This article serves as a guide for managing Two-Factor Authentication (2FA) using Duo Mobile.
2FA adds an extra layer of security to your account by combining:
The focus of this article is on setting up 2FA on your smartphone using the Duo Mobile app. Although other 2FA methods are available, as described in the panels below, using the Push Notification option in Duo is strongly encouraged for the best experience. Additionally, 2FA is required for all active members of the university community.
The Duo Mobile app is available in Google's Play Store and Apple's App Store. The app can be installed on most smartphones and on some tablets.
Note: Duo Mobile is a secure, popular 2FA service that can be used to log in to accounts other than those at the university. Duo can also be used as an alternative to Google Authenticator for logins to Instagram, Snapchat, PayPal, Amazon, and more. UITS support for Duo Mobile is for UA accounts only. For more information, see Duo's Third-Party Accounts website.
____________
Note: These instructions use an iPhone, but you can apply them to Android as long as you can install apps from the Play Store.
Instructions
With Duo Mobile installed, you are ready to go to the next panel where you'll enroll your smartphone in 2FA.
After you install Duo Mobile on your smartphone, follow these steps to enroll your smartphone in 2FA for the first time.
Note: If you have previously activated Duo Mobile with the same phone number, please review the Reactivate 2FA (Duo).
Once you activate your account, follow these instructions to verify that your 2FA is functioning. You can use your DUO credentials to log into all U of A resources that are behind NetID.
Note: Please be aware that if you are using DUO from an unusual location or if DUO identifies unusual activity on your account, you may be asked to complete an additional authentication step. Please see the Duo - Risk-Based Authentication article for details.
Use the instructions below to log into UAccess using a Duo Mobile Push on your device.
(Optional) Use a Duo Mobile Passcode
After setting up Duo Mobile on your mobile device, it's important to regularly verify all the devices connected to your account. This is a key information security practice, as unfamiliar devices on your account could mean it has been compromised.
Note: For enhanced security and easier account recovery, the university recommends configuring two backup options:
To confirm your account devices, you can follow the steps you used to enroll your smartphone in 2FA:
Note: If you notice any unfamiliar devices listed on your account, you should immediately perform a Change Password.
Please contact the 24/7 Support Center if you need additional assistance.
2FA account lockouts occur after four (4) failed attempts.
The actions listed below will cause failed attempts. Any combination of the following four actions will cause your 2FA account to be locked:
Failed Duo Push
Invalid Duo Mobile Passcodes
Invalid or expired SMS Passcodes