# MFA: I-MATH & DM3L

For Microsoft authentication, please check [here](https://wiki.math.uzh.ch/public/books/public-wiki/page/microsoft-authentication)

### Step 1 - configure MFA

<p class="callout info">Open [https://login.math.uzh.ch](https://login.math.uzh.ch)</p>


- If no MFA device is configured yet, the page asks to configure one. [![authentik-login.png](https://wiki.math.uzh.ch/public/uploads/images/gallery/2026-06/authentik-login.png)](https://wiki.math.uzh.ch/public/uploads/images/gallery/2026-06/authentik-login.png) [![authentik-configure-mfa.png](https://wiki.math.uzh.ch/public/uploads/images/gallery/2026-06/authentik-configure-mfa.png)](https://wiki.math.uzh.ch/public/uploads/images/gallery/2026-06/authentik-configure-mfa.png)
- **Setup** MFA methods
- **Recommended**: Setup a) TOTP, b) EMAIL and c) Recovery - **ALL** of them![![authentik-setup-mfa.png](https://wiki.math.uzh.ch/public/uploads/images/gallery/2026-06/authentik-setup-mfa.png)](https://wiki.math.uzh.ch/public/uploads/images/gallery/2026-06/authentik-setup-mfa.png)
- Only **one** email-base MFA can be configured and the email **can't be changed**, it uses the email assigned to the account. This is your Primary UZH Email address.
- We recommend configuring only **one** TOTP, across several devices (by copying the code to e.g. KeepassXC and scanning the QR code with MS Authenticator). 
    - Althgouth several TOTPs can be configured (like in the screenshot) and any code is accepted currently.

<table id="bkmrk-type-use-pro-contra-" style="border-collapse: collapse; width: 100%;"><colgroup><col style="width: 15.4946%;"></col><col style="width: 19.6663%;"></col><col style="width: 32.8993%;"></col><col style="width: 31.9398%;"></col></colgroup><tbody><tr><td>**Type**</td><td>**Use**</td><td>**Pro**</td><td>**Contra**</td></tr><tr><td>TOTP</td><td>Best for daily use</td><td>Possible configuration on multiple devices - **no single device dependency**.</td><td>TOTP App necessary.</td></tr><tr><td>Email</td><td>If TOTP is not available</td><td>Email is often already configured on mobile and laptop.</td><td>Email access necessary.</td></tr><tr><td>Recovery Codes</td><td>Emergency</td><td>Stupid simple.</td><td>Codes are quickly exhausted, the last has to be reservered to get new codes.</td></tr></tbody></table>

### Optional Step 2 - configure TOTP App

- [TOTP App overview and setup](https://wiki.math.uzh.ch/public/books/public-wiki/page/totp-app)
- Recommendation: [KeepassX](https://wiki.math.uzh.ch/public/books/public-wiki/page/keepassxc)

### Problems

#### I cannot configure email codes

Please contact us on support@math.uzh.ch . Possible causes:

1. There is another account this with email configured as a second factor. This usually happens to secondary accounts only.
2. You have already started to configure the email, but the address has not been verified. Your MFA configuration must be cleaned.

#### I have lost access to my device and cannot sign in anymore

Please contact us - we will generate a short-living one-time URL to let you access your account and reconfigure MFA.

#### I'm stuck at "Something went wrong! Please try again later."

This usually happens when you try to configure an email-based MFA for an email that is already in use. You have to delete cookies in your browser that are associated with the domain login.math.uzh.ch, then try to use another method as a second factor.

### MFA Services at I-MATH &amp; DM3L via login.math.uzh.ch

- Thinlinc - [https://tl.math.uzh.ch](https://tl.math.uzh.ch)
- Wiki - [https://wiki.math.uzh.ch](https://wiki.math.uzh.ch)
- Hello - [https://hello.math.uzh.ch](https://hello.math.uzh.ch)
- SSH - ssh.math.uzh.ch
- More services will follow (GIT, Nextcloud, R-Studio,...) to use the central MFA login.