What do you need to do?
If you have received an email with an overview of applications and IT services (hereafter referred to as services) you have signed in to via your UiO account in Microsoft 365, we request that you follow the instructions below. Please choose the appropriate option below to see what applies to you.
I have used an unapproved service for UiO purposes
UiO requests that you delete any UiO data that has been uploaded, synchronized, or stored in the service by 12pm on the 16th of September 2025. If you wish to retain the data, it must be stored in an approved location according to the UiO data storage guide.
How to log in to the service to manage your data:
-
Open the service
-
This could be via a website, an app on your phone, a program on your computer, or similar—depending on the specific service.
-
You can sign in to the service via https://myapps.microsoft.com and start the service from there to ensure you are using the correct service and account.
-
-
Select “Sign in with Microsoft”
-
This option may also be labeled “Continue with Microsoft,” “Microsoft,” “Microsoft 365,” “Office 365,” or similar.
-
Sometimes it is found under “More sign-in options” or “Enterprise login.”
-
The sign-in screen may look like the example below, but this can vary from service to service.
-
-
-
Use your UiO account
-
Enter your UiO username (username@uio.no) and password.
-
-
Locate and delete your data
-
Look for settings, profile, or privacy menus.
-
Choose to delete your account or remove stored data associated with your UiO account.
-
Tip: You can also sign in to the service via https://myapps.microsoft.com and start the service from there to ensure you are using the correct service and account.
The termination of access to the service for sign-in via your UiO account in Microsoft 365 does not necessarily mean that the user account will be deleted. You should therefore also delete the account by 12pm on the 16th of September 2025.
Please contact the service provider to request the deletion of your account or use functionality for deletion in the service provider's portal.
Suggestion for wording to use in a request for account deletion: “I request permanent deletion of my account and all data related to it.”
I have used an unapproved service for private purposes
Option 1:
If you want to keep access to the service, you need to change your sign-in method/authentication method before 12pm on the 16th of September 2025. For example, you can switch sing-in method to your personal email.
Option 2:
If the service does not allow changing the sign-in method, the user account must be deleted before 12pm on the 16th of September 2025
Please contact the service provider to request the deletion of your account or use functionality for deletion in the service provider's portal.
Suggestion for wording to use in a request for account deletion: “I request permanent deletion of my account and all data related to it.”
How to log in to the service to manage your data and sign-in method:
-
Open the service
-
???????This could be via a website, an app on your phone, a program on your computer, or similar—depending on the specific service.
- You can sign in to the service via https://myapps.microsoft.com and start the service from there to ensure you are using the correct service and account.
-
-
Select “Sign in with Microsoft”
-
This option may also be labeled “Continue with Microsoft,” “Microsoft,” “Microsoft 365,” “Office 365,” or similar.
-
Sometimes it is found under “More sign-in options” or “Enterprise login.”
-
The sign-in screen may look like the example below, but this can vary from service to service.
-
-
-
Use your UiO account
-
???????Enter your UiO username (username@uio.no) and password.
-
-
Locate and delete your data, switch sign-in method
-
???????Look for settings, profile, or privacy menus.
-
Choose to delete your account or remove stored data associated with your UiO account.
-
Switch sign-in method
-
Tip: You can also sign in to the service via https://myapps.microsoft.com and start the service from there to ensure you are using the correct service and account.
I have used an approved service with the wrong sign-in method/authentication method
Option 1:
If possible, you can change your sign-in method/authentication method in the service before 12pm on the 16th of September 2025.
Option 2:
If it is not possible to change your sign-in method/authentication method, you must delete any UiO data that has been uploaded, synchronized, or stored in the service before 12pm on the 16th of September 2025.
The restriction of access to the service for signing in via the UiO account in Microsoft 365 does not necessarily mean that the user account will be deleted. The account should, therefore, also be deleted before 12pm on the 16th of September 2025.
Please contact the service provider to request the deletion of your account or use functionality for deletion in the service provider's portal.
Suggestion for wording to use in a request for account deletion: “I request permanent deletion of my account and all data related to it.”
If you still want to use the service in your work at UiO, you need to create a new account with the correct sign-in method.
How to log in to the service to manage your data and sign-in method:
-
Open the service
-
This could be via a website, an app on your phone, a program on your computer, or similar—depending on the specific service.
-
You can sign in to the service via https://myapps.microsoft.com and start the service from there to ensure you are using the correct service and account.
-
-
Select “Sign in with Microsoft”
-
This option may also be labeled “Continue with Microsoft,” “Microsoft,” “Microsoft 365,” “Office 365,” or similar.
-
Sometimes it is found under “More sign-in options” or “Enterprise login.”
-
The sign-in screen may look like the example below, but this can vary from service to service.
-
-
-
Use your UiO account
-
???????Enter your UiO username (username@uio.no) and password.
-
-
Locate and delete your data, switch sign-in method
-
???????Look for settings, profile, or privacy menus.
-
Choose to delete your account or remove stored data associated with your UiO account.
-
Switch sign-in method
-
Tip: You can also sign in to the service via https://myapps.microsoft.com and start the service from there to ensure you are using the correct service and account.
What has happened?
At UiO, it has until recently been possible for employees and students to sign in to a number of services using their UiO account in Microsoft 365.
This includes both services that are not approved for use at UiO, and services that are approved for use at UiO but with a different sign-in method than Microsoft 365, such as Feide or Weblogin. Users who have signed in via their UiO account in Microsoft 365 have had the opportunity to give these services access to their data stored in UiO's Microsoft 365, without this being assessed, approved, or intended by UiO as the data controller.
This means that users, often without fully understanding it, have granted services access to:
- Emails and attachments
- Calendar and contacts
- Files in Teams, OneDrive, and SharePoint
- The ability to send emails on the user's behalf
- Other resources
This has occurred without UiO having entered into the necessary agreements and conducted the required assessments regarding privacy and IT security.
How is UiO handling this incident?
UiO has identified affected users and services. Affected users will be notified via email. UiO will restrict the ability to sign in to services using the incorrect sign-in method/authentication method, providing a deadline for users to retrieve any documents and other items they have stored in the service. UiO has reported the incident to the Datatilsynet (The Norwegian Data Protection Authority).