Body
Duo is the multi-factor authentication method used by all university employees.
Table of Contents
Passwords alone have proven to be insufficient to protect user accounts from cybercriminals and multi-factor authentication (MFA) has become the industry standards for accounts that have access to sensitive information. Every University employee has access to data that is protected by some form of regulation. By doing our best to protect employee accounts, we are protecting the university from attack by cybercriminals and protecting the privacy of our students, patients, and fellow employees.
All university employees (including full time, part time, intermittent, and contract employees) are required to use Duo MFA. Students, alumni, and other account holders are required to use a different form of MFA.
Duo is currently configured to protect web logins to Pacific's single sign-on environment. These include myAccount, Moodle, Box, BoxerApps and BoxerMail (Google), Boxer Alerts, Compliance Training, Qualtrics, Zoom, and others. Our VPN and RDS systems also use Duo MFA.
Most employees find it easiest to use their personal smartphones, or a university-owned smartphone issued to the employee, as their Duo authentication devices.
The Duo Mobile App can be downloaded for free from either the Apple or Google Play app stores.
No. The use of a personal smartphone is offered and suggested to employees as a convenience, but is not required. We also do not require employees to have personally owned smartphones.
Certain employees qualify for university issued cell phones, which can be set up for Duo MFA. In addition, some employees are issued tablets (e.g. iPads) issued to them that can run the Duo app. For employees that do not want to use a personal smartphone and do not have a university issued phone or tablet, hardware security keys (see below) are available.
UIS maintains a stock of basic hardware keys, and will distribute these to employees who request them at no cost to the employees or the employees' departments. Where a hardware key is needed by an employee, and UIS has run out of stock, or the basic model UIS carries is not sufficient, the responsibility is for the department to pay for a key.
Yes. Many security-minded people use security keys to secure both personal accounts and for use with Duo MFA as a Pacific employee. We strongly suggest purchasing Yubikey security keys from yubico.com. Avoid purchasing security keys from untrusted companies.
UIS maintains both USB-A and USB-C Yubikeys. For logging in to devices that do not have any USB port, UIS can help purchase a hardware token that generates authentication codes.
If you leave your Multi-Factor Authentication device at home, please contact the Technology Helpdesk and we will assist you with temporary access. You may consider purchasing a hardware security key to keep on a key ring for backup if needed.
For one’s primary web browser, it should generally be once a week, since one can tell Duo to keep one logged in for five days. Expect to authenticate via Duo MFA when logging in from any new device, new browser, or incognito window.
The Duo Mobile app will allow you to generate a one time code that can be used when your smartphone does not have data service. Choose the "Duo Mobile passcode" option when authenticating with Duo Mobile. See also this article for special instructions on using a one time code when logging into VPN.
Employees who may need to login on multiple devices at various locations will need to carry either their cell phone or a hardware key in order to login.
No. Multi-Factor Authentication with Duo will work on any computer used to access University resources protected behind Multi-Factor Authentication.
Duo Mobile will work on many of the recent versions of Apple iOS and Android versions as long as the phones have screen locks enabled and have not been "rooted".
Please see this Duo web site for supported Apple iOS versions.
Please see this Duo web site for supported Android OS versions.
Please see our Knowledgbase article for Changing Multi-Factor Authentication with Duo to a New Phone.
One can log onto a Duo-protected application using the browser on one’s cellphone, and authenticate using the Duo app on the same device.
On Safari on macOS Catalina 10.15 and macOS Big Sur 11.0, to take advantage of this feature, you must go to Preferences -> Privacy and uncheck the checkbox for "prevent cross-site tracking."
Please contact the Pacific Technology Helpdesk at 503-352-1500 or submit a ticket.
See Also
For more information, please see the Duo service catalog entry.
Questions?
Contact Support