></listitem><listitem><para>If you choose 'Phone', enter your mobile or office phone number or private phone number. </para><itemizedlist><listitem override="none"><para><inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=method_phone.png"/></imageobject><textobject><phrase>method_phone.png</phrase></textobject></inlinemediaobject> </para></listitem></itemizedlist></listitem></itemizedlist><section><title>Add third party TOTP app</title><para><emphasis role="strong">Attention</emphasis>: before you change your second factor: take care that there is always one factor which works! Typically your mobile number is a reasonable fallback during the reconfiguration.  </para><para>Adding and removing factors: the system might ask again for authentication, even if you are still logged in! </para><para><inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=MS-01.png"/></imageobject><textobject><phrase>MS-01.png</phrase></textobject></inlinemediaobject> <inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=MS-02.png"/></imageobject><textobject><phrase>MS-02.png</phrase></textobject></inlinemediaobject> <inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=MS-03.png"/></imageobject><textobject><phrase>MS-03.png</phrase></textobject></inlinemediaobject> <inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=qr-secret.png"/></imageobject><textobject><phrase>qr-secret.png</phrase></textobject></inlinemediaobject> </para></section><section><title>Recommendation: Additional phone numbers</title><itemizedlist><listitem><para>You'll need this to login to outlook.com (very seldom necessary), teams.microsoft.com (teams will be more often used), zoom.us, KWF, ... </para></listitem><listitem><para>What happens if you <emphasis>forget your mobile at home, or your mobile is not working, or you are at home, ... or whatever</emphasis>. Our recommendation is to configure several additional ways: </para><itemizedlist><listitem><para><emphasis role="strong">office phone number</emphasis> (if you don't have access to your mobile phone) </para></listitem><listitem><para><emphasis role="strong">personal mobile phone number</emphasis> (if you're not in your office) </para></listitem><listitem><para>if exist: <emphasis role="strong">classical phone</emphasis> from at home (if your mobile is broken) </para></listitem></itemizedlist></listitem><listitem><para><ulink url="https://www.zi.uzh.ch/en/support/Outlook-und-Kollaboration-Office-365/setup-multifactor-authentification.html"/> </para></listitem></itemizedlist></section><section><title>Authentication method</title><itemizedlist><listitem><para>Authentication methods have fixed priorites (not changeable by user). </para></listitem><listitem><para>The highest priority has 'MS Authenticator'. If this method is configured, this is always the default. </para></listitem><listitem><para>Via &quot;Sign in another way&quot; you can choose TOTP or SMS, ... </para><itemizedlist><listitem><para>If TOTP is not offered, please go to <ulink url="https://mysignins.microsoft.com/security-info"/>, click on 'Change' and select the TOTP or phone method. </para></listitem></itemizedlist></listitem><listitem><para>To change the the default authentication method, you have to remove methods with a higher priority. E.g. the 'MS Authenticator App'. </para><itemizedlist><listitem><para>in case when you click on 'delete' and you get an error, please change via &quot;Sign-in when most...  CHANGE&quot; to TOTP or Phone. </para></listitem></itemizedlist></listitem></itemizedlist><para><inlinemediaobject><imageobject><imagedata fileref="https://wiki.math.uzh.ch/public/MFA/Microsoft_Authentication?action=AttachFile&amp;do=get&amp;target=ms-delete.png"/></imageobject><textobject><phrase>ms-delete.png</phrase></textobject></inlinemediaobject> </para></section></section><section><title>Lost Access</title><itemizedlist><listitem><para>If you lost access to your Microsoft Account, you can contact the ZI Support and ask them to reset your Accounts Authentication settings. </para></listitem><listitem><para>ZI Support Contacts: </para><itemizedlist><listitem><para>Self-Service Portal: <ulink url="https://support.uzh.ch/"/> </para></listitem><listitem><para>More Information: <ulink url="https://www.zi.uzh.ch/en/support.html"/> </para></listitem><listitem><para>And for the next time: remember to setup a second way of authentication, before you loose the first one <inlinemediaobject><imageobject><imagedata depth="16" fileref="https://wiki.math.uzh.ch/public/moin_static198/moniker/img/smile4.png" width="16"/></imageobject><textobject><phrase>;-)</phrase></textobject></inlinemediaobject> </para></listitem></itemizedlist></listitem><listitem><para>After the reset, log in to your Microsoft Account and follow the steps listed under Method to set up your Microsoft Authentication </para></listitem></itemizedlist></section></article>