/gts/api.php?action=feedcontributions&feedformat=atom&user=SsukhramTechnology Services Wiki - User contributions [en]2025-05-01T20:25:11ZUser contributionsMediaWiki 1.31.1/gts/w/index.php?title=Duo_Two_Factor_Authentication&diff=38508Duo Two Factor Authentication2021-01-06T16:49:02Z<p>Ssukhram: </p>
<hr />
<div>Âé¶¹ÊÓÆµ requires DUO Two-Factor Authentication (TFA or 2FA) on your Âé¶¹ÊÓÆµ account. Two-Factor Authenication is also known as Strong Authentication or Multi-Factor Authenticaion (MFA). DUO TFA is required for employees and students. Please note that enrolling in DUO two-factor authentication is permanent and cannot be deactivated.<br />
<br />
[[File:duomobileapp.png|right|150px]]<br />
<br />
[https://guide.duo.com/ Learn more about Duo Two-Factor Authentication]<br />
<br />
<br />
<br />
{{DuoTwoFactorQuickLinks}}<br />
==Why enroll in two-factor authentication?==<br />
<br />
Two-Factor Authentication adds an additional layer of security to your Âé¶¹ÊÓÆµ account. In addition to your password, you will need a mobile device like your phone or a hardware token to verify your identity when logging into your account.<br />
<br />
Using just a username and password are no longer considered a secure mechanism for authentication. A password can be stolen or guessed. 2FA protects against password theft or guessing by requiring access to a physical mobile phone or hardware token to successfully login.<br />
<br />
A successful information security program is all about adding layers of protection and 2FA is one of those critical layers. Learn more about securing your login by visiting the following page.<br />
[https://www.lockdownyourlogin.com/ #LockDownURlogin]<br />
<br />
==How does it work?==<br />
<br />
#Access a resource protected by 2FA such as the Âé¶¹ÊÓÆµ website or GusMail.<br />
#Enter your username and password as you normally would.<br />
#Click DUO push to send a verification to your mobile device or it may be automatically pushed to your device. If you do not have a mobile device set up, you can receive a verification notification sent to your office phone, or hardware token (fob) where it will give a code to enter.<br />
#After verifying it from you, by checking location, you accept a prompt from your mobile device to approve the login. If you have a fob, press the button on the fob, and then type the code that appears on your fob into the web page.<br />
#Login is now complete.<br />
<br />
==Enrollment==<br />
<br />
Two-Factor Authentication is required on your Âé¶¹ÊÓÆµ account. Any user may enable 2FA on their Âé¶¹ÊÓÆµ account by following the instructions below. You will need a mobile device and the password for your phone to install the DUO Mobile App. You will also need your AppleID or Google Play account password to download the App Store or Google Play store. Please note that enrolling in DUO two-factor authentication is permanent and cannot be deactivated.<br />
<br />
Follow the steps below to begin the two-factor enrollment, or watch our [https://youtu.be/7S2KyOexQJg Getting Started with Duo Two Factor at Âé¶¹ÊÓÆµ Video].<br />
<br />
#Visit the [/account/manageTwoFactor Âé¶¹ÊÓÆµ DUO Management] portal.<br />
#Enter your username and password. <br>[[File:ssologinpage.PNG]]<br />
#Click '''Start Enrollment''' or proceed to the next step if GTS has enabled your account for two-factor.<br />
#Click '''Start Setup'''. <br>[[File:tfasetup1.PNG]]<br />
#Select your device type. We recommend a mobile device such as a phone. If you would like to set up your office phone, choose Landline.<br>[[File:tfasetup2.PNG]]<br />
#Enter your phone number and select the platform of the device. <br>[[File:tfasetup3.PNG]]<br />
#Install the '''Duo Mobile''' App from the App or Play store on your mobile device. <br>[[File:tfasetup4.PNG]]<br />
#Please enable notifications and access to the camera.<br />
#Activate the '''Duo Mobile''' App by opening it and scanning the QR code. <br>[[File:tfasetup5.PNG]]<br />
#We recommend adding a secondary device such as your office phone by selecting '''Add Another Device''' in case your primary device is unavailable.<br />
#Click '''Continue to Login''' to try 2FA for the first time. <br>[[File:tfasetup6.PNG]]<br />
#Select '''Send Me a Push''' if you are using a mobile device. Select Call me if you are using your office phone. Enter code if you are using a hardware token (fob). <br>[[File:duoauthenWCall.PNG]]<br />
#Click '''Accept''' on your mobile device. If you are using your office phone, press any key on your key pad and hang up.<br />
#Your login is complete.<br />
<br />
==Additional Information==<br />
<br />
*An enrollment email will be sent to you from Duo as well to enable two-factor authentication. <br />
*A mobile device such as a smart phone with the DUO mobile app is recommended for convenience and ease of use. <br />
*If you do not want to use your mobile device, a [[Security Key]] may be purchased. We recommend the Yubikey 5 or [[Security Key]] (NFC) from Yubico. There are several options depending on your devices: [https://www.yubico.com/store#security-key-series https://www.yubico.com/store#security-key-series]<br />
*GTS recommends installing the Duo Mobile app made by Duo Security on your supported device and enabling '''Automatically send me a: Duo Push.'''<br />
<br />
To learn more, please visit:<br />
*https://guide.duo.com/enrollment or watch our [https://youtu.be/7S2KyOexQJg Getting Started with Duo Two Factor at Âé¶¹ÊÓÆµ Video].<br />
<br />
<br />
<br />
[[File:duomobileapp.png|right|100px]]<br />
<br />
==Everyday Use of Duo==<br />
===Modifying Settings and Devices===<br />
There are two options for modifying your settings or to add an additional device:<br />
*Visit the [/account/manageTwoFactor Âé¶¹ÊÓÆµ DUO Management] portal.<br />
*Logout and back into the Âé¶¹ÊÓÆµ website. Then click '''My settings & Devices'''<br />
<br />
===Automatic Settings===<br />
Duo can be configured to '''automatically''' send a Push or make a phone call to your default device.<br />
*Access your Duo settings (see above)<br />
*Under the list of current devices, you will see an option to select a '''Default Device:'''. If you have more than one device configured, select your default device.<br />
*From the '''When I log in:''' pop-down select either '''Automatically send this device a Duo Push''' or '''Automatically call this device'''.<br />
<br />
===Unprompted Notifications===<br />
If you receive Push notifications that you did not initiate, '''DO NOT''' approve them. If your account has been compromised, and someone has your password, they could initiate the Push, if you accept, you have granted them access to your account. If you feel as if the Push Notification is fraudulent, please change your Âé¶¹ÊÓÆµ password and contact Technology Services.<br />
<br />
===Remember Me===<br />
[[File:Duo_Remember_Me.jpg|right|thumb]]You can set Duo to '''Remember me for 15 days'''. If you check the box (on the ''Choose an authentication method'' window), the authentication is remembered for 15 days on that browser from that machine only.<br />
<br />
==Supported Devices==<br />
<br />
*iPhone and iPad<br />
*Android device<br />
*Blackberry<br />
*Windows Phone<br />
*Hardware Token<br />
*Security Key<br />
<br />
==Video Tutorial==<br />
Watch our [https://youtu.be/7S2KyOexQJg Getting Started with Duo Two Factor at Âé¶¹ÊÓÆµ Video].<br />
<br />
==FAQ==<br />
===Am I required to enroll in DUO?===<br />
Yes, Âé¶¹ÊÓÆµ employees are required to enroll in DUO TFA. This includes student employees.<br />
<br />
===Do I need a smartphone to use Duo?===<br />
No, you can have Duo call your office phone, send texts to your cellphone, or you can use a hardware token (fob) that you can add your key ring which provides codes you can enter into the verification menu to access your account.<br />
<br />
===How can I use my FOB all the time?===<br />
The Default Device pop-down does not allow users to choose a FOB as their default device. However, at the Duo '''Choose an authentication method''' window, you can select '''Enter a Passcode'''. You can then enter a passcode from your FOB, the Duo app on your phone or pre-generated passcodes.<br />
<br />
===Does the system allow for multiple hardware tokens and phones to be added to an account?===<br />
<br />
Yes and we strongly recommend adding multiple options in case one is unavailable. However, GTS only provides one hardware token per user. If an additional one is required, there are several options available for purchase online.<br />
<br />
===How does it work?===<br />
Once you are enrolled, every time you access a web page that uses the Âé¶¹ÊÓÆµ Single Sign On page, use remote desktop or access the Remote server, you will be prompted with a Duo-Two Factor Authentication option, after you supply your credentials.<br />
<br />
[[File:Duo_Two_Factor_Image.jpg|400 px]]<br />
<br />
If you choose '''Enter a Passcode''', the code can be from the Duo application on your phone, a FOB or generated passcodes.<br />
<br />
===Do I need to use Duo Two Factor every time I log into my computer?===<br />
No, Duo Two Factor is only needed when you are logging into a resource below.<br />
<br />
===Which resources will use Duo Two Factor?===<br />
*Âé¶¹ÊÓÆµ Google Suite - Drive, Calendar, GusMail<br />
*Moodle<br />
*Remote Desktop<br />
*Âé¶¹ÊÓÆµ User Settings<br />
*Âé¶¹ÊÓÆµ Web Resources<br />
*Office 365<br />
*etc<br />
<br />
===Can I set Duo up to automatically send a Push to my phone?===<br />
Yes, you can. Those settings are in the Duo Two Factor settings. There are two options for modifying your settings:<br />
<br />
*Visit the [/account/manageTwoFactor Âé¶¹ÊÓÆµ DUO Management] portal.<br />
*Logout and back into the Âé¶¹ÊÓÆµ website. <br />
<br />
Then click '''My settings & Devices'''. <br />
<br />
You can then choose a Default Device (a hardware token or fob cannot be selected as the default device) and what method to use. Select either<br />
*Ask me to choose an authentication method<br />
*Automatically send this device a Duo Push<br />
*Automatically call this device<br />
<br />
===I am traveling abroad and do not have access to texts/internet, how can I use Duo?===<br />
When you are traveling abroad and do not have access to text messages or phone calls: <br />
#Open the Duo Mobile app on your phone<br />
#Press the down arrow to the right of the Âé¶¹ÊÓÆµ heading. This will show you a passcode to enter at the two factor authentication screen. <br />
#Instead of choosing push notification, press enter passcode and enter the number it generates in the app. <br />
#If you set it to automatically send you a push notification, press cancel and choose enter passcode.<br />
<br />
===I lost my device or I got a new device===<br />
If you lost your phone and don't have a secondary device added to your account, please contact the Technology Helpline at (507-933-6111 or [mailto:helpline@gustavus.edu helpline@gustavus.edu]) to get a new device added. You will need to speak with a full time staff member. If you have purchased a new phone, please see our web page [[Duo_TF_-_Device_Replacement_for_End_Users]].<br />
<br />
===I forgot my device at home?===<br />
If you have your cell phone configured as your device, and it isn't available (left at home or dead batteries) you can contact the Technology Helpline (507-933-6111) to get your landline added, or get printed bypass codes. You will need to speak with a full time staff member.<br />
===Can I get '''one''' time use bypass codes?===<br />
Yes, it is possible to get one time use bypass codes. These are numeric codes you would print or write down and use one time for authentication. You can get a list of bypass codes by contacting the Technology Helpline (507-933-6111 or [mailto:helpline@gustavus.edu helpline@gustavus.edu],<br />
you will need to speak with a full time staff member). To use your codes, from the '''Choose an authentication method''' window, select '''Enter a Passcode''', and input one of your codes.<br />
<br />
==Troubleshooting==<br />
===When I log into my account on my iPhone, I do not see the Duo screen. I see a blank white/grey screen.===<br />
This symptom usually indicates a web content restriction. Please see [https://help.duo.com/s/article/3710?language=en_US Duo Mobile's help page] for information on how to resolve this issue.<br />
===Duo doesn't remember me for 15 days like it says it will on my Internet browsers.===<br />
Update your browsers to the newest versions, and then try clearing the website data/cache for duosecurity.com. Also allow cookies for websites you visit.<br />
<br />
===On my Mac, when I try to update my Internet Accounts for GusMail with my new password, the accounts page freezes and doesn't allow me to update the password.===<br />
Open Keychain Access on your Mac, and search for Google saved passwords and remove them. Restart your computer and try again.<br />
[[Category:Duo Two Factor Authentication]]<br />
[[Category:Security]]</div>Ssukhram