Info |
---|
This information is available in German and English. 🇦🇹 Deutsche Version | 🇬🇧 English Version |
Anker | ||||
---|---|---|---|---|
|
Für alle Mitarbeitende Alle Mitarbeitenden der WU wird verwenden die Zwei-Faktor-Authentifizierung (2FA) eingeführt, um unsere Accounts und Daten besser zu schützen. Wir geben Antworten zu den wichtigsten Fragen in Bezug auf die Funktionsweise und den Nutzen der 2FA.
Anker | ||||
---|---|---|---|---|
|
Panel | ||
---|---|---|
| ||
Two-factor authentication (2FA) |
Two-factor authentication (2FA) is being introduced for all WU employees used by all faculty and staff at WU to improve the protection of our accounts and data. We provide answers to the most important questions regarding the functionality and benefits of 2FA.
What is two-factor authentication and why is it required?
Two-factor authentication (2FA) is a protection mechanism to prevent account abuse and mitigate the consequences of password theft.
Account abuse can have serious consequences for WU and its members: Once attackers have gained access to a WU account, they try to advance piece by piece into the heart of our network. Ransom demands in connection with data outflows, long-lasting outages and restrictions of the IT infrastructure are the worst-case scenarios. However, password thefts often go unnoticed if the attackers are clever. This gives attackers time, and the more time that passes, the greater the damage can be.
How does two-factor authentication work?
The protection of an account often depends solely on a password. However, passwords can easily be stolen or cracked. In 2FA, the protection of an account is divided into two factors (password + numeric code): The first factor is the information that only the authorized person alone is allowed to know (e.g. account password), and the second factor is information that only the authorized person alone is allowed to possess (e.g. time-limited numeric code, one-time valid TANs, biometric features ...).
At WU, the first factor is the account password and the second factor is a six-digit numeric code that is valid for a limited time. Both factors are required together to successfully authenticate. After entering the account password, the second factor is entered, which is either obtained from an "authenticator app" or received via SMS. Without the second factor, the login fails. As a result, the entire protection no longer depends on the password alone.
What is the second factor and how do I get it?
The second factor is a six-digit numeric code, also called "Time-based One-Time Password" (abbreviated: TOTPor OTP). This is a password that is intended for one-time use and is only valid for a short period. The TOTP can either be obtained from an "Authenticator App" or received via SMS.
There are different Authenticator apps, but they all calculate the TOTP in the same way locally on the device and according to internationally recognized cryptographic standards.
The second factor is therefore not transmitted compared to the SMS alternative. (The apps also do not require an Internet or a mobile connection.) There are attack scenarios in which attempts are made to intercept the TOTP on this transmission path. Therefore, the option with the Authenticator app is to be preferred from a security perspective.
When do I submit the second factor?
WU applications and online services automatically prompt you to enter a second factor when needed. To enter your six-digit OTP, you may be presented with one of two prompt screens (see screenshots below)
WU Central Login Page or
WU Page for Cloud Services (e.g. authentification using Azure AD)
You will see this page if - in simplified terms - you enter your WU email address as the username for a (web)application offered by WU. This login is typically associated with your Microsoft business account (i.e. work- and school account) that you already use for MS Teams.
OTP queries
Your six-digit one-time password will be requested either through the WU Central Login Page or through the WU page for Cloud Services.
Authenticator App: Which one shall I choose?
All Authenticator apps work in the same way and calculate the time-based one-time password according to the same industry standard. Every employee is free to choose the app for the second factor. Theinstructions for two-factor authentication includes a description of two common Authenticator apps:PrivacyIDEA Authenticator is an app from NetKnights GmbH and is considered a privacy- and user-friendly open source variant.
Microsoft Authenticator is a widely used authenticator app from Microsoft and is also considered very user-friendly.
How do I set up two-factor authentication?
Login and setup of the two-factor authentication is done via the Controlpanel in the menu "Two-factor authentication". Theinstructions for two-factor authentication will support you in this process. From this point on, you will always need a second factor when logging in for the control panel and VPN. IT-SERVICES will be very happy to assist you with the setup and answer any further questions you may have during Q&A sessions. Please note the announcements in the "General" channel of our "Help Community".Do I have to disclose my private cell phone number?
The private cell phone number with the area code +43 is only required if you choose the option with the private cell phone and the SMS to the private phone number. However, we recommend using an Authenticator app because 1) it is preferable from a security perspective and 2) no phone number is required. Read more in the section "What is the second factor and how do I get it?".
What happens if I do not set up two-factor authentication?
If two-factor authentication is not set up within the scheduled deadline, the affected WU account will be deactivated for security reasons. After that, access to any WU services will no longer be possible.
What happens when my cell phone number changes?
If you choose the SMS option instead of the Authenticator app, you must register a mobile phone number in the control panel. If your phone number changes, you can change the specified phone number in the Controlpanel in advance. For details, please refer to the instructions for two-factor authentication.
What happens when I receive a new cell phone?
Option with SMS
Option with Authenticator App
The Cell phone number remains the same
no change
1) Creation of a new token in the Controlpanel.
2) Set up the 2FA according to the instructions on the new device
3) Deletion of the old token
The Cell phone number changes
cf. "What happens when my phone number changes?"
What happens if I forget my cell phone, lose it, or if it gets stolen?
The idea of two-factor authentication as a protection mechanism is that your cell phone is far more difficult to steal than your password. Therefore, you necessarily need the cell phone with you as a medium for your second factor to authenticate successfully. If your cell phone is not with you, you are not able to log in.
If you have lost your cell phone, you must either come to the IT Support Center in person or send proof of identity (photo ID) to hotline@wu.ac.at. If you have lost your employee cell phone, please follow the steps after losing an employee cell phone.
I have entered my password, but the second factor via SMS is not there right away. What do I do now?
It may happen rarely, but nevertheless, that the SMS transmission has slight delays. In such a case, please wait for a short moment. The SMS will be delivered to you with a time delay of a few minutes.