Summary:
This article provides instructions on how to set up DUO Multi-Factor Authentication (MFA) at John Carroll University. DUO MFA enhances the security of your JCU network account by requiring two-factor authentication for login.
This Article Covers:
Prerequisites:
- JCU network username and password
- Access to a smartphone, landline phone, or security key (depending on your chosen method)
Procedure:
What is DUO Multi-Factor Authentication (MFA)
DUO MFA provides an additional layer of security by requiring two factors for authentication. These factors are "Something you Know" (your password) and "Something you Have" (smartphone app/phone, landline, or security key).
Smartphone Setup
- Begin by accessing the service as you normally do.
- You'll be prompted for your JCU Network username and password.
- The DUO MFA setup will start automatically if the service requires MFA.
- Click the "Next" button.
- You may be shown an introduction to MFA. Click 'Next' on these screens.
- Select "Duo Mobile" and press "Continue."
A note about MFA security:
While Duo MFA does support authentication by either a text message/SMS or a phone call, both of these methods can be spoofed and are not considered secure. ITS strongly recommends the installation and use of Duo Mobile on your mobile device, or if given the option, a biometric method (iOS TouchID for example). If you do not wish to install Duo Mobile on your mobile device, a USB Security Key can be obtained from the ITS Service Desk.
- Enter your smartphone's phone number.
- Verify the number is correct.
- Press "Yes, It's Correct."
- Download and install the DUO Mobile app from the App Store or Play Store on your smartphone. Once installed, press next on your computer.
- Open the DUO Mobile app on your smartphone and press the "+" button.
- Use your smartphone's camera to scan the QR code displayed on your PC's screen (example above).
- This registers your smartphone.
- If you press the Get an activation link instead, it will send you an email.
- To use the activation link please open your JCU email on the device you want to connect to Duo, then click the link within the email sent from Duo Security.
- Confirm that the "John Carroll DUO Protected" setting is displayed to complete the setup.
- Once setup is complete, you will see:
-
MFA Login Complete! Your smartphone is now set up for DUO Multi-Factor Authentication.
-
Depending on your DUO Mobile version, you may be prompted for additional configuration or a device security assessment. These steps are not required for DUO setup.
Landline Phone Setup
While Duo MFA does support authentication by either a text message/SMS or a phone call, both of these methods can be spoofed and are not considered secure. ITS strongly recommends the installation and use of Duo Mobile on your mobile device, or if given the option, a biometric method (iOS TouchID for example). If you do not wish to install Duo Mobile on your mobile device, a USB Security Key can be obtained from the ITS Service Desk.
- Access the service as usual.
- You'll be prompted for your JCU Network username and password.
- The DUO MFA setup will start automatically if required.
- Follow the instructions above, but this time select "Phone Number" from the options screen.
Security Key Setup
- Access the service.
- Enter your JCU Network username and password.
- DUO MFA setup will begin if required.
- Follow the instructions above, but this time select "Security Key" from the options screen.
- Follow on-screen prompts to set up your security key.
- You are now set up for DUO MFA using a security key.
Adding Additional Devices / Settings
You can associate multiple devices/phones with your DUO MFA account. To add additional devices:
- Access the DUO Security login screen by visiting any JCU site that requires Duo (i.e. banner.jcu.edu or canvas.jcu.edu)
- You may need to close and reopen your browser or use a Private Browser window (incognito).
- On the Duo Security Login screen, ask the client to select the Other Options option, then the Manage Devices option.
- You will be asked to perform a normal Duo Authentication to confirm your identity.
- If you don't have your old device please call the Service Desk to obtain a by-pass code.
- Click the Add a Device button and follow the onscreen prompts.
You can also adjust your DUO account settings, including renaming devices and changing login priorities and preferences:
- Follow steps 1 through 3 above
- Click the Edit button on the device you wish to update.
**An Important Warning!**
If you ever receive a DUO MFA approval request that you didn't initiate, press "DENY" and contact the ITS Service Desk. This could be an unauthorizd login attempt.