Duo Multi-Factor Authentication - Setup and Device Management

Summary

KU uses Duo for multi-factor authentication (MFA) for systems behind KU Single Sign On (SSO), such as: Canvas, Enroll and Pay, and HR Pay. All students, current employees, faculty, and retired and emeritus staff are required to enroll in Duo to access these systems.

Those required to use Duo include:

  1. Employees

    • New employees will not be granted access to Duo until their official start day.

    • If access isn't granted on the first day, this can be due to a delay in the system.

    • Contact the IT Help Desk for Duo related issues.

  2. Retired and Emeritus Staff

    • Duo will be used for authentication indefinitely.

  3. Students

    • Once students enroll in classes, they will receive a message giving them 14 days to enroll in Duo.

Those who are excluded from using Duo are:

  1. Parents & Guardians

  2. Graduated students

  • Students who have graduated will no longer use Duo.

  • For more information, refer to: Leaving KU? 

Prerequisites

  1. Ensure your mobile device is compatible with Duo mobile.

  • Android - Duo article that specifies which version of Android Duo Mobile supports.

  • iOS/iPadOS - Duo article that specifies which version of Android Duo Mobile supports.

Reference Items

  1. Duo Access Denied

  • Duo article explaining why IP addresses originating from certain countries are blocked from authentication and includes list of restricted countries.

  1. Enroll & Pay

  • Delegate access login page.

  1. IT Help Desk Contact Information

    • Includes the IT Help Desk's phone number, email, business hours, and address.

  2. My Identity Page

  • Login page for your KU Online ID and Password.

  1. Leaving KU

  • Article includes information what happens to your email and other accounts after you leave the university, and the steps you should take before you go.

  1. Web Browser - Troubleshooting Tips for Desktops and Laptops

  • Article features instructions for opening an incognito/pivate browsing window for Chrome, Edge, Firefox, and Safari mobile web browsers.

  1. Web Browser - Troubleshooting Tips for Mobile Devices

    • Article features instructions for enabling third-party cookies for Chrome, Edge, Firefox, and Safari mobile web browsers.

    • Article features instructions for opening an incognito/pivate browsing window for Chrome, Edge, Firefox, and Safari mobile web browsers.

Before You Begin

It's recommended to use a computer to complete the following steps. Make sure you're on the KU Single Sign‑On (SSO) page via an incognito/private browsing window. After entering your KU Online ID and password, you will be prompted with the Duo MFA screens referenced in this article.

  • If you are unsure how to open an incognito/private browsing window, follow the instructions in article "Web Browser - Troubleshooting Tips for Desktops and Laptops," section "Open a Private Browser Window," and select the appropriate subsection for the web browser of your choice. 

Initial Setup - Mobile Device with Duo Mobile App

You will need to ensure your mobile device is compatible with Duo mobile as specified in the Android and iOS articles. 

If you are unsure what operating system (OS) version your phone has, follow the instructions for the appropriate phone OS below.

For Android phones, open: Settings, then find and open the About Phone category, and scroll down to find Android version or Software Information to find your OS version.

  • Note: The appearance and organization of Android phone settings vary by manufacturer’s OS. These instructions are a general guideline for finding OS version information on two common Android devices. If you have a different device, they should guide you to where you can find your version.

For iPhones or iPads, open the Settings application and select General. Then select About and the look for the Software Version.

Once the system is ready for you to enroll in Duo, you will be prompted to go through the process below to set it up. After your Duo account is setup, you will no longer be able to sign in to KU Single Sign-On, VPN, or other KU services without using Duo to complete your authentication request.

Enroll in Duo

After following the steps within section "Before You Begin" above, perform the following:

  1. Log in to: My Identity Page via an incognito/private browsing window with your KU Online ID and password, confirm Single Sign-On if prompted.

  2. You should then see the Duo welcome screen below. Click: Get Started.

    Screenshot of step 2 above.

  3. Select the type of device you will use with Duo. KU IT recommends using a cell phone with the Duo Mobile application and the instructions in step 4 and continuing will explain how to add a cell phone. The following options are also available for multifactor authentication:

    1. A cell phone without the Duo Mobile app installed and using phone calls or text message passcodes to authenticate.

    2. A landline or cell phone to authenticate via phone call.

    3. A tablet with Duo mobile and an active internet connection.

    4. If you will be using a hardware token, one must be assigned by the IT Help Desk. Follow the steps in section "Initial Setup - Other Supported Authentication Methods" sub-section "Hardware Tokens Provided by KU IT" below.

    5. If you have a security key device, you can follow the steps in section "Initial Setup - Other Supported Authentication Methods" sub-section "Security Key" below to add it as your Duo device. 

Screenshot of step 3 above.

  1. Enter your mobile phone number, and tap: Continue.

    Screenshot of step 4 above.                                     

  2. Verify you typed the number correctly. Tap: Yes, it's correct if it's correct or No, I need to change it, if you need to retype it.

    Screenshot of step 5 above.

  3. Download the Duo Mobile application to your mobile phone through your device's application store (App Store on iOS devices or Google Play store on Android devices). Once the app is installed, tap: Next.

    Screenshot of step 6 above.

  4. Activate the phone by either scanning the QR code through the Duo Mobile application or by sending an activation link by email.

    Screenshot of step 7 above.

    • To activate using the QR code, open the Duo application on your phone and tap the Add + icon in the upper right. You will need to provide the Duo Mobile application permission to use your device's camera. Then scan the QR code on the screen.

    • If you activate via a link, follow the steps in the prompts.

  5. After adding the Duo account to the application, your screen should show the image below. Click: Continue.

    Screenshot of step 8 above with message saying Added Duo Mobile. You can now use Duo Mobile to log in using a push notification sent to your mobile device. Since you added a phone number, you can also use text messages and phone calls.

  6. Click: I don't want to add more devices, unless you have a physical security key device that you'd also like to set up. 

    • If you need to set up a physical device, follow the steps in section "Initial Setup - Other Supported Authentication Methods" sub-section "U2F Device" below.

Screenshot of step 9 above.

  1. Tap: Log in with Duo to log in to the KU website where you began.

    Screenshot of step 10 above.

You will now be prompted to authenticate with Duo authentication whenever you sign into your KU account. Single sign-on has the option Remember Me for 30 Days, so that you only have to use Duo once every 30 days in that particular browser. When connecting to the VPN, you will need to use Duo authentication every time.

Methods for Authentication

Log in with your KU Online ID and password to Single Sign-On if prompted by any of the following means:

  1. Push - This will send a notification to your phone. You can approve the push directly from your notification window or you can open the Duo Mobile application to approve the push. 

  2. Passcode - This method is applicable for both the Duo Mobile application and the Duo hardware token. Type the passcode from your device in the Passcode field. Do not include any spaces when typing the passcode; the spaces between numbers in the application and on the token are only for readability.

    • When using a token, press the button on your Duo hardware token to retrieve a code. You will need to click Verify before the countdown indicator on the token (located to the left of the first number on the token screen) reaches the bottom. Once the countdown is complete, the token screen goes blank and the code retrieved is no longer valid.

    • When using the Duo mobile application, open the application on your phone and tap Show on the KU account to view your passcode. This code will be valid for 30 seconds. 

  3. Text Message - Passcode - This method initiates the sending of a text message to the default phone on your account. Open your text message to view the passcode. Enter the passcode from the text message in the Passcode field, then click Verify.

    • Note: This is a one-time use passcode and will only be valid for 30 minutes.

  4. Phone Call -  This method initiates a phone call to the default phone on your account. Answer the call coming from Duo. Listen to the voice message and select the number the message indicates is for approval.

    • This option is available only for employees and retirees, not students.

Initial Setup - Other Supported Authentication Methods

Once you have enrolled a device with Duo and you have it available for authentication process you may add additional devices as means for authentication, such as additional phones, hardware tokens, etc.

Additional Devices

  1. Log in to: My Identity Page via an incognito/private browsing window with your KU Online ID and password, confirm Single Sign-On if prompted.

  2. Click: Other Options.

    Screenshot of step 2 above.

  3. Click: Manage devices toward the bottom of options.

    Screenshot of step 3 above.

  4. Authenticate with Duo using your existing device.

    Screenshot of list of methods for verifying your identity.

    • After successfully authenticating with Duo, you will be redirected to your Duo devices page.

  5. Select: Add a device.

    Screenshot of step 5 above.

  6. Select what type of device you are adding and follow the prompts. See the appropriate panel within this article for further steps on adding your device.

    • For steps on adding an international phone, see "International Travel and Phone Number Support" panel below.

Hardware Tokens Provided by KU IT

Duo tokens are available to KU students, faculty, and staff. Token's can be picked up on campus at the IT Help Desk. You will need to bring a government issued photo ID with you.

Accounts are prohibited from having more than one token assigned at any given time. If you have lost your token, it will be replaced at no charge. Your old token will no longer work even if its found and returned to KU IT.

Security Key

KU IT supports several standards for authentication security keys for KU applications protected by Duo Multifactor Authentication (MFA). If you own a security key device such as Yubikey or iCloud Keychain, you can register it as an MFA option to associate with your account and cannot be shared with other users. Your security key method will work on any computer where you can log in with your KU Online ID and password. The instructions for how to register it are below.

  • Note: Yubikeys and other security key devices are supported on a best-effort or bring-your-own service basis. 

  1. Log in to: My Identity Page via an incognito/private browsing window with your KU Online ID and password, confirm Single Sign-On if prompted.

    • Important: You must use a Chromium-based web browser to add or use security key devices. If your browser is not compatible, the choice will be unavailable.                    

  2. On the Duo screen, click: Other Options rather than performing your Duo authentication.

Screenshot of step 2 above.

  1. Click: Manage devices at the bottom.

    Screenshot of step 3 above.

  2. Authenticate with Duo using your existing device.

    Screenshot of step 4 above.

    • After successfully authenticating with Duo, you will be redirected to your Duo devices page.

  3. Select: Add a device.
    Screenshot of step 5 above.

  4. Select: the Security key option.

    Screenshot of step 6 above.

  5. Click: Continue.

    Screenshot of step 7 above.

  6. Windows Security will prompt you to setup the key. Select an option then click: Next. If Security key is selected, go to step 11. Otherwise, continue to step 9.

    Screenshot of step 8 above.

  7. If iPhone, iPad or Android device is selected, scan: the QR code with your device.

    Screenshot of step 9 above.

  8. You should see a message as shown below that you can now use your device to sign in with Duo.

    Screenshot of step 10 above.

  9. If Security Key is selected, insert your security key device into a USB port on your computer.

    • It should flash when inserted. If the device does not flash, remove it from the USB port and re-insert it.

    • Note: It is best practice to pinch the USB device carefully from the top and bottom to avoid damaging the USB device or port when inserting or re-inserting the device.

  10. Place your finger on the security key device's flashing key icon when prompted. This should register as an accepted authentication.

  11. Click: Continue and the security key will be added to your Duo devices page.

    Screenshot of step 13 above.

The next time you login to a KU website, it should automatically request authentication using the security key device. When prompted, insert the security key device and touch the blinking key to authenticate Duo and this will let you login with MFA.

Multiple KU Accounts

Users with multiple KU accounts, such as an admin account, also called "underscore A account" due to the format for the username being j123h456_a, must use Duo authentication for both accounts. You can use the same phone number and devices across multiple accounts, but you will need to log in to KU Single Sign-On (SSO) individually for every account you are required with which to use Duo, including admin accounts, in order to start the enrollment process. The instructions and screenshots below assume the secondary account is an admin account, but they are applicable to any account that uses SSO and Duo authentication.

Adding a Secondary Account

Admin accounts must begin the process by signing in to MyIdentity and then clicking on View Profile. As with your initial enrollment in section "Initial Setup - Mobile Device with Duo Mobile App" section above, you will not be able to set up Duo with your admin account until it has been added to the multifactor authentication group. Once you are active in that group, the Duo enrollment will start automatically once you sign in.

If you are using the same phone number to enroll in Duo with both your admin account and your main KU account, enrollment may deviate after you enter your phone number. Instead of being asked to scan the phone number, you will be prompted to verify your phone number.

  1. Click: Call Me or Text Me to get a six-digit verification code.

    Image of step 2 above.
  2. Check your text messages or answer the phone call to get the six-digit code. Type in the code, then click: Verify.

Screenshot of step 2 above.

  1. Click: Continue to finish.

This will complete the enrollment process and connect your phone number to your admin account.

Managing Multiple Accounts in Duo Mobile Application

You generally don’t need to interact with the account via the Duo Mobile app if you use push notifications. Once approved, the login process continues. However, if you want to use a mobile passcode, note that both accounts have the same name: KU. This may not be the case if you set up your accounts in Duo Mobile after the October 2021 UI change, which prompted users to set up accounts with a custom name.

As a solution, you can rename the accounts to distinguish between the two. The process is the same on Android and iOS devices, with minor differences in the UI.

  1. Click: the three dots located in the upper right corner of the account card.

    Screenshot of step 1 above.
  2. Select: Rename.
    Screenshot of step 2 above.

  3. Enter the new name for your Duo account. This name will only impact the device you're on; it doesn't change the account name on other Duo devices you may have connected to your KU account. Then select: Save.

    Screenshot of step 3 above.

Viewing Push Notification Details

To view the details of a push notification to determine its source, click the notification as it comes in. You can also view these details by opening the Duo Mobile application — when a request is pending, you will see the full request automatically, or by clicking: (1) Login request waiting at the top of the application.

Push details will include:

  1. Whether the push came from SSO, also called CAS, or from the KU Anywhere VPN.

  2. The account used to send the push notification.

  3. The IP address and location of the request.

  4. The date and time of the login request.

Support for International Travel and Phone Numbers

Important: Users who are traveling abroad to a country where Duo is restricted will not be able to access KU resources until they leave the restricted country. You can see a list of countries within Duo's article: Duo Access Denied. This article assumes you have a device already enrolled with Duo and you have it available with which to authenticate.

If you have previously selected the This is my device option, you must clear your cache and cookies or use incognito/private browsing.

Activating International Number

  1. Log in to: My Identity Page via an incognito/private browsing window with your KU Online ID and password, confirm Single Sign-On if prompted.

  2. On the Duo screen, click: Other Options rather than performing your Duo authentication.

    Screenshot of step 2 above.

  3. Click: Manage devices at the bottom.

    Screenshot of step 3 above.

  4. Authenticate with Duo using your existing device.

    Screenshot of step 4 above.  

    • After successfully authenticating with Duo, you will be redirected to your Duo devices page                                                               

  5. Select: Add a device.

    Screenshot of step 5 above.

  6. Select: Phone number.

    Screenshot of step 6 above.

  7. Select your country code from the scrollable drop-down on the left, then enter your phone number in the text field to the right. 

    Screenshot of step 7 above.

  8. Click: Continue to add the number.

    Screenshot of step 8 above.

Signing in with Alternate Number

These instructions will outline how to sign in with alternate phone numbers. When you return from your travels you will need to follow these steps again.

  1. When you get the Duo prompt page you need to select: Other Options

    Screenshot of step 1 above.

  2. Then you can select the number you wish to authenticate with or choose the method and correct phone number from the list.

    Screenshot of step 2 above.

Troubleshooting and Support for Common Issues

The subsections below provide instructions for the most common issues and errors users can experience when trying to unable to authenticate with Duo and their workarounds. If you are still unable to solve the issue after attempting the workaround, please contact the KU IT Help Desk.

This article assumes you have a device already enrolled with Duo and you have it available with which to authenticate.

If you have previously selected the This is my device option, you must clear your cache and cookies or use incognito/private browsing.

403 Forbidden Error Message

If you receive the error below after entering your credentials and are awaiting Duo authentication when attempting to sign in to any KU service, check your system clock settings.
Screenshot of 403 Forbidden Error Message box referenced above.

For Mac:

  1. Click on the Apple icon in the top left and select: System Settings.
    Screenshot of step 1 above.

  2. Click: General, then click: Date & Time.

    Screenshot of step 2 above.

  3. Ensure the time zone is set to Central Time if in Lawrence or the appropriate time zone based on your location. You can also turn on the Set time zone automatically using your current location option.

    Screenshot of step 3 above.

For Windows:

  1. Click on the Windows icon and select: Settings.

    Screenshot of step 1 above.

  2. Click: on Time & language, then click: Date & Time.

    Screenshot of step 2 above.

  1. Ensure the time zone is set to Central Time if in Lawrence or the appropriate time zone based on your location. You can also turn on the Set time zone automatically option.
    Screenshot of step 3 above.

Corrupted Font on Mac

When completing Duo authentication, you may see a screen similar to the one below. This is likely the result of corrupted fonts on your Mac. To resolve this issue, follow the steps below.

During Duo authentication, if you receive a window with symbols instead of text, it may be a result of corrupted fonts on your Mac.

  1. On your Mac, go to Apps and search: Font Book and select the application to open it.

    Screenshot of step 1 above.
    Screenshot of step 1 above.

  2. Click: Font Book in the upper left hand corner and select: Settings from the dropdown menu.

    Screenshot of step 2 above.

  3. Click: Advanced, then click: Reset Fonts.

    Screenshot of step 3 above.

  4. Click: Proceed to confirm, and enter your password if asked.

Screenshot of step 4 above.

Device Was Replaced, Lost, or Stolen

If for any reason you are unable to access your device to complete your login attempt, please contact the IT Help Desk to request a bypass code. You will be required to provide a government-issued ID. The bypass code is valid for either five uses or four hours, whichever comes first. If you have not yet obtained a replacement mobile device, a longterm solution may be to use a hardware token. Refer to section "Initial Setup - Alternative Authentication Methods" subsection "Hardware Tokens Provided by KU IT" above for more information.

Prompt Not Received

If the Duo Prompt does not display in Safari on iOS, try the following:

  1. Clear cookies, cache, and other website data:

  2. Ensure that Safari is configured to accept cookies from Duo:

  3. Disable content restrictions. Refer to the instructions for your iOS version in this article.

Reactivate Duo Mobile

If you have upgraded/replaced the phone you were using with Duo but have the same phone number, you can activate Duo Mobile on the new device with the following steps.

  1. Log in to: My Identity Page via an incognito/private browsing window with your KU Online ID and password, confirm Single Sign-On if prompted.

  2. On the Duo screen, click: Other Options rather than performing your Duo authentication.

    Screenshot of step 2 above.

  3. Click: Manage devices at the bottom of the list.

    Screenshot of step 3 above.

  4. Authenticate with Duo using your existing device. You must use a text message passcode or phone call to authenticate at this step.

  • After successful authentication with Duo, you will be redirected to your Duo devices page.

Screenshot of step 4 above.

  1. Click: I have a new phone under your previous Duo device.

  • If you don't have a Duo device or if your new phone uses a different number than your current Duo device listed on the device page, please follow the steps in the "Initial Setup - Alternative Authentication Methods" section of this article to add the new device.

Screenshot of step 5 above.

  1. Click: Get Started.

    Screenshot of step 6 above.

  2. Download the Duo Mobile application on your new phone, and click Next.

    Screenshot of step 7 above.

  3. Activate the new phone by either scanning the QR code through the Duo Mobile application, or by sending an activation link by email.

    Screenshot of step 8 above.

Unable to Access Device

If for any reason you are unable to access your device to complete your login attempt, please contact the IT Help Desk to request a bypass code. You will be required to provide a government-issued ID. The bypass code is valid for either five uses or four hours, whichever comes first.

 

Article Changelog

17% helpful - 6 reviews