Center for Information Technologies, Faculty of Arts
How to use multi-factor authentication
Setting up multi-factor authentication (MFA) at FF MU involves three main steps:
- Download and install an app for generating one-time access codes.
- Set up multi-factor authentication for Single Sign-On.
- Set up multi-factor authentication for the MU Information System.
To set up multi-factor authentication, you will need a smartphone with the Android or iOS operating system, on which you will have an app that will generate one-time time-limited numeric codes. This phone must have the correct time set, otherwise the codes generated on it will not work.
You will also need a computer. Although a computer is not necessary, setting up with a computer and mobile phone is much more convenient.
Once you have set up multi-factor authentication, you will no longer be able to log in without entering a one-time code from the app. Therefore, whenever you log in, you must have a device with the app for generating one-time codes available.
You will need
mobile phone with Android or iOS operating system, computer
Application for generating one-time codes
-
Installing the Ente Auth application.
Android- Open Google Play on your mobile phone (Fig. 1, A).
- Select Search (Fig. 2, A) and enter Ente Auth in the search field (Fig. 2, B).
- Find and select the Ente Auth app from the results.
- Click the Install button (Fig. 3, A) and wait for the app to download and install.
- Once the installation is complete, click the Open button (Fig. 4, A) or launch the Ente Auth app from your device's home screen.
Alternatively, you can use the following link and QR code for installation:
iOS- Open the App Store on your mobile phone (Fig. 1, A).
- Select the magnifying glass icon (Fig. 2, A) and enter Ente Auth in the search field.
- Find and select the Ente Auth app from the results.
- Click the Get button (Fig. 3, A) and wait for the app to download and install.
- Once the installation is complete, click the Open button (Fig. 4, A) or launch the Ente Auth app from your device's home screen (Fig. 5, A).
Alternatively, you can use the following link and QR code for installation:
-
First run
- When you first launch the app, it will offer several options: New Ente User, Existing User, Use Without Backup.
- If you do not want to create an Ente account for synchronization across multiple devices and easier transfer to another device, select Use without backup (Fig. 5, A).
- Read and confirm the subsequent warning that appears on the screen (Fig. 6, A).
Settings for Single Sign-On
-
Sign up for Single Sign-On multi-factor authentication management.
- Open the page mfa.id.muni.cz in your web browser on your computer.
- If you are not yet logged in, enter your UČO and primary password in the Single Sign-On login form.
- If you are prompted to confirm your identity, click the Log in button (Fig. 7, A).
-
Start creating a new verification token.
- If you are logging into the system for the first time, a token addition wizard will automatically appear.
- Press the I have an authentication app button to confirm to the system that you already have an authentication app installed on your mobile phone (Fig. 8, A).
- Enter a name for the token in the name field (e.g., "My iPhone" or "Work Android") so that you can easily identify it later (Fig. 9, A).
- Click the Continue button (Fig. 9, B).
-
Connect the mobile app to the Single Sign-On system.
- Open the Ente Auth app on your mobile phone and select Scan QR code (Fig. 10, A).
- Scan the QR code displayed on your computer screen with your phone (Fig. 11, A).
- The Ente Auth app will start generating one-time codes.
-
Ověřte a potvrďte funkčnost kódů.
- Opište aktuální šestimístný kód z mobilní aplikace do pole na webové stránce (Obr. 12, A).
- Klikněte na tlačítko Ověřit token pro dokončení spárování (Obr. 12, B).
-
Uložte si záložní kódy.
- Systém zobrazí sadu jednorázových záložních kódů pro případ ztráty zařízení s autentizační aplikací. Tyto kódy si okamžitě stáhněte (Obr. 13, A), vytiskněte (Obr. 13, B) nebo uložte do správce hesel.
- Jakmile máte kódy bezpečně uloženy, potvrďte tuto akci kliknutím na tlačítko Záložní kódy mám (Obr. 13, C) pro závěrečnou aktivaci vícefaktorového ověřování.
-
Vyzkoušejte si nové přihlášení.
- Zvolte libovolnou službu, do které se přihlašujete pomocí Jednotného přihlášení (např. ELF, Microsoft365), a pokuste se přihlásit.
- Po zadání UČO a hesla se zobrazí nová stránka, kde budete vyzváni k zadání jednorázového kódu vygenerovaného vaší aplikací.
Settings for the MU Information System
-
Enable multi-factor authentication
- Log in to IS MU on your computer.
- Find the System menu and click on the Change Passwords link (Fig. 14, A).
- From the following menu, select Two-factor account verification (Fig. 15, A).
- Alternatively, use the direct link https://is.muni.cz/auth/system/dvoufaktorove-overeni.
-
Select the Verification App method
- V nastavení vícefaktorového ověřování si zobrazte všechny podporované varianty kliknutím na Další možnosti (Obr. 16, A).
- Vyberte variantu Ověřovací aplikace (TOTP) (Obr. 17, A) a svoji volbu potvrďte tlačítkem Aktivovat dvoufaktorové ověření (Obr. 17, B).
-
Add verification codes to the application
- Open the Ente Auth app on your mobile phone, tap the + button (Fig. 18, A) in the lower right corner, and select Scan QR Code (Fig. 18, B).
- Scan the QR code displayed on your computer monitor with your phone (Fig. 19 A). The app will start generating codes for IS MU.
- Enter a name for the token (e.g., "My iPhone" or "Work Android") in the name field (Fig. 19, B) so that you can easily identify it later.
- Return to your computer and enter the current six-digit code generated by your Ente Auth app in the One-time verification code field (Fig. 19, C).
- Finish the setup by clicking the Add button (Fig. 19, D).
-
Try out the new login to the Information System.
- Now log out of IS and try logging in again.
- After entering your UČA and primary password, you will be prompted to enter a one-time code (Fig. 20, A).
Congratulations!
You have successfully set up multi-factor authentication for Single Sign-On and the Information System.