MFA provides an extra layer of protection by adding an extra verification step when you log into UniSA websites and systems to make sure it’s really you.
Multi-factor authentication is a way of increasing the security of your account. When you login to a service you are providing a “factor” of authentication, usually a password. This is referred to as “something you know”, but there are other factors such as “something you have” and “something you are”. MFA adds the ability for you to use “something you have” to also help prove that you are who you say you are, in this case a mobile device that only you have.
The way it works is that when you login to certain UniSA services you will be asked to provide your regular account and password, and then you may be asked to validate the Push notification in the Okta App. This prevents a hostile party from using your account without your permission, as only you will have access to your mobile device so only you will be able to provide the code or approval.
Passwords can be stolen, guessed or hacked, and compromised user accounts have become one of the primary methods used by cyber criminals to gain access to networks and data. New technology and hacking techniques combined with the limited pool of passwords most people use for multiple accounts means information online is increasingly vulnerable.
Multi-factor authentication adds a second factor of authentication as an additional layer of security to make sure that no one else can access your account, even if they know your password. The second factor of authentication is separate and independent to the password step and never uses or sees your password.
When you attempt to access certain UniSA applications and services, you will be prompted to enter your username and password as usual (the first ‘factor'). You will then be taken to an additional MFA screen. The first time you visit one of these MFA pages, you will be asked to enroll an MFA Factor to the Okta Verify app (the second 'factor'). On subsequent visits, you will be directed to an MFA screen where you will be asked to verify against your enrolled MFA factor. This additional step is used to verify the person logging in is really you, not someone else that has stolen your credentials.
All UniSA staff and students will be required to register and use MFA to access UniSA applications and services
Please follow this guide to complete registation of YubiKey for MFA Okta - Windows
NOTE: UniSA has been notified by our service provider for multi-factor authentication, that as of Monday 17th October 2022 they will cease to service requests from the countries identified by the United States regulatory changes to their export control laws. As such any UniSA users will not be able to access UniSA’s digital environment from Cuba, Iran, North Korea, Syria, the regions of Crimea, Luhansk (LNR) or Donetsk (DNR either directly through the internet or through a VPN (virtual private network).
UniSA supports Multi-Factor Authentication using the Okta Verify mobile app only.
If you do not have a mobile phone, please contact the IT Help Desk.
NOTE: It is recommended to complete the initial MFA registration process from your computer web browser as it has a more user friendly interface, and you need to scan a QR Code with your phone during the setup.
Or for step by step instructions (including screenshots) see the How to register for Multi-factor Authentication via the Okta Verify App page.
The first thing you should do is contact the IT Help Desk and let them know. They can reset your factor to allow you to re-register a new number or in the case of a lost phone, they will disable the ability for your old phone to be available for MFA. Once you are setup with a new phone you can register it for MFA using the steps in this FAQ.
You will be prompted for MFA when connecting to UniSA applications and service while on:
Once you are logged in, you will not get prompted again until you logoff or your login times out.
NOTE: It is suggested to complete the change from SMS to the Okta Verify App from your computer web browser, due to the requirement to scan a QR Code with your phone during the setup.
Or for step-by-step instructions (including screenshots) see How to change MFA from SMS to Okta Verify App page.
| Service | Risk Factor | 
| Outlook Web Access | Reduce email account takeovers and identity abuse. (e.g. impersonation of employees) | 
| myHR | Protect personal and financial information associated with myHR stored value services | 
| F5 Big-IP Edge Client VPN | Prevent users connecting to the UniSA network and resources using your credentials. | 
| Office 365 Applications | Prevent users accessing SharePoint, MS Teams, Webmail, etc using your credentials. | 
| Appian Workflows | Prevent users connecting to Appian workflows using your credentials. | 
Other staff services that require MFA include:
CiAnywhere & finance workflows, ProMaster, ExpenseMe, AssetBank, myOSH, AskLibrary, AskPTC, AskCampus Central, AskOnline, Career Hub, SkillsForge, InPlace, Marketing Cloud, Service Cloud, Genesys PureCloud, StudyLink, TimeTrade.
| Service | Risk Factor | 
| Office365 | Protect your data data and email | 
| Learning Planner | Prevent users accessing and changing your data | 
| learnonline (Moodle) | Prevent users accessing and changing your data | 
| learnonline (UniSA Online Moodle) | Prevent users accessing and changing your data | 
| Library Catalogue | Prevent users using your credential to access UniSA resources | 
| myCourseExperience (Student) | Prevent users accessing and changing your data | 
| Student Portal (myUniSA) | Prevent users accessing and changing your data | 
| Study Planner | Prevent users accessing and changing your data | 
| Teaching | Prevent users using your credential to access UniSA resources | 
| UniSA Student App | Prevent users using your credential to access UniSA resources | 
| Zoom | Prevent users using your credential to access UniSA resources | 
| eReserve | Prevent users using your credential to access UniSA resources | 
| Student Calendar Tool | Prevent users accessing and changing your data | 
| Gartner | Prevent users using your credential to access UniSA resources | 
| Library - LinkedIn Learning | Prevent users using your credential to access UniSA resources | 
| Panopto - AU | Prevent users using your credential to access UniSA resources | 
| PrintIQ | Prevent users using your credential to access UniSA resources | 
| SafeZone | Prevent users using your credential to access UniSA resources | 
| StudyLink | Prevent users accessing and changing your data |