This article is for people who use University of Pittsburgh services and also hold a UPMC account. It covers Pitt's authentication tools and how to avoid browser sign-in conflicts when you move between Pitt and UPMC in the same session. It does not document UPMC's systems — for UPMC authentication setup, use UPMC's own resources or contact the UPMC Help Desk at 412-647-HELP (4357).
Pitt Multifactor Authentication
Pitt uses two multifactor authentication (MFA) services, depending on what you are signing in to.
When Pitt uses each multifactor authentication method
| Method |
Used For |
| Duo Security |
Most Pitt Passport sign-ins for current students, faculty, and staff. |
| Microsoft Authenticator |
Specific Microsoft administrative services — the Azure portal, the Microsoft Entra ID and Intune admin centers, the Azure CLI, Azure PowerShell, the Azure mobile app, and some infrastructure-as-code tools. |
Pitt Single Sign-On
Single sign-on (SSO) lets you log in once and reach many services without re-entering your credentials each time.
Pitt single sign-on services and their scope
| SSO Service |
Used For |
| Pitt Passport |
Most University of Pittsburgh IT services. |
| HSConnect |
Some IT services under the Senior Vice Chancellor for Health Sciences and the School of Medicine. Supported by the iTarget team. |
If You Also Have a UPMC Account
UPMC runs its own authentication and single sign-on services, separate from Pitt's. This article does not document them — for setup and support, follow UPMC's own two-step verification guidance or contact the UPMC Help Desk at 412-647-HELP (4357). The guidance below covers only the parts that affect you as a Pitt user.
Using Multiple Authenticator Apps on One Device
You can install more than one authenticator app on the same phone — your Pitt app alongside any app UPMC asks you to use. When you sign in, use whichever app the sign-in screen prompts you for. Do not assume one app applies everywhere; follow the prompt for each service.
Avoiding Sign-In Conflicts Between Pitt and UPMC
When you sign in with single sign-on, an SSO token is stored in your browser. While that token is active, you can keep reaching services without re-entering your username and password.
Warning: Tokens from one organization can block the other.
If you use both Pitt and UPMC single sign-on within the same 24-hour period, your browser may hold onto a Pitt SSO token when you try to sign in to UPMC (or the reverse), causing the login to fail.
Workaround: Separate Browser Profiles
The most reliable fix is to keep two browser profiles — one for Pitt services and one for UPMC services — so their SSO tokens never collide.
Note: An alternative to profiles.
You can also use one brand of browser for Pitt and a different brand for UPMC. Keep in mind that some individual services have specific browser requirements that can make this approach harder to sustain.