Carnegie Mellon University

How to Use Two-Factor Authentication

Two-factor authentication (2fa) provides an extra layer of security to protect your identity and university data. At Carnegie Mellon University, we use the DUO app. When you enroll in 2fa and attempt to log in with CMU Web Login, you'll receive a prompt from DUO on your smartphone, tablet or hardware token to approve the login. This takes security beyond your username and password by verifying with CMU's servers that you are who you say you are.

Use the buttons below to find the information you need. And if you're still stuck, review our FAQ.


Register to Use 2fa for the First Time

If you have never used 2fa, you will need to register. Follow the steps below to register with a mobile device. 

Before you begin registration, make sure you have the following on hand:

  • Your mobile device (smartphone or tablet) and a computer.
  • Your Andrew userID and password.
  • Your CMU ID card number OR your personal email address on file with the university if a card has not been issued.

Download and install the DUO Mobile app on your smartphone or tablet.


iOS
Android

On your computer or other device:

  1. Visit the Two-Factor Authentication Self-Service (2fa) Tool.
  2. Log in with your Andrew userID and password.
  3. Click Register to Use 2fa.
  4. Select Mobile Device and click Continue. You must have the device with you to complete the enrollment process.
  5. Follow the prompts to proceed.
  6. Click I have DUO Mobile installed. A QR code will display on your screen.

On your smartphone or tablet:

  1. Open DUO Mobile.
  2. Tap the plus (+).
  3. Hold your tablet or smartphone up to your computer to scan the QR code that displayed in step 3.
  4. Carnegie Mellon University will appear in the DUO app with the text DUO-PROTECTED.

On your computer:

  1. A green checkmark will appear on your QR code.
  2. Click Continue. You will receive a message that your enrollment was successful!

Pro Tip: Before you leave the Two-Factor Authentication Self-Service Tool, add a secondary device to help ensure you don’t get locked out if you lose your primary device.


Use Your Registered Device with 2fa

Once you've registered a device for 2fa, you'll be prompted to approve your log in whenever you attempt to access CMU systems or services. You'll want to keep your registered device with you to use with 2fa.

Note: When you first authenticate, DUO automatically selects the most-secure authentication method that you have configured. If you want to authenticate using another option, click or tap Other options. DUO will use the method that you choose for future login attempts.

  1. The DUO mobile app will send a push notification to your mobile device.
  2. Tap Approve on your mobile device.

Use Touch ID on your MacBook Pro, MacBook Air, or Magic Keyboard with a Touch ID button.

Note: Touch ID is only compatible with Google Chrome in normal browser windows. DUO may not offer Touch ID in Incognito mode

  1. Open the DUO app on your mobile device.
  2. Find your Carnegie Mellon University account and click Show.
  3. Enter the passcode into the DUO prompt on your computer and click Verify.
  1. Press the button on the token to generate a one-time passcode.
  2. Enter the passcode into the DUO prompt on your computer.
  3. Click Verify.

Tap your U2F token (Yubikey) to send approval.

 

After you authenticate, Duo will ask whether or note to trust your browser. If you choose to trust the browser, you can skip 2fa when you log in again with the same browser and device for the next 30 days.

To enable a trusted browser session:

  1. Log in to any service protected by CMU Web Login with your Andrew userID and password.
  2. Authenticate with Duo when prompted.
  3. Click or tap Yes, this is my device.

If you are using a shared device, click or tap No, other people use this device.


Update Your 2fa Device

When Should I Update?

Update your existing device for 2fa if you:

  • Purchased a new smartphone with the same phone number.of 2fa.
  • Have performed a factory reset on your phone and need to reconnect to 2fa.

Note: You may not currently register a new smartphone with a new phone number using the Two-Factor Authentication Self-Service (2fa) Tool unless you registered a secondary device. Learn more.

How to Update Your 2fa Device

  1. Visit the Two-Factor Authentication Self-Service (2fa) Tool.
  2. Log in with your Andrew userID and password.
  3. Click Add a new device to 2fa.
  4. Follow the prompts to complete the update.

Have an iOS device? Use Instant Restore to update registration.

 


Manage Your Devices

If you have already registered a primary device for 2fa, follow these steps to add a secondary device, manage device preferences, remove a device, or change a device name.

  1. Visit the Two-Factor Authentication Self-Service (2fa) Tool.
  2. Log in with your Andrew userID and password.
  3. Click Manage Devices.
  4. Authenticate with DUO using your preferred method.
  5. Perform the following actions as desired:

To add a secondary device:

  1. Click + Add another device.

To remove a device:

  1. Click Device Options (or the gear icon on mobile).
  2. Click the trash can to the right of the device to be removed.

To change a device name:

  1. Click Device Options (or the gear icon on mobile).
  2. Click Change Device Name.
  3. Type a new name for your device.
  4. Click Save.

Frequently Asked Questions

Review the topics below for answers to common questions related to 2fa.

If you already registered to use 2fa and need to add a new smartphone, follow the instructions below. If this is your first time using 2fa, review Register to Use 2fa.

I have a new smartphone with the same phone number:

I have a new smartphone with a new phone number:

  • Review Manage Your Devices and add a new device. You may only use this option if you registered a secondary device (tablet, hardware token, or Yubikey) that you can use to authenticate instead of your old smartphone.
  • If you did not register a secondary device, contact the Computing Services Help Center to register your new smartphone.

DUO will lock you out after several consecutive failed authentication attempts. You may see the following error messages:

  • Account disabled: Your Duo account is disabled and cannot access this application. Please contact your IT help desk.
  • Your two-factor account is disabled. Contact an administrator for assistance.

To reactivate your account, visit the Two-Factor Authentication Self-Service (2fa) Tool and log in.

If you have an active personal email address associated with your account, DUO will automatically begin the unlock process. If you don’t have a personal email address associated with your account, contact the Computing Services Help Center.

Yes! You can generate a numeric passcode even if your device does not have any network connection.

Yes! We encourage you to register multiple devices. To learn how, review Manage Your Devices.

Yes! 

  • Students, faculty, and staff can purchase a Yubikey, a device that can connect to DUO and provide you with a secure passcode for 2fa.
  • Faculty and staff can request a Hard Token from the Computing Services Help Center by emailing it-help@cmu.edu.

Faculty and staff can request a Hard Token from the Help Center. Once you receive your hard token:

  1. Visit the Two-Factor Authentication Self-Service (2fa) Tool.
  2. Log in with your Andrew userID and password.
  3. Click Register DUO Hardware Token.
  4. Enter the serial number from the back of the token.
  5. Click Submit.
  6. Follow the prompts to continue with the registration and click Submit.

Campus affiliates (students, faculty, and staff) can purchase a Yubikey, a device that can connect to DUO, and provide you with a secure passcode for 2fa. Once you have your Yubikey in hand:

  1. Visit the Two-Factor Authentication Self-Service (2fa) Tool.
  2. Log in with your Andrew userID and password.
  3. Click Register a Device.
  4. Select Yubikey and click Continue. You must have the device with you to complete the enrollment process.
  5. Follow the prompts to proceed.

A hardware token may become "out of sync" if the button is pressed too many times and the generated passcodes aren't used. Go to the Two-Factor Authentication Self-Service (2fa) Tool, click RESYNC Hardware Token and follow the onscreen instructions.

Enable a Trusted Browser Session the next time you use DUO.

You may have lost your network connection. If so, you may still authenticate by generating a numeric passcode.

Alternatively, you may have disabled push notifications for DUO.

  1. Visit Two-Factor Authentication Self-Service (2fa) tool.
  2. Click Manage Devices.
  3. Verify Ask me to choose an authentication method is selected.
  4. If this still does not resolve the issue, check your mobile device settings below.
  1. Tap Settings > Notifications > DUO Mobile.
  2. Verify the Allow Notifications option is enabled.
  1. Tap Settings > Apps & notifications > DUO Mobile.
  2. Verify the Notifications are set to on.

Contact the Computing Services Help Center immediately if you lose your phone or suspect that it's been stolen. A Help Center consultant will disable your device for 2fa and help you log in using another device.

CMU uses the DUO Security  app to support services using Single Sign-On (SSO) with CMU Web Login. Some examples of services that use CMU Web Login with 2fa include Box, LinkedIn Learning, Workday, SIO/S3, Sparcs, Google for Education apps, Canvas, and Zoom.

Note: CMU also uses DUO Security for 2fa with some services that don't require Web Login (including VPN, Citrix, and Campus Cloud). 

All students, faculty, staff, alumni, and sponsored accounts must be enrolled in 2fa. You will not be able to opt-out of this service.