As of April 15, 2026, mandatory multi-factor authentication (MFA) will be enabled on all guest-type accounts in the Office 365 environment. This change applies to all external accounts that are not part of the CTU IS and were invited to the Office 365 environment based on an email address (e.g., for access to shared files, Microsoft Teams, or other Office 365 services).
What should I do?
- Verify which type of guest account you are using, see the procedure below: “Not sure which type of guest account you are using?”
- If you sign in only using a code sent to your email, set up MFA by April 14, 2026, see the procedure below: “Microsoft Authenticator setup guide”. If you do not set up MFA by this date, you will be automatically prompted to do so upon your first login.
- If you sign in using a work/school Microsoft account or a personal Microsoft account and already have MFA configured, usually no further action is required.
What is a guest account in Office 365?
A guest account is a type of account in the Office 365 environment that allows external users limited access to selected university services without being employees or students. It is not a full internal CTU account. It is created based on an invitation, primarily used for online collaboration, and allows only limited access to the services and data that a specific team, document owner, or service administrator grants to the guest.
For guests, it typically applies that:
- they have a different Microsoft / Office 365 account (e.g., from another university or company), a personal Microsoft account, or they use a personal email address (e.g., Gmail, Seznam, etc.),
- they were invited by the university to collaborate in the Office 365 environment,
- after accepting the invitation, they can sign in to selected services, such as Microsoft Teams,
- they can open shared documents, join online meetings, or communicate in teams if they have been granted permission,
- they do not have a login name in the format: username@cvut.cz.
There are three basic types of accounts:
- Work or school Microsoft account
- Personal Microsoft account
- E–mail account (sign-in using a code sent to email).
For the first two types, authentication methods set in the home organization or in the personal Microsoft account are used. If you already have MFA configured, no further configuration is required. For email accounts, however, it is necessary to set up MFA directly in the CTU Office 365 environment.
General information:
- Sign in using the email address to which you received the invitation from the CTU Office 365 environment. Do not use a login name in the format username@cvut.cz, as this format is reserved for internal CTU accounts.
- On the following links, you can configure MFA for your specific type of guest account!
- If you are unable to sign in to any of the links below, it is likely that your account no longer exists in CTU Office 365.
Follow these steps:
- Open the page: https://mysignins.microsoft.com/security-info
- If you are able to sign in, you are using a work or school Microsoft account from an external organization.
- If an error appears (e.g., the username is incorrect), proceed to the next step.
- Open the page: https://account.microsoft.com/security
- If you are able to sign in, it is a personal Microsoft account.
- If you cannot sign in, proceed to the next step.
- Open the page: https://aka.ms/mfasetup?tenant=f345c406-5268-43b0-b19f-5862fa6833f8
- If you are able to sign in, it is an email account.
- In this case, it is necessary to configure MFA according to the guide below.
Microsoft Authenticator setup guide
Microsoft Authenticator can be installed on Android 8+ and iOS 16+. Depending on the operating system version, individual steps when adding an account may differ.
App icon:
1 |
Install the Microsoft Authenticator app on your phone: Android: Google Play / iPhone: App Store Make sure you are installing the correct app! (see icon above!) |
4 |
Open the Microsoft Authenticator app on your phone and select Add account, or click + in the top right corner and choose Work or school account. Then select Scan QR code. |
2 |
On your computer, go to the page for configuring sign-in methods based on account type and sign in using the email address to which you were invited to the CTU network. In case of issues, we recommend using an incognito window. |
5 |
Point your phone at your computer screen and scan the QR code. This will add the CTU account to the app on your phone. On the computer screen, confirm by clicking Next. |
3 |
Click + Add sign-in method and select Microsoft Authenticator. In the wizard, choose Next twice, after which a unique QR code will be generated. |
6 |
A numeric code will appear on the computer screen. Enter it into the app on your phone and confirm. After clicking Next, your CTU account will be protected by MFA. |
Note: Third-party applications such as Google Authenticator and others can also be used as an authentication method.
Procedure:
- Open the account management link: https://aka.ms/mfasetup?tenant=f345c406-5268-43b0-b19f-5862fa6833f8 and sign in with the account registered as a guest in the CTU environment.
- In the left menu, select Organizations.
- For the organization Czech Technical University in Prague, click the Leave button.
- Confirm leaving the organization. The change usually takes effect immediately or within a few minutes.
What happens after leaving the organization:
- you will lose access to teams, channels, and conversations in Microsoft Teams within CTU,
- you will lose access to shared documents and files (e.g., SharePoint or OneDrive CTU),
- you will no longer be able to sign in to CTU services as a guest.
Important information
- This step does not affect your personal or work accounts outside the CTU environment.
- Your data stored outside CTU (e.g., in your own Microsoft account or company Office 365 environment) remains unchanged.
- If you need access again in the future, you must be re-invited by the CTU organization.
If you lose access to multi-factor authentication (MFA), experience technical issues, or have questions regarding CTU guest accounts, you can contact the CTU Service Desk at servicedesk@cvut.cz. Please include a brief description of your request and the email address associated with your guest account in the Microsoft 365 environment. This information will help speed up account identification and request processing.
What is multi-factor authentication? What are the options for second factors? Detailed information can be found here: https://ist.cvut.cz/nase-sluzby/vicefaktorove-overovani-mfa/. Warning: The configurations listed at this link are not valid for Office 365 guest accounts!