You are here

User Guide on Installation of 2FA Mobile App (FortiToken) for HKU 2-Factor Authentication (2FA) for Staff


The 2-Factor Authentication ("2FA") is a security measure for strengthening the information security protection of the authentication process in using the central IT services.  On top of HKU Portal UID/PIN, a one-time token code is required for accessing those services that require 2FA to login.

Under the current plan, 2FA is applied on using HKU Virtual Private Network ("HKUVPN") and some applications under HKU Portal outside campus network (for staff only).

Staff (except visiting, honorary and hourly-paid staff who can use alternate email address only) can choose to receive the token code either through a registered alternate email address or a 2FA Mobile App (FortiToken).  

For staff who prefers using 2FA Mobile App (FortiToken) to receive the token code, please register through the online form “Register To Use 2FA” via the following link and select “2FA Mobile App (FortiToken)” under section (A)-

NOTE: Staff will be required to input their HKID card no./passport no. for identity verification during 2FA registration or update of 2FA registration information.

After registration, staff will receive a SMS to inform them about the registration made. Please follow the procedure below to install the 2FA Mobile App (FortiToken).

Installation Procedures for 2FA Mobile App (FortiToken) (applicable to staff who chooses to use 2FA Mobile App (FortiToken) for receiving the token code)

Please follow the procedures below to install the 2FA Mobile App (FortiToken) for receiving the HKU 2FA token code on ONE mobile device-

Procedures for Reset of 2FA Mobile App (FortiToken) (applicable to staff who chooses to use 2FA Mobile App (FortiToken) for receiving the token code)

For staff who chooses to use 2FA Mobile App (FortiToken) to receive the token code, in case 

  • they change to use another mobile device; or
  • their mobile device is lost; or
  • they forget the 4-digit PIN on using the 2FA Mobile App (FortiToken) 
  1. Please complete the online form “Reset 2FA App” via
    (NOTE: The function “Reset 2FA App” requires 2FA to access outside HKU campus network.  Please refer to for the procedures.  If 2FA is not available, please arrange the reset within HKU campus network.)  
  2. Install the 2FA Mobile App (FortiToken) again by following the above procedures.
  3. For cases on forgot of 4-digit PIN, the 2FA Mobile App (FortiToken) on the installed device has to be removed before reinstallation.

Procedures for Removal of 2FA Registration

This can be done through the online form "Remove 2FA Registration" via the following link-

Please note that after your 2FA registration is removed, you will not be able to use

  1. HKUVPN (HKU Virtual Private Network)
  2. HKU Portal services containing personal information such as Manager Self Service, Student Information System, Personal & Family Data Form, Personnel File, Pay Slip and Annual Tax Return outside campus network (applicable to staff only) (see as well as to view/edit some important personal information in the Personal & Family Data Form and Personnel File
  3. Online reset of HKU Portal PIN

You are advised to keep your alternate email address and mobile phone number registered with ITS for the purposes of identity authentication, service event notification and communication with you.