MFA provides an extra layer of protection by adding an extra verification step when you log into UniSA websites and systems to make sure it’s really you.
Multi-factor authentication is a way of increasing the security of your account. When you login to a service you are providing a “factor” of authentication, usually a password. This is referred to as “something you know”, but there are other factors such as “something you have” and “something you are”. MFA adds the ability for you to use “something you have” to also help prove that you are who you say you are, in this case a mobile device that only you have.
The way it works is that when you login to certain UniSA services you will be asked to provide your regular account and password, and then you may be asked for a code or to approve a notification that will be sent to your mobile device. This prevents a hostile party from using your account without your permission, as only you will have access to your mobile device so only you will be able to provide the code or approval.
Passwords can be stolen, guessed or hacked, and compromised user accounts have become one of the primary methods used by cyber criminals to gain access to networks and data. New technology and hacking techniques combined with the limited pool of passwords most people use for multiple accounts means information online is increasingly vulnerable.
Multi-factor authentication adds a second factor of authentication as an additional layer of security to make sure that no one else can access your account, even if they know your password. The second factor of authentication is separate and independent to the password step and never uses or sees your password.
When you attempt to access certain UniSA applications and services, you will be prompted to enter your username and password as usual (the first ‘factor'). You will then be taken to an additional MFA screen. The first time you visit one of these MFA pages, you will be asked to enroll an MFA factor, either SMS or a mobile application (the second 'factor'). On subsequent visits, you will be directed to an MFA screen where you will be asked to submit a code or approval sent to your enrolled MFA factor. This additional step is used to verify the person logging in is really you, not someone else that has stolen your credentials.
All UniSA staff and students will be required to register and use MFA to access UniSA applications and services
Your mobile device number is securely stored with UniSA’s provider and is only used for the purpose of your account security.
NOTE: UniSA has been notified by our service provider for multi-factor authentication, that as of Monday 17th October 2022 they will cease to service requests from the countries identified by the United States regulatory changes to their export control laws. As such any UniSA users will not be able to access UniSA’s digital environment from Cuba, Iran, North Korea, Syria, the regions of Crimea, Luhansk (LNR) or Donetsk (DNR either directly through the internet or through a VPN (virtual private network).
UniSA supports Multi-Factor Authentication using the Okta Verify mobile application and SMS messages.
Note: SMS text messages do require cellular access
If you do not have a mobile phone, please contact the IT Help Desk.
NOTE: While you can register your device using any MFA-enabled application, we recommend performing the initial setup via the Okta portal using a PC/Mac web browser as this has the most user-friendly interface
Or for step by step instructions (including screenshots) see the How to register for Multi-factor Authentication via the Okta Verify App page.
NOTE: While you can register your device using any MFA-enabled application, we recommend performing the initial setup via the Okta portal using a PC/Mac web browser as this has the most user-friendly interface
Or for step by step instructions (including screenshots) see the How to register for Multi-factor Authentication via SMS Code page.
If you have previously enrolled in MFA via the Okta Verify App or SMS, follow the instructions below to enroll in an additional MFA factor
PLEASE NOTE: If you select the option to enroll a factor you have already enrolled, you will receive a '403 Access Forbidden' error.
If you cannot log in using the previously configured MFA factors, please contact the IT Help Desk.
The first thing you should do is contact the IT Help Desk and let them know. They can reset your factor to allow you to re-register a new number or in the case of a lost phone, they will disable the ability for your old phone to be available for MFA. Once you are setup with a new phone you can register it for MFA using the steps in this FAQ.
Or for step-by-step instructions (including screenshots) see Sign-In with MFA page.
You will be prompted for MFA when connecting to UniSA applications and service while on:
Once you are logged in, you will not get prompted again until you logoff or your login times out.
Or for step-by-step instructions (including screenshots) see How can I remove Okta verify app OR SMS authentication page.
Service |
Risk Factor |
Outlook Web Access |
Reduce email account takeovers and identity abuse. (e.g. impersonation of employees) |
myHR |
Protect personal and financial information associated with myHR stored value services |
F5 Big-IP Edge Client VPN |
Prevent users connecting to the UniSA network and resources using your credentials. |
Office 365 Applications |
Prevent users accessing SharePoint, MS Teams, Webmail, etc using your credentials. |
Appian Workflows |
Prevent users connecting to Appian workflows using your credentials. |
Other staff services that require MFA include:
CiAnywhere & finance workflows, ProMaster, ExpenseMe, AssetBank, myOSH, AskLibrary, AskPTC, AskCampus Central, AskOnline, Career Hub, SkillsForge, InPlace, Marketing Cloud, Service Cloud, Genesys PureCloud, StudyLink, TimeTrade.
Service |
Risk Factor |
Office365 | Protect your data data and email |
Learning Planner | Prevent users accessing and changing your data |
learnonline (Moodle) | Prevent users accessing and changing your data |
learnonline (UniSA Online Moodle) | Prevent users accessing and changing your data |
Library Catalogue | Prevent users using your credential to access UniSA resources |
myCourseExperience (Student) | Prevent users accessing and changing your data |
Student Portal (myUniSA) | Prevent users accessing and changing your data |
Study Planner | Prevent users accessing and changing your data |
Teaching | Prevent users using your credential to access UniSA resources |
UniSA Student App | Prevent users using your credential to access UniSA resources |
Zoom | Prevent users using your credential to access UniSA resources |
eReserve | Prevent users using your credential to access UniSA resources |
Student Calendar Tool | Prevent users accessing and changing your data |
Gartner | Prevent users using your credential to access UniSA resources |
Library - LinkedIn Learning | Prevent users using your credential to access UniSA resources |
Panopto - AU | Prevent users using your credential to access UniSA resources |
PrintIQ | Prevent users using your credential to access UniSA resources |
SafeZone | Prevent users using your credential to access UniSA resources |
StudyLink | Prevent users accessing and changing your data |