Multi-Factor-Authenticator (MFA)

With your Unibas account, you can access the University of Basel’s network and applications around the clock. Because this involves processing data that requires a higher level of protection, multi-factor-authentication, MFA (two-step login) is enabledfor all user accounts. In addition to your password, you’ll need a second factor.

No text messages or phone calls

SMS and phone calls are considered insecure methods. Microsoft is phasing out both methods. As of September 1, 2026, they can no longer be registered as a second factor, and they will be phased out starting in January 2027. The phase-out will occur on a rolling basis; we cannot provide a specific date for individual accounts.

If you’re still using text messages or phone calls today, set up a different method now. Don’t wait until Microsoft leaves you with no other option - that will certainly be an inconvenient moment.

Secure Methods for a Second Factor

For the second factor, you have three options:

  1. A software token on a mobile device, free of charge
  2. A software token on a laptop or desktop computer, free of charge
  3. Hardware token in the form of a hardware token card, expenses: CHF 20.-

NOTE: The laptop option (Option 2) works on Windows, macOS, and Linux and requires neither a cell phone nor a token card. This means you can use the second factor even without a mobile device.


The Three Types of Second Factor

All three types generate a six-digit one-time code that changes every 30 seconds. Technically, this method is called TOTP, or time-based one-time password. The only difference between them is where the code is generated.

A note on the terminology: A software token is no less secure than a hardware token because both use the same method. The difference lies in where the secret key is stored and how well it is protected there. For this reason, please protect the software token on your laptop or desktop using biometrics or a password.

1. Software token on a mobile device

An authenticator app on a smartphone or tablet generates the code. This option also offers push notifications: You confirm the application by entering a two-digit number displayed on the screen of your mobile device. Push notifications are the fastest method for everyday use, but they are only available with the Microsoft Authenticator app.

2. Software token on a laptop or desktop

A program on your work device generates the code, either a dedicated authenticator app or a password manager with a TOTP feature. You don’t need a second device or a card. The code is provided in the same window where you register. There are free programs available for Windows, Linux, and macOS.

3. Hardware token

A credit-card-sized card displays a code at the push of a button. It requires no software, no device, and no internet connection. This option costs CHF 20.- and can be picked up in person at the Service Desk. (Unfortunately, bank transfer, TWINT, cash, and shipping are not available.)

Overview of Apps and Tokens

The following lists show the most common products for each type. Click on a product name to open a detailed description below.

These apps run on a cell phone or tablet:

 

ProductPlatformPushexpensesProvider, Location
Microsoft Authenticator [1]iOS, AndroidYesFreeMicrosoft, USA
Proton Authenticator [1]iOS, AndroidNoFreeProton AG, Switzerland
PingID [1]iOS, AndroidNoFreePing Identity, USA
Ente AuthiOS, AndroidNoFreeEnte, USA
Google AuthenticatoriOS, AndroidNoFreeGoogle, USA
AuthyiOS, AndroidNoFreeTwilio, USA
Aegis AuthenticatorAndroidNoFreeAegis Project, Open Source
FreeOTPiOS, AndroidNoFreeRed Hat, USA
1Password, BitwardeniOS, AndroidNoSee Tab 2See Tab 2

[1] supported by IT-Services

These apps run on your device. You don't need a cell phone to use them:

 

ProductOperating SystemsexpensesProvider, Location
Proton Authenticator [1]Windows, macOS, LinuxFreeProton AG, Switzerland
KeePassXCWindows, macOS, LinuxFreeKeePassXC Project, Open Source
Ente AuthWindows, macOS, LinuxFreeEnte, USA
PasswordsmacOSFreeApple, USA
2FAGuardWindowsFree2FAGuard, Germany
BitwardenWindows, macOS, Linuxonly with a paid plan, approx. USD 20 per yearBitwarden Inc., USA
1PasswordWindows, macOS, Linuxapprox. USD 48 per yearAgileBits, Canada

The product names in the first column are links to the detailed descriptions in the «Product Details» section.

[1] supported by IT-Services

 

A credit-card-sized card that displays a code:

 

ProductexpensesPurchaseSupport
IT Services Hardware CardCHF 20In person at the Service DeskSupported by ITS

See the section «Purchase a hardware card» for all the details.

These lists are not exhaustive. There are other authenticator apps and password managers with TOTP functionality that work in the same way. You can use any product that generates time-based one-time passwords according to the TOTP standard.

IT-Services exclusively supports Microsoft Authenticator, PingID, the Proton app, and the hardware token. You may use any other products independently. If you need assistance installing them on your university device, please contact our Service Desk. The mention of a product does not constitute a recommendation by the University of Basel. Prices are based on manufacturer information, in foreign currency, and subject to change; current as of September 2026.


Two Methods on Two Devices

Register two methods on two separate devices, such as push notifications on your cell phone and a one-time code on your university laptop. That way, you’ll still be able to access your account even if one device is at home, gets lost, or needs to be reset.

Push notifications and one-time codes in the same Microsoft Authenticator app do not count as two separate methods. Since they are both on the same device, they become unusable together if the device is lost.

Product Details

Here you'll find the strengths, weaknesses, and information on data management and transferring data to a new device for each product listed in the overview:

Provider: Microsoft, based in the U.S. Available on iOS and Android. Free. Supported by IT-Services.

The only app with push notifications and number matching. You enter the two-digit number shown on the screen instead of reading six digits. This also prevents an accidental confirmation from being enough if attackers flood you with requests. It makes phishing attacks more difficult because attackers must tailor the text of the requested app to avoid being exposed by an attentive user.

The app can be locked using Face ID, Touch ID, or the device PIN. Cloud backup is available. The codes cannot be transferred to another app. It runs only on mobile devices and therefore does not solve the problem of “no cell phone.”

Provider: Proton AG, based in Switzerland. Windows, macOS, Linux, iOS, and Android. Free, open source. Supported by IT-Services.

Runs on laptops and mobile phones and fully covers the “no mobile phone” scenario. An account is not required; syncing between devices is optional via a Proton account or iCloud. The app can be locked using biometrics or a PIN; the codes can be exported and transferred to a new device.

Manages only codes, not passwords. No push notifications.

KeePassXC Project, open source with no corporate headquarters. Windows, macOS, and Linux. Free.

Passwords and codes are stored in a single file protected by a master password. Suitable for anyone who wants to keep control of their own data. KeePassXC does not include its own synchronization feature, but the database file can be stored in a synchronized folder and thus used on multiple devices. Backing up the file is mandatory; otherwise, the codes will be lost if a device fails. This version does not support push notifications.

Provider: Ente, based in the U.S. Windows, macOS, Linux, iOS, Android, and in the browser. Free, open source.

Available on all platforms; synchronization is encrypted via an account or not required for purely local use. Codes can be exported. Smaller provider; no push notifications.

Provider: Apple, based in the U.S. macOS, iOS, and iPadOS; available on Windows via iCloud for Windows. Free; included with the operating system.

Already available on Apple devices; automatically fills in the code when you register and syncs it to your other Apple devices via iCloud. Unlocks via Touch ID, Face ID, or the device passcode. The most convenient option for Apple users.

Only useful within the Apple ecosystem. No push notifications. There is no feature to export the codes.

Provider: 2FAGuard, based in Germany. Windows only. Free, open source.

Pure Windows application; unlock via Windows Hello; data remains local. Very small project, examine maintenance status before use. No push notifications.

Provider: Bitwarden Inc., based in the U.S. Available on all platforms and as a browser extension. Open source. The built-in authenticator has not been included in the free plan since January 2026; the paid plan costs approximately USD 20 per year (subject to change).

Passwords and codes are stored together and synced across all devices; users can also host the servers themselves.

The separate «Bitwarden Authenticator» app is free but is only available for iOS and Android, so it does not solve the «no cell phone» scenario.

Provider: AgileBits, based in Canada. Available on all platforms and as a browser extension. Approximately USD 48 per year (subject to change); no free plan.

Well-developed user interface; codes are filled in automatically; syncs via the cloud. No push notifications.

Provider: Ping Identity, based in the U.S. Available on iOS and Android. Free. Supported by IT-Services.

The app generates TOTP codes and can integrate third-party accounts for this purpose. It can be locked using biometrics or a PIN.

Please note: When switching to a new device, third-party accounts are not automatically transferred. You must reconnect each account individually. No push notifications for the Unibas account.

Provider: Twilio, based in the U.S. iOS and Android only. Free.

Twilio discontinued the desktop versions for Windows, macOS, and Linux in 2024. Since then, Authy has run exclusively on mobile devices. The app can be unlocked using biometrics or the device PIN. An encrypted cloud backup is available, and synchronization across multiple devices is possible. No push notifications for the Unibas account.

Three lightweight apps for mobile devices, all free.

Aegis Authenticator runs only on Android, is open source, and stores the codes in an encrypted vault with an encrypted backup file. FreeOTP by Red Hat runs on iOS and Android, is open source, and doesn’t require an account. We don’t know if codes can be exported from FreeOTP; we haven’t examined it. Google Authenticator runs on iOS and Android and optionally syncs codes via a Google account.

None of these apps offer push notifications, and none run on a laptop.


How to Set Up Two-Factor Authentication

The process is the same for all options: You register in the Microsoft portal, add a sign-in method, and link it to your program or app.

  1. Select a product for your operating system from the list and install it on your university laptop. If you need assistance, contact our Service Desk (support-its@unibas.ch or +41 61 207 14 11.
  2. Open a private browser window and go to aka.ms/mfasetup. Register with your Unibas email address and password.
  3. Select «Add Login Method» and then choose the Authenticator app. Specify that you’d like to use a different app.
  4. You’ll receive a QR code. A program on your laptop cannot scan the code from its own screen. Therefore, select the option to display the key as text and enter it into your program.
  5. Enter the six-digit code displayed to confirm.
  6. Done

You can find detailed instructions with pictures in the quick guides and step-by-step guides; see the link box below.


Purchase a hardware card

The hardware card is the solution for anyone who doesn't want to use a device to register. It's an option, not a requirement.

Recommendation: Please submit a ticket in advance to support-its@unibas.ch to notify us of your visit . This allows us to prepare your card registration in advance, minimizing your wait time at the Service Desk. Without prior notice, registration will take place on-site and will take longer.

  • Pick up your card in person at the Service Desk, Spitalstrasse 41, 3rd floor, Monday through Friday from 8 a.m. to 12 p.m. and 1 p.m. to 5 p.m.
  • Expenses: CHF 20.-; payment must be made on-site and exclusively by credit or debit card. Cash, invoices, and bank transfers are not accepted
  • Shipping is not available, not even to a private address or a research location
  • A third party may pick up the card for you. This requires prior notification via a support ticket and a power of attorney
  • If the card is lost or defective, a replacement fee of CHF 20.- will apply

There is no central budget for these cards, so users must cover the expenses themselves. You may submit the amount as an expense to your supervisor or to the management of your unit. There is no official policy regarding this, and we cannot guarantee that the expenses will be reimbursed.


Changing Devices, Lost or Forgotten

You're switching devices but still have access to your old one.
Open a private browser window, go to https://aka.ms/mfasetup, and register. Confirm the application on your old device. Then remove the old method by clicking «Delete» and add the new device by clicking «Add sign-in method».

If the old device doesn't have an internet connection, you won't need a push notification. On the sign-in screen, click «I can't use my Microsoft Authenticator app right now» and then «Use a verification code». The app will display the six-digit verification code even without an internet connection.

You’ve forgotten your device.
Use your secondary method. That’s exactly what it’s for. If you haven’t registered a secondary method, contact the Service Desk.

You no longer have access to your device.
If the device is lost, broken, or has been reset, and you haven’t registered a second method, you cannot change it on your own. The Service Desk will reset your registered MFA methods after verifying your identity. You can do this either by telephone at +41 61 207 14 11, please have your UNIcard ready, or via video call; during the call, you must present a valid form of identification (e.g., ID card, national ID, or passport).


Frequently Asked Questions

Yes. A cell phone is not required. The one-time code is generated either for free using a program on your university laptop or on a hardware card for CHF 20.-

No. We do not require you to use a personal device. Use the one-time code on the university laptop or a hardware card.

No. Using your university laptop is free, as is the Microsoft Authenticator app. You’ll only incur expenses if you choose the hardware card. For information on the CHF 20.- and the option to submit it as an expense, see the section «Purchase a hardware card».

No. Pickup and payment are only available on-site at the Service Desk, exclusively by credit or debit card. We do not offer shipping, not even to a private address or a research facility. We cannot provide invoices or accept bank transfers.

Yes. The «Passwords» app is already available on macOS, iOS, and iPadOS; it can generate verification codes, automatically fills them in when you register, and syncs them to your other Apple devices via iCloud. During setup, go to https://aka.ms/mfasetup, select the Authenticator app, and choose to display the key as text, which you’ll then enter into the app. The Service Desk does not provide support for this process.

We do not currently offer passkeys based on the WebAuthn standard for the University of Basel user account, and a launch date has not yet been set. What you may be familiar with from SWITCH edu-ID is part of a different system with its own set of login methods. The process most similar to what you’re used to is unlocking the Microsoft Authenticator app using Face ID or Touch ID, after which you confirm the application registration via a push notification with a two-digit code.

Yes, and we strongly recommend it. Using two methods on two separate devices will save you from having to call the service desk if one device goes missing.

The library network, VPN, self-service options, and email are standalone services, each with its own session and session duration. Choosing a particular method does not change this. However, with push authentication and biometric unlocking, each confirmation takes only a few seconds.

Most likely, yes. Any product that generates time-based one-time passwords according to the TOTP standard can be connected. The lists on this page are not exhaustive.

Close the window, open a new private browsing window, and go to https://aka.ms/mfasetup again.


Security and Privacy

Why text messages and phone calls are no longer enough.
Both rely on the cellular network and can be intercepted or rerouted relatively easily—for example, through a SIM swap, vulnerabilities in the SS7 signaling network, or call forwarding set up without the user’s knowledge. With phone calls, the code can also end up in voicemail, which is often protected by only a weak PIN.

Why a one-time code offers better protection.
The secret key is transmitted once during setup and never leaves your device afterward. The code is generated locally from this key and the current time, so nothing is sent over a network during each application. That’s why the process also works offline.

What a push notification transmits.
With push notifications, your device receives a request containing the service name and the location of the application registration. You confirm with a two-digit number displayed on the application registration screen. This “number matching” prevents an accidental confirmation from being sufficient.

If you use a personal device.
No data is sent from your personal device to the university. The device is not managed, and we do not see any content on it. Only the login method itself is registered so that your application works.

If you do not want to use a personal device.
This is an option and requires no justification. Use the one-time code on your university laptop or a hardware token. Both methods do not require a personal device.

Privacy Information
You can find the privacy notice regarding the MFA procedure in the link box below.


Service Desk

IT-Services
Spitalstrasse 41, 3rd Floor
CH-4056 Basel
Phone +41 61 207 14 11
E-mail support-its@unibas.ch

To top