
The professional messaging system of AP-HP is based on an infrastructure that has significantly evolved in recent years. Between the old browser access via courriel.aphp.fr and the gradual deployment of two-factor authentication with Microsoft Authenticator, the connection methods are no longer the same depending on the user’s profile and equipment. Understanding these differences helps avoid the most common blocks during the first connection or after a job change.
Connection methods to APHP messaging: comparative table
AP-HP offers several paths to access the professional mailbox. Each involves a different level of security, type of equipment, and enrollment procedure.
Further reading : Complete guide on how to easily access my SFR mailbox
| Access method | Required equipment | Authentication | Main use case |
|---|---|---|---|
| Webmail (courriel.aphp.fr) | Web browser on AP-HP or personal workstation | Username + password (+ MFA depending on profile) | Quick consultation from a shared workstation |
| Citrix Portal (messagerie.aphp.fr) | Browser + Citrix Receiver installed | Username + password + Citrix session | Remote access to the complete work environment |
| Outlook Client on AP-HP workstation | AP-HP workstation with Outlook configured | Internal network authentication | Daily use in service |
| Mobile application (smartphone/tablet) | Mobile device with Microsoft Authenticator | Username + password + MFA code | Mobile access, on-call duties |
The most significant difference lies between access from the hospital’s internal network and remote access, which systematically requires enhanced authentication. On the local network, the AP-HP workstation manages part of the authentication transparently. From outside, each connection goes through an additional verification.
To better understand the technical mechanism behind this verification, a detailed guide allows you to access APHP messaging by decrypting the functioning of the two-factor authentication implemented by the IT department.
You may also like : How to Successfully Convert Grams to Liters: Practical Guide and Tips

MFA Authentication on AP-HP Messaging: What Changes Practically
AP-HP has gradually phased out the old one-time password generator VIP Access (Symantec) in favor of Microsoft Authenticator as the MFA validation application. This switch modifies the enrollment procedure and the daily routine of agents.
Initial Enrollment with Microsoft Authenticator
The enrollment phase involves linking an AP-HP account to the Authenticator application installed on a personal or professional smartphone. This step is done only once, but it conditions all subsequent remote accesses.
- Download Microsoft Authenticator from the Play Store or Apple Store, then scan the QR code provided by the IT department during account activation
- Validate the push notification sent by the application during the first test connection on messagerie.aphp.fr or courriel.aphp.fr
- Keep the application active on the mobile, as each remote connection will trigger a validation request or a temporary code to enter
A often underestimated point: changing phones requires a new enrollment. Without this step, the old device no longer transmits codes, and the account becomes blocked. The reset procedure goes through IT support, reachable at *75 from the hospital or at 01 40 27 40 00 from outside.
Why MFA Is Not Just About Convenience
Multi-factor authentication on AP-HP messaging is not an arbitrary technical choice. Article 32 of the GDPR requires security measures appropriate to the risk for any system processing health data. Hospital messaging contains exchanges between practitioners, reports, and patient data sometimes in plain text in the body of the email.
The European NIS2 directive, whose French transposition directly concerns public health establishments, reinforces this requirement. AP-HP hospitals, as health entities considered high-criticality public services, fall within the scope of enhanced security obligations for remote access and privileged accounts.
Common Blocks When Connecting to the Citrix Portal
The Citrix portal (messagerie.aphp.fr) remains the main entry point for many agents accessing their work environment from home. The most common errors do not come from the password itself.
Disabled cookies in the browser block Citrix connection even before entering the credentials. The portal then displays a generic message (“Cookies Disabled”) that does not always mention the solution. Third-party cookies must be allowed for the domain messagerie.aphp.fr, and then the cache should be cleared before trying again.
The second classic block concerns Citrix Receiver (or Citrix Workspace, its successor). If the application is not installed or if its version is outdated, the portal offers a download that requires accepting the Citrix license terms. On a personal workstation, installation rights may be lacking. In this case, the HTML5 version of the client, accessible directly from the browser, provides a functional alternative to consult the mailbox without local installation.

Storage Space and APHP Email Address Format
Each AP-HP mailbox has a storage space of 200 MB for online data. This quota, documented in internal sheets, seems limited considering the daily exchange volume of a hospital practitioner. Saturation of the mailbox prevents the reception of new messages without generating a visible alert for the sender.
The email address format follows the model [email protected]. In case of homonymy, a number is added after the name ([email protected]). The internal messaging directory displays the trigrams of the affiliated site in the “Service” column, allowing for quick identification of a correspondent’s establishment within the AP-HP network.
The AP-HP professional messaging system remains a work tool subject to rules of proper IT usage. Regular updates of the operating system and browser are part of the security prerequisites emphasized by the IT department. An outdated workstation may be denied access to the Citrix portal or webmail, as the security certificate is no longer recognized by the server.