Alternative Methods:
Windows Hello
Windows Hello is an easy way to use a passkey for multi-factor authentication. You can authenticate on a Windows computer using a PIN, fingerprint, or facial recognition.
Note! Windows Hello is device-specific. The passkey will only work on the computer on which it was set up. If you switch to a different computer, you will need to set up the Windows Hello passkey again on the new device.
If you are unable to set up a Windows Hello passkey, you can use an alternative method such as KeePass or Bitwarden.
1. On your Windows computer, search for “Sign-in options” and open the settings.
2. Select “Windows Hello PIN”. You can also choose Fingerprint or Face if supported by your device.
3. Set up your preferred Windows Hello sign-in method by following the on-screen instructions.
4. Go to the IDM page:
Enter https://idm.utu.fi in your browser’s address bar and press Enter.
5. Select “Multi-Factor Authentication (MFA) Settings.”
6. Click “Set up Passkey.”

7. Sign in using your account password.
8. Select “Register” and then choose “Windows Hello or external security key.”
9. Follow the on-screen instructions and authenticate using your selected Windows Hello method.
10. Give the passkey a descriptive name, such as “Windows Hello.”

Mac
On a Mac computer, you can use Touch ID fingerprint authentication for multi-factor authentication. You can easily confirm your sign-in using your fingerprint.
Note! Your passkey may also be available on your other Apple devices, such as an iPhone or iPad. However, you may need to set up the passkey again when using a new device.
If you are unable to set up the passkey, you can use an alternative method, such as an authenticator app.
Setting up Touch ID
If you do not already have Touch ID enabled, follow these steps to set it up:
- Open System Settings on your Mac.
- Select “Touch ID & Password” from the sidebar.
- Click “Add Fingerprint.”
- Follow the on-screen instructions.
You can also find instructions on Apple’s website.Actions in IDM
- Go to the IDM page using Safari:
Enter https://idm.utu.fi in the browser’s address bar and press Enter. - Select “Multi-Factor Authentication (MFA) Settings.” If you already have an authentication method registered, you must use it to sign in. If it does not work, contact helpdesk@utu.fi.
- Select “Set up Passkey”
- Select “Register”
- Touch the Touch ID sensor with your finger.
- Give the passkey a descriptive name, such as “Mac.”
Note
Some Macs also support Face ID or other biometric authentication methods. If available on your device, these methods can also be used.
Security Key
A physical security key is a small USB-like device that can be used for multi-factor authentication. Authentication is performed by connecting the key to a computer’s USB port or by using it via NFC on a mobile device.
A physical security key is a good option, for example, when you use shared computers. It can be particularly useful if you want to keep your MFA authentication separate from your personal phone.
Purchasing a security key
Students: Purchase a security key yourself. Make sure that the key supports the FIDO2 or U2F standard.
Staff: Contact helpdesk@utu.fi to request a security key.
Recommended and tested security keys include the Yubico Security Key series and the YubiKey 5 series.
Security keys can be used with the most common web browsers, including Chrome, Edge, Firefox, and Safari, as well as on Windows, macOS, and Linux computers.
1. Setting up a passkey with an external security key
2. Open a web browser on your computer. You can use Chrome, Edge, or Safari.
3. Go to the IDM UTU website:
Enter https://idm.utu.fi in the browser’s address bar and press Enter.
4. Select “Multi-Factor Authentication (MFA) Settings.”
5. Select “Signing In / Kirjautuminen.”
6. Select “Set up Passkey / Rekisteröi pääsyavain.”
7. Select “Register / Rekisteröi.”
8. From the list that appears, select “Windows Hello or External Security Key.”
If you are prompted to use a Windows Hello PIN or fingerprint, select “Cancel.”
9. Under “Security Key setup,” click “OK.”
10. Create a PIN code for your security key.
11. Touch the sensor on the security key twice when prompted.
12. Give the security key a descriptive name, such as “USB security key.”
Linux & others
KeePass or Bitwarden can be used for multi-factor authentication, for example on a Linux computer. These are alternative methods when it is not possible to use an authenticator app or a passkey.
We recommend using an authenticator app on your phone as the primary method whenever possible.
Bitwarden
Instructions for setting up Bitwarden:
- Create a Bitwarden account Go to Bitwarden and select “Create Account.” Fill in the following fields:
- Email address
- Name (optional)
- Master Password
- Confirm Master Password
- Password hint (optional)
- Install the Bitwarden browser extension
Download the extension from Bitwarden Downloads. - Sign in to the Bitwarden browser extension.
- Go to the IDM UTU website: Enter https://idm.utu.fi in the browser’s address bar and press Enter.
- Select “Multi-Factor Authentication (MFA) Settings.”
- Select “Signing In / Kirjautuminen.”
- Select “Set up Passkey / Rekisteröi pääsyavain.”
- Select “Register / Rekisteröi.”
From the list that appears, select “Bitwarden.” - Create a passkey in Bitwarden.
- Give the passkey a descriptive name, such as “Bitwarden.”
KeePass
Install Keepass and create a new database according to the Keepass instructions. Once the database is created, you can follow these steps.Add a new entry to the database via the Entry menu:

Fill in your UTU account details in the window so you can find it in the database. You do not need to add a password if you are using the program only as an authenticator. After filling in the upper fields, click “OTP Generator Settings” from the Tools menu.

Next, copy the QR code shown on the authentication app registration page into the “Shared secret” field in the window that opens. You can see it by clicking “Unable to scan.” After pasting, remove any spaces from the code. The same window will show a changing code that you can use to complete the app registration. Finish the registration in your browser, then click OK in the window.

Finally, complete adding the entry to the database by clicking OK in the “Add Entry” window.
Now, to get the one-time codes used for multi-factor authentication, open the database in Keepass, and enter the database password. Then, right-click your entry in the database and choose to either copy the code to the clipboard or display it on the screen.

