
Why 2fa Matters
In an age where cyber threats and credential theft are becoming increasingly sophisticated, relying on passwords alone is no longer sufficient to protect sensitive personal and institutional data. Two-factor authentication (2FA) introduces a crucial second layer of defense by requiring an additional step to verify your identity before granting access to your account.
At Carnegie Mellon University, 2fa is fundamental to maintaining our cybersecurity posture. However, the advantages of multi-factor verification extend well beyond campus, making it an essential practice for all your personal online accounts.
How 2fa Works at CMU
Whenever students, faculty, or staff sign into CMU login protected services such as Google Workspace, Canvas, or Workday, they are prompted to authenticate using 2fa with DUO.
To streamline the day-to-day login experience while preserving security, DUO includes a "Remember me for 30 days" option on trusted personal devices, preventing constant prompts while keeping unauthorized users out.
Staying Safe: Best Practices for CMU 2fa
While 2fa greatly enhances security, attackers occasionally attempt to bypass it using sophisticated social engineering or phishing scams. To ensure your account remains safe:
- Verify the Login Page URL: Always verify that any authentication page requesting your Andrew credentials begins with login.cmu.edu or login.microsoftonline.com/ before signing in.
- Be Wary of Suspicious Prompts: If you receive a DUO Push notification when you are not actively trying to log in, tap Deny immediately.
- Report Missing Push Options: Phishing sites masquerading as DUO often lack the option to send a push notification and only request passcodes. Report any suspicious pages directly to the Information Security Office.
- Register a Secondary Device: Set up a tablet, backup phone, or enable DUO Instant Restore so you don't lose access if your primary mobile device is replaced or lost.
Extending 2fa to Your Personal Digital Life
Cybercriminals frequently target personal email, banking, social media, and shopping accounts. Extending 2fa beyond campus dramatically lowers your risk of account compromise across all platforms.
Consider these four main 2fa options for your personal digital life:
- Authenticator Apps (Recommended): Apps like Google Authenticator, Microsoft Authenticator, 1Password, or DUO Mobile generate timed, single-use passcodes (TOTP) directly on your device.
- Why use it: Works offline, isn't vulnerable to SIM-swapping attacks, and is supported by almost all major platforms (Google, Apple, Amazon, social media).
- Passkeys and Biometrics: Passkeys use native biometric authenticators such as Apple Touch ID/Face ID, Windows Hello, or Android Biometrics for seamless cryptographic logins.
- Why use it: Fast, highly phishing-resistant, and removes the burden of remembering traditional passwords.
- Hardware Security Keys (FIDO2 / WebAuthn): Physical USB or NFC keys—such as a YubiKey or Google Titan Key—require you to insert or tap the key to confirm your identity.
- Why use it: Offers the highest tier of protection against remote phishing and hardware tampering, making it ideal for securing primary email or financial accounts.
- Text Message (SMS) or Email Verification: Verification codes sent via SMS text message or secondary email upon signing in.
- Why use it: While less secure than authenticator apps or passkeys due to SIM-swapping risks, SMS-based 2fa is still significantly safer than using a password alone.
2fa & Security Resources at CMU
2fa Self-Service Tool
Manage registered devices, set up new phones, or adjust preferences.
Safe Computing Portal
Review university cybersecurity best practices and training guides.
Computing Services Help Center
Get assistance with account lockouts, DUO registration, or IT issues.