MFA Enrollment & Management

Enrollment and Duo Device Management

Enrollment is the process of establishing your additional factor for authentication. Typically, you will only need to complete this once. However, you may need to re-enroll if you change your phone or begin using another MFA device. The first time you log in, Duo will start your enrollment process.

Learn more about Duo enrollment

Manage Your Duo Devices

Use the Duo Device Management page to enroll a new device, reactivate Duo Mobile after getting a new phone, or review and manage your available sign-in methods.

To access the Duo Device Management page, you must sign in using an available anti-phish method such as Verified Duo Push with Bluetooth Autofill or Platform Authentication.

If you need a bypass code or cannot sign in to manage your devices, contact the Service Desk for assistance.

Open the Duo Device Management Page

Learn more about adding or managing devices

Contact the IT Service Desk by phone at 619-209-4357 (HELP) during normal business hours
(7:00am - 5:00pm, Monday - Friday).

Supported Sign-In Methods

1. Duo Mobile App

Duo Mobile is the recommended option because it supports the most sign-in methods. It is an app installed on supported iOS or Android smartphones and tablets, including Wi-Fi-only devices.

Duo Mobile can also generate passcodes even when the device has no internet connection or cellular service.

Verified Duo Push with Bluetooth Autofill (anti-phish)

This is a feature inside the Duo Mobile app. When available, it helps confirm that the sign-in is coming from your nearby device. If Bluetooth Autofill is not available or permission was not allowed, you can still complete the sign-in by manually entering the code shown on the screen.

Requirements: Duo Mobile on a supported mobile device, Duo Desktop on the computer you are signing in from, Bluetooth turned on, and nearby device or Bluetooth permission allowed when prompted.

Learn more about Verified Duo Push with Bluetooth Autofill

Duo Mobile passcode

Duo Mobile can also be used to generate a passcode that you type in manually during sign-in.

Use caution when entering codes manually. Code-based methods are more phishable because attackers may try to trick you into typing your code into a fake sign-in page or giving it to them directly.

Learn more about Duo Mobile passcode

2. Platform Authentication (anti-phish)

Platform Authentication uses security features already built into the device you are using. It does not require an app.

Supported methods include Windows Hello, Touch ID, Face ID, and Android biometrics.

If you want to use Platform Authentication on more than one device, you will need to enroll each device separately. 

Windows Hello support for staff devices is coming soon.

3. SMS Text Message

A passcode can be sent to your mobile phone by text message. No app is required.

This is supported, but it is slower and less secure than Duo Mobile or Platform Authentication.

Important caution for text message codes

SMS passcodes are a code-based method and are more phishable.

Be careful when manually entering texted codes. Attackers may try to trick you into typing the code into a fake sign-in page or sharing it with them.

Learn more about SMS passcode

4. Bypass Code

If you lose access to your normal MFA method because your phone was lost, replaced, unavailable, or not yet reactivated, the Service Desk may be able to provide a one-time bypass code to help you sign in.

Bypass codes are temporary and one-time use.

Important caution for bypass codes

Bypass codes are a code-based recovery method and are more phishable.

Be very careful when using a bypass code. Never enter it into an unexpected page and never share it with anyone.

Learn more about bypass code

Recommended Order

For the best experience, use these methods in this order when available:

  1. Verified Duo Push with Bluetooth Autofill and Platform Authentication as equal first-choice anti-phish options
  2. Duo Mobile passcode
  3. SMS text message
  4. Bypass code when recovering access

General Reminders

Only approve a sign-in you started yourself.

Be extra careful with any code-based sign-in method. Manually entered codes are more phishable because attackers may try to trick you into entering them into a fake sign-in page or sharing them directly.

Verified Duo Push with Bluetooth Autofill and Platform Authentication are stronger options because they are more closely tied to the device you are actively using.

On supported web sign-ins, Duo may remember a successful sign-in for up to 12 hours in a browser session, although that can vary depending on device, network, browser, and other risk conditions.

Questions and Answers

What is the difference between enrollment and device management?
Enrollment is the first time you set up MFA. Device management is what you use later to add a device, reactivate Duo Mobile, review your methods, or remove an old device.
Can I use any sign-in method to access the Duo Device Management page?
No. The Duo Device Management page should be accessed using an available anti-phish method such as Verified Duo Push with Bluetooth Autofill or Platform Authentication. If you cannot sign in, contact the Service Desk for help.
Is Verified Duo Push with Bluetooth Autofill part of the Duo app?
Yes. It is a feature inside the Duo Mobile app and works with Duo Desktop on the computer you are signing in from.
What is the difference between Verified Duo Push with Bluetooth Autofill and Duo Mobile passcode?
Verified Duo Push with Bluetooth Autofill is the stronger option because it helps confirm the sign-in is coming from your nearby device. Duo Mobile passcode is a code you type in manually and is more phishable.
What if Bluetooth Autofill does not work?
You can still sign in by manually entering the code shown on the screen into the Duo Mobile app. Because this is a manual code entry method, be cautious and make sure you are signing in to a page you trust.
Can Duo Mobile work on a tablet or a device without cell service?
Yes. Duo Mobile works on supported smartphones and tablets, including Wi-Fi-only devices. The app can also generate passcodes without internet or cellular service.
Do I need an app for Platform Authentication?
No. Platform Authentication uses security features already built into your device, such as Windows Hello, Touch ID, Face ID, or Android biometrics.
Do I need to set up Platform Authentication on every device?
Yes. Each device must be enrolled separately if you want to use Platform Authentication on that device.
Do I need an app for text message sign-in?
No. SMS text messaging does not require an app.
What should I do if I get a new phone?
Go to the Duo Device Management page and reactivate Duo Mobile or add your new device. If you cannot sign in, contact the Service Desk for help.
What if I changed carriers and text messages stopped working?
If text messages stop working after a carrier change or number port, wait for the carrier update to finish. Number ports can sometimes delay texting for up to 24 hours. If it still does not work after that, contact the Service Desk so your phone record can be refreshed if needed.
What if I accidentally replied STOP to Duo text messages?
Try texting START, YES, or UNSTOP to 386732, then request a new code. If that does not work, contact the Service Desk.
Can I still use Duo if my phone has no service?
Yes. If you are using Duo Mobile, the app can still generate passcodes without internet or cellular service. If you have already enrolled Platform Authentication on the device you are using, that method also does not depend on your phone having cellular service.