Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Warning

Don't be a victim! Never provide the Duo verification code to anyone!

If you get random requests for Duo verification – when you're not logging into anything – your account has been compromised and someone has your password. Select "I'm not logging in" and reset your password immediately! 

Table of Contents
maxLevel4
minLevel2
absoluteUrltrue

2-Step with Duo - The Basics

...

2-Step with Duo verified push authentication is required to access any service that uses the University's main sign-in page. Check the "Trust Browser" box to reduce the number of notifications you get from Duo.  Select this feature in all browsers you use for the most seamless experience. You should only use this feature on your personal devices. For more information, see Duo - Trust Browser Option - Instructions.

I can't use the Duo Mobile app. What should I do?

...

What is the Trust Browser option and how does it work?

You should ONLY usethis feature on your personal devices. This is a setting that gets saved in your browser's cookies. If you check the "Trust Browser" box, and use the same computer and browser, you won't have to verify your identity with Duo for 30 days.  Select this feature in all browsers on your personal devices, that you use for the most seamless experience.  For more information, see Trust Browser instructions.

What is a Bypass code and when can it be helpful to me? 

A Bypass code can be used to grant temporary access for multiple use case scenarios:

  • Complete activating your mobile device.

  • Adding a new phone/device. 

  • If you are a current Duo user, and you don't have access to your registered device, your device stopped working unexpectedly, or was lost/stolen. 

Request a self-service Bypass code when the need arises. The Bypass code will provide secure temporary access for 24 hours

...

ITS recommends registering multiple devices via the Duo Device Portal to authenticate. Make 2-Step with Duo as mobile as you are by registering your Smart phone, tablet, and other devices to maximize your verification options. 

...

Tip

Set up Duo Instant Restore to make it easy to move your Duo account from one Android phone to another. You must set up Duo Instant Restore before you get your new phone, and you'll need both phones to successfully complete this process. Duo Instant Restore can only be used to move between Android devices.

  1. Open Duo Mobile and tap the menu icon in the top right to open Settings.

  2. Tap

...

  1.  Duo Restore in the "General" settings.

  2. On the "Duo Restore Settings" screen, tap to enable the

...

  1.  Backup accounts with Google Drive.

  2. Select the Google account to use for Duo Restore and grant Duo Mobile permission to store the backup in your Google Drive.

  3. Choose to enable account recovery for your third-party accounts by

...

  1. tapping Automatically reconnect third-party accounts. If you don't enable this now, Duo Mobile will remind you later.

  2. When prompted, enter and confirm a recovery password between 10-128 characters.

...

  1.  Do not lose this password! You'll need this to recover any third-party accounts after restoring Duo Mobile on a new phone. Duo cannot recover this password for you.

iOS Devices

Tip

Set up Duo Instant Restore to make it easy to move your Duo account from one iOS device to another. You must set up Duo Instant Restore before you get your new device, and you'll need both devices to successfully complete this process. Duo Instant Restore can only be used to move between iOS devices. 

  1. Verify that you are running the latest version of Duo Mobile on your device. 

  2. Backup your iPhone to iCloud with iCloud keychain enabled. Make sure to enable iCloud keychain before backing up data.

  3. From your new iPhone, sign in to iCloud and restore the phone from iCloud.

  4. Enable iCloud keychain.

  5. Install Duo Mobile from the AppStore.

  6. Open Duo Mobile and tap Get Started

...

  1.  on the "Welcome Back" screen.

    Image Modified
    Duo Mobile will locate your backed-up Duo Mobile account and restore it to your new device.
    A success message will display when the Duo Mobile account is restored on the new device. 

...

Warning

Duo will send a notification to your old phone indicating that Duo Mobile has been activated on a new phone.

  • If you didn't perform a restore to a new device,

    tap 

    tap Report as Fraud.  This will deactivate your Duo accounts on both devices and alerts your organization's Duo administrators about the fraudulent reactivation.

  • If you did the restore,

    tap 

    tap This is not

    fraud 

    fraud to dismiss the notification.  

Using 2-Step with Duo

What's the best way to authenticate using Duo and which browsers and operating systems are supported?

ITS recommends using the Duo Mobile app for the easiest, most secure experience.  The Duo Mobile app is available from the App Store or Google Play

  • It's free, easy to use and provides options that work with or without WiFi or a data connection.

  • Supported browsers include Chrome (Desktop and Mobile), Firefox, Safari (Desktop and Mobile), Edge, and Internet Explorer. Not all browsers support all Duo authentication methods, so for the widest compatibility we recommend Chrome.

  • Duo Mobile supports specific versions of iOS and Android.

How do I authenticate to Duo?

...

Using the Duo Mobile App:

  • 'Send Me a Push' is the default. Duo sends a notification requiring you to enter a code into the app. You'll need WiFi or a data connection.

  • 'Enter a Passcode' generates a 6-digit code that you'll enter when prompted. You do not need WiFi or a data connection.

Using a Hardware Token:

No smartphone? No problem. Ask ITS for a free Hardware Token.  Once you have been provided a hardware token, follow these instructions to use it for gaining access to UAlbany services.

...

A security key plugs into your USB port and when tapped or pressed it sends a signed response back to Duo to verify your login.  A security key is considered a secondary back up method because it will not work with all UAlbany applications.  It does not work with the VPN nor the CBORD app.   You will need to download the free Duo Mobile app from the App Store or Google Play for full authentication functionality with UAlbany services and activate your mobile device in addition to using a security key. There are also supported browser and security key requirements.  Please see the instructions for using a security key with the Duo Universal prompt. 

How do I change my Duo devices and settings?

Log into the Duo Device Portal to change Duo devices or settings. You will need to verify your identify with your current Duo settings prior to making any changes. For more information, see the Duo Device Portal - Instructions page.

...

Yes. Use the Duo Mobile app utilizing the built-in Passcode feature while traveling within the United States as well as Internationally.  This is a great feature to use because you can generate and use passcodes without a Wi-Fi connection (i.e airplane mode).  You may wish to manage or update devices to correspond with the availability of technology resources while you are traveling.  For more information visit our our International Travel and International Number Use with Duo resource.

...

Not sure if that Duo verification is suspicious? These clues can help:

  • Are you logging into a campus IT service? If not, deny and reset your password.

  • Is the timestamp on the Duo verification consistent with a login you initiated? If not, deny and reset your password.

  • Is the geolocation on the Duo verification consistent with your location? Depending on your network, this may reflect a neighboring town or city. It should not reflect a distant location, such as another state or country.

Duo locked me out of my account. What happened?

...

Hardware Tokens can get 'out of sync' if the button is pressed too many times and the passcodes are not used. If your Token stops working or you can't login with the passcode it provides, try re-syncing it:

  1. Generate 3 passcodes in a row

  2. Login to a Duo-protected service, such as MyUAlbany, with your NetID and password

  3. Use the third passcode you just generated to verify your identity

Contact the ITS Service Desk if you are still unable to access campus IT services.

...

Contact the ITS Service Desk. If you have a secondary method for receiving Duo notifications, ITS recommends logging into the Duo Device Portal and disabling your Hardware Token.

...

Duo Guide to Two-Factor Authentication

What data does Duo collect and use?

The Duo Mobile app and Duo prompts collect information from your device whenever you open the app, and whenever you use it to verify your identity. This includes the following:

  • The model of your device, its operating system, address, and the version of the app you are using

  • Connection information, including the name of a mobile operator or ISP, language, time zone, and phone number

  • IP address

The Duo Mobile app does not:

  • Track your location

  • Access your contacts, text messages, or email

  • Access your browser history

  • Erase anything on your device

  • Allow UAlbany to manage your device in any way

  • Access your photos

How does Duo Mobile protect my privacy?

Learn more about:

Include Page
footer
footer