Duo Security Two-Step Login
Two-Step Login is used to protect your account, even if your password is stolen.
- On This Page
- Set Up Duo
- What is Duo?
- FAQs
Using Duo
The recommended method is to setup up Duo Mobile on a smart phone to receive push notifications.
A push notification is a message that pops up on your smart phone and allows you to approve the login and finish the authentication process into a protected system, or deny the login if you suspect it is fraudulent.
You can add multiple devices into Duo, such as a tablet or another mobile device that can also be used to approve Duo authentication. You can add and remove devices in Duo and also reactivate Duo when you get a new device.
The Duo Verified Push notification will ask you to enter a number displayed on your screen instead of simply authorizing the login with a single click. This is designed to stop MFA fatigue attacks, where users mistakenly authorize fraudulent logons.
It's important to be mindful of the devices you are using to ensure that they remain up to date with the most recent version of Duo that's available. Older devices may experience issues with Duo, such as not being able to activate the Duo Mobile app or not being able to receive Duo Push notifications that need to be verified and approved.
Verified Duo Push requires:
- Duo Mobile 4.16.0 or later on Android 8 or later.
- Duo Mobile 4.17.0 or later on iOS 13 or later.
What is the Purpose of 2-Step Login?
After entering your password into a system (step 1) that is protected by Duo, you will be prompted to approve the login using another device (step 2).
2-Step Login adds an extra layer of security. Even if someone has your password, they will not be able to get into a system that requires Duo. No one can get into the system unless the login is approved with Duo.
Duo will challenge users during the login process if they are registered Duo-user and the service is protected by Duo:
RDP Gateway Connections
Stony Brook's VPN
VPN
SeaWulf
LastPass Enterprise
Single Sign-On
Virtual SINC Site
Save your DUO authentication in your personal device for 7 days so you don't need to DUO authenticate as frequently.
Frequently Asked Questions
Yes, Duo Mobile can generate passcodes locally, without requiring network connectivity.
Using a Duo App Passcode for Two-step Login When Your Device Does Not Have Internet or Cell Service
Yes, Duo does work in China. Apple devices will work without issue, whereas for Android devices the app will need to be installed directly from Duo's website. More info is available here.