FAQs

Topics on this page:

General

1. Is UTORMFA required at U of T ?2024-02-22T16:32:12-05:00

UTORMFA is required for staff, faculty, librarians and students at U of T.

2. Will I be prompted to authenticate every time I try to log in to an application?2024-03-01T09:53:19-05:00

It depends on the profile of the application:

  • If you are connected to a U of T network (excluding Wi-Fi and VPN connections) and the application is listed as a standard profile application, you will not be prompted to authenticate with Duo and you can continue to access the application as usual.
  • If you are not connected to a U of T network and the application is listed as a standard profile  application, you will only be prompted to authenticate with Duo once every 24 hours, if you decide to trust the device that is accessing the U of T application.
  • If you are trying to access an enhanced profile application, you will be prompted to authenticate with Duo every single time that you are timed out. Additionally, if you are not enrolled in MFA, you will be denied access to the U of T application.

Please refer to the UTORMFA security profiles for more details on the application categories.

3. Which applications are protected by UTORMFA?2024-03-01T09:58:16-05:00

Refer to the UTORMFA protected applications for the list of applications.

4. Can I start the UTORMFA sign-up process and come back to it later?2024-02-20T16:30:00-05:00

No, you should set aside 10 minutes to complete the entire process at once. If you stop before completing the process, you will need to contact the help desk.

5. How do I select a device to authenticate if I have more than one device registered on my UTORMFA account?2024-02-20T16:41:03-05:00

By default, you will be prompted on the device that you used last time. If you would like to choose a different authentication method, select “Other options” as indicated in the screenshot below.

Duo application showing the screen for checking for a DUO Push.
6. How do I remember my MFA session?2024-02-20T16:43:36-05:00

When you access a UTORMFA protected service, you will be asked “Is this your device?” after responding to the push notification. If you are using your personal device, you can select “Yes, this is my device” to remember your MFA session for seven days. If you are using a public or shared computer, do not use this feature.

Duo application showing the screen for asking user to confirm whether this is their device.
7. Do I need to do anything with UTORMFA if I change my UTORid password?2024-02-20T16:44:38-05:00

No, there is no action you need to take as long as your UTORid remains the same.

8. What if my phone is not compatible with the Duo mobile app or I don’t want to use my own device?2024-02-21T10:40:45-05:00

Hardware tokens are available as an alternative to generate a passcode. Please contact the help desk to order a hardware token. You will need to get approval for the cost from your department/division.

9. How do I use a hardware token to access UTORMFA protected services?2024-02-20T16:54:45-05:00

When you access a UTORMFA protected service, choose the “Hardware token” option. Then press the button on the hardware token to generate a one-time passcode and enter it in the highlighted field.

Duo application showing the screen for logging in with other options where the Hardware token option is highlighted.
Duo application showing the screen for user to enter their passcode.
10. Can I set up a second UTORMFA device?2024-02-20T17:09:02-05:00

Yes, you can. Log in to the device management portal to add a new UTORMFA device. After you select “Add another device” follow the instructions provided in the portal.

Screenshot of the UTORMFA enrollment and device management portal with the option "Add another device" highlighted.
11. How do I recover my UTORMFA account if I get a new phone?2024-02-22T16:37:08-05:00

If you are using the same number, log in to the device management portal. From there, you will see a screen that asks you to either “Send me a push” or “Enter a passcode” to authenticate yourself. Choose one of the two options. After authenticating yourself, you can select “Device options” next to the device you want to recover.

12. How do I authenticate if I don’t have access to Wi-Fi or data?2024-02-21T10:48:48-05:00

The Duo mobile app can automatically generate a passcode if you don’t have access to Wi-Fi or data. To generate a passcode:

  • Launch the Duo app and select “University of Toronto”.
  • A code will be generated. Enter the code when you log in.
13. What should I do if I lost my device?2024-02-22T16:37:52-05:00

If the device you lost is your only device for UTORMFA, contact your campus help desk to get a bypass code. Log in to the device management portal, select “Device options” next to the device you lost and select the trash button to remove your device.

Screenshot of the UTORMFA enrollment and device management portal with the button "Device options" highlighted.

Once your lost device has been removed, select “Reactivate Duo mobile” to generate a new barcode for your UTORMFA account. On your new phone, use the Duo mobile app to scan the barcode and add your UTORMFA account to Duo.

Screenshot of the UTORMFA enrollment and device management portal with the button "Reactivate Duo Mobile" highlighted.
14. What should I do if I leave my phone at home after installing UTORMFA?2024-02-20T17:19:15-05:00

Contact the help desk for a one-time use bypass code. This code will allow you to log in to your applications.

15. How do I get help with setting up a UTORMFA account?2024-02-20T17:20:28-05:00

Please contact the help desk for assistance.

Duo mobile app

1. Can I use any third-party mobile apps to generate a Duo passcode or push prompt?2024-02-21T07:31:13-05:00

Only the Duo mobile app can be activated for use with Duo’s service. You can use the Duo app to replace other passcode generating apps for third-party accounts, but you can’t use other apps to replace Duo mobile.

2. What data does the Duo mobile app collect from my mobile phone?2024-02-21T07:31:59-05:00

For iOS and Android phones, the data collected includes smartphone model, Duo mobile app version, operating system version and screen lock type.

3. What permission(s) on my phone are required for the Duo mobile app?2024-02-22T16:39:27-05:00

Visit the Duo website for information about permissions and privacy.

4. Is my phone compatible with the Duo mobile app?2024-02-21T10:06:45-05:00

Duo is compatible with iOS and Android.

5. How do I test if my mobile app and account are set up properly?2024-02-21T07:35:51-05:00

You can test if your Duo mobile app and UTORMFA account are set up properly by logging in to the test site. If you receive a UTORMFA login prompt and access the website successfully, your UTORMFA account and mobile app are correctly set up.

6. What are the numbers that appear in the Duo mobile app?2024-02-21T07:44:29-05:00

The numbers are the one-time passcode, which can be used to access UTORMFA protected services. When you try to access a UTORMFA protected service, you can either authenticate by Duo push or a one-time passcode.

To receive a passcode, select “Duo mobile passcode” and enter the one-time passcode in the highlighted field.

Duo application showing the screen for logging in with other options where the Duo Mobile passcode option is highlighted.
Duo application showing the screen for user to enter their passcode.
7. Why does the approve/deny notification display different names at different times?2024-03-01T09:52:29-05:00

The approve/deny notification will display one of three names – Weblogin Standard, Weblogin Hybrid or Weblogin Enhanced. The name you see during authentication depends on the type of U of T application you are accessing, its profile and the criticality of its data. Refer to the UTORMFA security profiles for details on the application categories.

8. What should I do if I get spammed with push notifications?2024-02-22T09:20:18-05:00

Pause before you approve an MFA notification sent to your device. Only approve the notification if you logged in to an application that requires MFA within the last 60 seconds. Contact security.response@utoronto.ca if you are being spammed with push notifications, or use the report a phish button in Outlook.

Bypass codes

1. What is the bypass code service?2024-02-21T07:54:14-05:00

The bypass code service enables UTORMFA users to generate 10 codes that enable them to log in if their mobile device is unavailable.

2. How do I generate bypass codes?2024-02-21T07:54:01-05:00

Visit the bypass codes website to set up your codes.

3. When should I generate bypass codes?2024-02-21T11:15:53-05:00

You should generate bypass codes as soon as possible. Codes cannot be generated after a device is lost or stolen. They must be generated when your mobile device is in your possession.

4. How should I store my bypass codes?2024-02-21T07:55:18-05:00

Print out or write down your bypass codes and store them in a safe place. Don’t save your bypass codes on your computer.

Students

1. Is UTORMFA required for students?2024-02-21T08:00:26-05:00

Yes, all students are required to use UTORMFA.

2. When do I need to enrol in UTORMFA by?2024-02-22T16:44:21-05:00

Students have 14 days from the conversion of their JOINid to UTORid to sign up for UTORMFA. After this period, students will not be able to log in to any services until they have completed the UTORMFA enrolment process.

3. I don’t have a compatible mobile phone. Is there an alternative?2024-02-21T08:01:42-05:00

If you don’t have a compatible mobile phone, you can request a hardware token.

4. What do I do if my mobile phone is temporarily unavailable to authenticate into UTORMFA?2024-02-21T08:03:07-05:00

Information Security recommends that you set up your bypass codes immediately after enrolling in UTORMFA. Visit the bypass codes website to set up your codes.

These codes can be stored in your wallet to use if your mobile phone is not available. If you don’t have your bypass codes or your phone with you when you need to authenticate, please contact the help desk for assistance.

5. If I have an exam or assessment that does not allow phones, what should I do?2024-02-21T08:04:01-05:00

Bypass codes provide a simple alternative to your phone in situations where your phone is not permitted. Faculty and instructors have been informed that procedures may need to change to accommodate the need for MFA during an exam or assessment.

6. If I am an international student and studying or travelling abroad, will MFA still work on my phone?2024-02-21T08:04:37-05:00

Yes, MFA authentication will work internationally. It does not depend on your phone number.

7. How long will UTORMFA remain active after a student graduates?2024-02-21T08:05:17-05:00

UTORMFA will remain active for one session plus one month after the last registered session. At this point, the UTORMFA account will be disabled.

Last modified: June 18, 2024

Go to Top