Multi-Factor Authentication with Duo Frequently Asked Questions

Body

Duo is the multi-factor authentication method used by all university employees.

Table of Contents

Why are we being required to use Multi-Factor Authentication?

Passwords alone have proven to be insufficient to protect user accounts from cybercriminals and multi-factor authentication (MFA) has become the industry standards for accounts that have access to sensitive information.  Every University employee has access to data that is protected by some form of regulation.  By doing our best to protect employee accounts, we are protecting the university from attack by cybercriminals and protecting the privacy of our students, patients, and fellow employees.

Who is required to use Multi-Factor Authentication?

All university employees (including full time, part time, intermittent, and contract employees) are required to use Duo MFA.  Students, alumni, and other account holders are required to use a different form of MFA.

Which services require that we use Multi-Factor Authentication?

Duo is currently configured to protect web logins to Pacific's single sign-on environment. These include myAccount, Moodle, Box, BoxerApps and BoxerMail (Google), Boxer Alerts, Compliance Training, Qualtrics, Zoom, and others.  Our VPN and RDS systems also use Duo MFA.

What devices do employees use for Multi-Factor Authentication with Duo?

Most employees find it easiest to use their personal smartphones, or a university-owned smartphone issued to the employee, as their Duo authentication devices.

How do I get the Duo Mobile App for my smartphone?

The Duo Mobile App can be downloaded for free from either the Apple or Google Play app stores.

Can the university require people to use their personal cell phones?

No.  The use of a personal smartphone is offered and suggested to employees as a convenience, but is not required.  We also do not require employees to have personally owned smartphones.

What if I do not want to use my personal cell phone when setting up this service?

Certain employees qualify for university issued cell phones, which can be set up for Duo MFA.  In addition, some employees are issued tablets (e.g. iPads) issued to them that can run the Duo app.  For employees that do not want to use a personal smartphone and do not have a university issued phone or tablet, hardware security keys (see below) are available.

Who pays if I need a hardware security key?

UIS maintains a stock of basic hardware keys, and will distribute these to employees who request them at no cost to the employees or the employees' departments.  Where a hardware key is needed by an employee, and UIS has run out of stock, or the basic model UIS carries is not sufficient, the responsibility is for the department to pay for a key.

Can I purchase my own security key device?

Yes.  Many security-minded people use security keys to secure both personal accounts and for use with Duo MFA as a Pacific employee.  We strongly suggest purchasing Yubikey security keys from yubico.com.  Avoid purchasing security keys from untrusted companies.

What if my device does not have the right port for the a basicYubikey?

UIS maintains both USB-A and USB-C Yubikeys.  For logging in to devices that do not have any USB port, UIS can help purchase a hardware token that generates authentication codes.

What happens if I forget my cell phone or security key at home?

If you leave your Multi-Factor Authentication device at home, please contact the Technology Helpdesk and we will assist you with temporary access. You may consider purchasing a hardware security key to keep on a key ring for backup if needed.

How often would we have to use Multi-Factor Authentication?

For one’s primary web browser, it should generally be once a week, since one can tell Duo to keep one logged in for five days.  Expect to authenticate via Duo MFA when logging in from any new device, new browser, or incognito window.

What if my smartphone does not have data service?

The Duo Mobile app will allow you to generate a one time code that can be used when your smartphone does not have data service.  Choose the "Duo Mobile passcode" option when authenticating with Duo Mobile.  See also this article for special instructions on using a one time code when logging into VPN.

Will I need to carry around my cell phone everywhere I go?

Employees who may need to login on multiple devices at various locations will need to carry either their cell phone or a hardware key in order to login. 

Am I limited to using only University owned computers?

No.  Multi-Factor Authentication with Duo will work on any computer used to access University resources protected behind Multi-Factor Authentication.

Which Phones will work with Duo Mobile?

Duo Mobile will work on many of the recent versions of Apple iOS and Android versions as long as the phones have screen locks enabled and have not been "rooted".
Please see this Duo web site for supported Apple iOS versions.
Please see this Duo web site for supported Android OS versions.

What do I need to do if I get a new cell phone?

Please see our Knowledgbase article for Changing Multi-Factor Authentication with Duo to a New Phone.

Do I need to authenticate with Duo if I am accessing a site on my mobile phone that has the Duo app installed?

One can log onto a Duo-protected application using the browser on one’s cellphone, and authenticate using the Duo app on the same device.

I set my browser to reject all cookies except from sites I've specifically allowed. What sites should I allowlist?

  • duo.com
  • duosecurity.com

Why won't my Mac remember me for 7 days?

On Safari on macOS Catalina 10.15 and macOS Big Sur 11.0, to take advantage of this feature, you must go to Preferences -> Privacy and uncheck the checkbox for "prevent cross-site tracking."

Where do I go for help if I’m having problems with Multi-Factor Authentication?

Please contact the Pacific Technology Helpdesk at 503-352-1500 or submit a ticket.

See Also

For more information, please see the Duo service catalog entry.

Questions?

Contact Support

Details

Details

Article ID: 134328
Created
Sun 7/11/21 7:24 PM
Modified
Mon 7/27/26 1:51 PM