meta data for this page
  •  

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
overview:new [2025/11/24 12:13] hkunzoverview:new [2025/11/29 15:46] (current) – [1st step: Setup your IfI account credentials] hkunz
Line 10: Line 10:
 **Password Authentication:** On account creation, we sent you an **initial password** and/or a **link to reset your password** – together with instructions on how to set a password. Please act accordingly and you are set and ready to continue. **Password Authentication:** On account creation, we sent you an **initial password** and/or a **link to reset your password** – together with instructions on how to set a password. Please act accordingly and you are set and ready to continue.
  
-Important: please also read more on [[:account:passwords|passwords]], [[:account:phishing|phishing and malware]] (note that you need to login to access these pages, a perfect way to test if your IfI credentials work), plus the [[https://www.zi.uzh.ch/en/staff/it-security/guidelines-and-security-rules.html|Guidelines and Security Rules]] (UZH).+Important: please also read more on [[:account:passwords|passwords]], [[:account:phishing|phishing]] and [[:account:malware|malware]] (note that you need to login to access these pages, a perfect way to test if your IfI credentials work), plus the [[https://www.zi.uzh.ch/en/staff/it-security/guidelines-and-security-rules.html|Guidelines and Security Rules]] (UZH).
  
 **2-factor Authentication (2FA): **2FA makes the process of identifying user (authentication) more secure, by requiring a 2nd factor in addition to the password. If one factor (usually the password) becomes known, due to fishing or a data leak for example, the 2nd factor is still necessary to log in. This makes such attacks much harder. **2-factor Authentication (2FA): **2FA makes the process of identifying user (authentication) more secure, by requiring a 2nd factor in addition to the password. If one factor (usually the password) becomes known, due to fishing or a data leak for example, the 2nd factor is still necessary to log in. This makes such attacks much harder.
Line 16: Line 16:
 <WRAP caution>2FA is right now in the testing/migration stage. This means, that if you do not have a 2nd factor configured, you will not need to provide one when logging in. If you would like to test our 2FA, all you need to do is to setup a 2nd factor (see below).</WRAP> <WRAP caution>2FA is right now in the testing/migration stage. This means, that if you do not have a 2nd factor configured, you will not need to provide one when logging in. If you would like to test our 2FA, all you need to do is to setup a 2nd factor (see below).</WRAP>
  
-**Setup your first 2nd factor:** The 2nd factors for IfI accounts are managed in our PrivacyID3A server. To add a 2nd factordo the following steps:+**Setup your first 2nd factor:** To start, we recommend to to setup PUSH token or a TOTP token. Please check the [[:account:mfa|step by step guides]]. After that, you are ready to go. We recommend to read more on [[:account:passwords|passwords]], [[:account:phishing|phishing]] and [[:account:malware|malware]] (note that you need to login to access these pages, which is perfect way to test if your IfI credentials/2nd factors work)plus the [[https://www.zi.uzh.ch/en/staff/it-security/guidelines-and-security-rules.html|Guidelines and Security Rules]] (UZH).
  
-   Log in on the privacyIDEA server[[https://pi.ifi.uzh.ch|pi.ifi.uzh.ch]] +**2FA-enabled Services:** As noted above, we are currently in the implementation and testing stagePlease check on [[:overview:services|]] for which of our services 2FA has already been activated. NOTEas indicated aboveas of now, no 2nd factor is necessaryas long as you do not setup a token (see above).
-  - In the left-side menu click **Enroll Token**  (Tokens are the 2nd factors in the privacyIDEA terminology). +
-  - By default, a PUSH token will be installed. But you can also choose other token types, such as TOTP. \\ PUSH: this is the most seamless of the 2nd factors. You only need to confirm your login on your mobile phone. \\ TOTP: this is the most common of the 2nd factors. You will need to type a 6-digit number when logging in. \\ privacyIDEA authenticator app: for the PUSH token to work, you need to install it to your mobile phone (use the QR codes provided). \\ The TOTP token can be added to any authenticator app (Google, Microsoft, FreeOTP, etc.) \\ We recommend to use the privacyIDEA authenticator (you can add Microsoft and EduID TOTP tokens used for UZH services to the privacyIDEA authenticator too, so you have everything in one place). +
-  - Click **Enroll Token**  (bottom) ans proceed according to the instructions given (which differ for different token types). +
-  - After that, you are ready to goWe recommend to read more on [[:account:passwords|passwords]], [[:account:phishing|phishing and malware]] (note that you need to login to access these pageswhich is perfect way to test if your IfI credentials/2nd factors work)plus the [[https://www.zi.uzh.ch/en/staff/it-security/guidelines-and-security-rules.html|Guidelines and Security Rules]] (UZH).+
  
-**2FA-enabled Services:**  As noted above, we are currently in the implementation and testing stage. Please check on [[:overview:services|]] for which of our services 2FA has already been activated. NOTE: as indicated above, as of now, no 2nd factor is necessary, as long as you do not setup a token (see above). 
  
 ===== Further steps ===== ===== Further steps =====