Principle & Context
What is it about?⚓
Two-factor authentication (A2F or 2FA) is a form of multi-factor authentication (MFA) that relies on the use of at least 2 factors or secrets and not just a single one, the password. Learn more on Wikipedia.
At Unistra, it is most often combined with central authentication (CAS). In this way, the first factor is simply the knowledge of your Unistra password, via a classic authentication on CAS. The second factor can then be defined by choice among several methods based on the knowledge of another secret or the possession of another device.
Note :
For certain applications that do not rely on authentication via CAS, two-factor authentication is managed differently: these situations are not covered in this guide.
Who is concerned and when?⚓
Staff⚓
From mid-July 2026, every staff member can configure and use a second factor to secure access to a set of digital services.
From October 1st, two-factor authentication will be mandatory for all staff and on most digital services.
Extra : Progressive implementation⚓
Early 2026, people with privileged rights[1] in certain digital applications of the institution were progressively contacted and informed of the implementation modalities concerning them.
For each application, the implementation is carried out in two phases :
The 2FA will be available for the targeted application: any concerned person will be able to configure and use a second factor for access to this application.
💡 If this person already uses a second factor for another CAS-based application, the same factor will be requested from the start and in the same way on the new targeted application.
A few weeks later, the 2FA will be mandatory for this application: any concerned person must use a second factor for access to this application.
Students⚓
From mid-July 2026, every student can configure and use a second factor to secure access to a set of digital services.
Extra : Progressive implementation⚓
For members of the student community concerned, the implementation concerns all digital services of the institution that rely on CAS authentication.
It will be enough to activate one or several other authentication methods. When at least one method is activated, a second factor is required to authenticate you on the university's digital services.
If desired, you can at any time deactivate all your methods to revert to simple authentication.
Warning :
Note: This measure must in no case imply a reduction in vigilance in protecting your Unistra account! Having a second factor does not exempt you from taking care of your primary password.
Legal :
The list of services or applications for which 2FA must be used has been validated by the Strategy and Digital Projects Committee (CSPN). It is a decision taken by the institution.
How to proceed?⚓
To use two-factor authentication, it is necessary to choose the types of factors you wish to use and then to activate the “methods” beforehand. Once a method is activated, you can use it daily. If needed, you can at any time modify or revoke an activated method.
Tip : Do you want in‑person support?⚓
We invite you to come ask your questions or activate your second factor during our office hours (free access, no registration) :
📅 Monday 21 September 2026, between 2 p.m. and 5 p.m.
& 📅 Tuesday 22 September 2026, between 9 a.m. and 5 p.m. (non‑stop) :
- At the Atrium, in the digital spot on the ground floor.
- At the University Palace, in the Aula.
📅 Thursday 24 September 2026, between 9 a.m. and 12 p.m. :
- At the Atrium, in the digital spot on the ground floor.
- At the University Palace, in the Fustel room.
Cronenbourg campus staff, office hours are also organized by your local IT staff :
🗓 Friday 25 September 2026, between 9 a.m. and 12 p.m.
🗓 Tuesday 29 September 2026, between 9 a.m. and 12 p.m.
Both days, in Werner room, at the ECPM (building 100). Signage will be set up to guide you.
For on‑site activation, bring your device (laptop, mobile, ...).