MFA is currently the single most important security measure for ensuring that the right person is signing in. Here you can find answers to frequently asked questions about MFA.
Implementing MFA and connecting it to your personal KTH account is part of the security requirement and a necessary security measure to protect the information that KTH handles. Several other universities are already using MFA and KTH is now joining them.
Yes, you do.
MFA will be mandatory for all students from 1 September 2026. If you have not enabled MFA, you will not be able to sign in to services such as Canvas, view your timetable, or complete digital examinations.
MFA is currently the single most important security measure for ensuring that the right person is signing in—that the individual attempting to access an account is genuinely who they claim to be. By requiring an additional verification step alongside your password, MFA significantly reduces the risk of unauthorised access, even if a password has been compromised.
An iPhone 11 or later model with iOS 17 or a newer version installed.
An Android phone with Android OS 8 or a newer version installed.
Information about the model and version can be found under Settings on the mobile phone.
We are aware that sometimes problems can occur if you are already using the app with another account.
It is important that you follow step 2 correctly in the quick reference quide on page the
Enable multifactor authentication (MFA)
, and thus open aka.ms/mfasetup in a private window or incognito mode.
Tick one or more mobile phones that you wish to remove MFA from and click “Remove selected”.
Approve with your Mobile BankID to confirm that MFA should be removed from the selected device
Yes, it is possible to connect multiple mobile phones to MFA at the same time.
You can use a work- or a personal mobile phone, or both at the same time. To connect a new phone to MFA, you need to approve it using a mobile phone that is already connected to MFA.
In Step 2:Sign in with your KTH account, approve the sign-in using the phone where MFA is already activated. You will also need to approve adding another device using the phone where MFA is already activated.
The actions you need to take depend on whether you still have access to your previous mobile phone with MFA or not.
You still have access to your previous mobile phone
If MFA is activated on your previous mobile phone, you need to add MFA to your new mobile phone before deleting or resetting the old one.
Follow the instructions for Step 1 on the page
Activate Multi-Factor Authentication
and then step 2: Sign in with your KTH account on your computer, approve the sign-in using your old phone where MFA is already activated.
You no longer have access to your previous mobile phone
If you do not have access to your old mobile phone with MFA, you can still remove MFA from it using Mobile BankID.
Follow the instructions under the heading “How do I remove a mobile phone linked to MFA?” onthis page.
You do not have Mobile BankID
If you do not have access to Mobile BankID and cannot sign in with MFA, you need to
contact IT Support
for assistance.
In addition to your username and password, you need to use Multi-Factor Authentication (MFA) to access the central sign-in service. This is used when signing in to services such as Canvas, viewing your timetable, and completing digital examinations.
You need to sign in with MFA for each browser and device. If you close the browser window or remain inactive for an extended period of time, you will need to authenticate again with MFA the next time you log in. If you are already signed in to KTH.se you only need to refresh the web page—you do not need to sign in with MFA again.
Wait for about 2-3 minutes and then try again.
Do not refresh your browser window in the meantime, it will not help.