Topics Map > Account Management > 2FA/Duo
Multi-Factor Authentication (MFA), Device Management
Introduction
If you get a new phone, change your phone number, or get a new device, you can update this information so you can continue to secure your account using MFA.
You can manage your devices via the NetID Center or the Duo Universal Prompt. You can find instructions on using either interface below.
- If you use the NetID Center (https://identity.uillinois.edu), take a moment to make sure that your recovery information is up to date.
- If you are at a Duo Universal Prompt, you will need to click Other options to go to the authentication methods screen. On the next screen, click on Manage devices and verify your identity.
Don't Have Your Device?
If your MFA devices are not available and you need to regain access to your account, you can get a temporary bypass code sent using your recovery information. Navigate to the Temporary passcode page (https://identity.uillinois.edu/iamFrontEnd/iam/passcode) and follow the instructions there. If you need additional information, please see this help article: Multi-Factor Authentication (MFA), Troubleshooting.
- Bypass codes are meant to be used as a temporary means to access your account and can be requested 24 times per year. Each code can be used 100 times and expires after 3 days.
Duo Mobile App and Duo Push
The Duo Mobile app provides the ideal combination of security and convenience. The push notification function of the app is the preferred option to authenticate with MFA. Unlike SMS-based authentication, Duo push notifications do not require your cell phone to have a cellular signal. The app is available in the Apple App Store (link) and the Google Play Store (link).
Additionally, Duo Mobile can be set up on tablets or other compatible devices that do not have a phone number.
Starting in August 2024, push notifications via the Duo Mobile app will be required when accessing the Remote Desktop Gateway.
Set up Duo Mobile on an existing device
If your current device is set up to only receive SMS/Text messages or if you have a new phone and need to reactivate Duo Mobile, these two sections will help. If you run into any issues, please reach out to your Help Desk.
Reactivate the Duo Mobile app (new phone but same phone number)
NetID Center
- Log into the NetID Center
- If the Duo prompt automatically sends you a push notification, click on Other options.
- Authenticate using the Text meessage option, or via another device
- Click on Manage my 2FA.
- Click on your device under My Devices & Settings, then click on Reactivate Duo App
Duo Universal Prompt
- Click on Other options to go to the authentication methods screen.
- Click on Manage devices.
- You'll need to verify your identity here, so choose an alternative authentication method such as text message.
- At the device management screen, click on I have a new phone.
Change your phone type (for example: changing from a basic phone to a smartphone)
NetID Center
If you want to change the type of phone you have registered for MFA (for example if you get a smartphone or you want to add SMS capability), you will want to add a new device with the same phone number.
- Log into the NetID Center
- Go to Manage my 2FA
- Click on Add a new device.
- Continue through the setup process. When you are done adding your device, it will overwrite the old entry.
Duo Universal Prompt
If you want to change the type of phone you have registered for MFA (for example if you get a smartphone or you want to add push capability), you will want to add a new device with the same phone number.
When you are done adding your device, it will overwrite the old entry.
For Urbana campus users:
- Log into an application that uses Shibboleth or Entra ID SSO.
- When you get to the Duo MFA prompt, click on Other options to go to the authentication methods screen.
- Click on Manage devices.
- You'll need to verify your identity here, so choose an alternative authentication method such as text message.
- At the device management screen, click on Add a device and follow the instructions. Make sure to choose the Duo Mobile option.
Before:
After:
Set up Duo Mobile on a new device
The section below will assist you with adding a new device to use with the Duo Mobile app.
Add a new device
NetID Center
- Log into the NetID Center
- Go to Manage my 2FA
- Clicking Add a new device will walk you through a few steps to get a new device added. Make sure to choose smartphone as your device type.
Duo Universal Prompt
For Urbana campus users:
- Log into an application that uses Shibboleth or Entra ID SSO.
- When you get to the Duo MFA prompt, click on Other options to go to the authentication methods screen.
- Click on Manage devices.
- You'll need to verify your identity here, so choose an alternative authentication method such as text message.
- At the device management screen, click on Add a device and follow the instructions. Make sure to choose the Duo Mobile option.
Notifications from Duo When Adding/Removing Devices
To help protect your Duo account from unauthorized activity, you will receive a Duo push and an email notification when you add or remove an authentication device in Duo.
If you receive a notification and did not add or remove a device, select "No, this wasn't me", and take immediate action to change your password and review registered devices within Duo. You can use the NetID Center or the Duo Universal Prompt. Additionally, you can reach out to the Help Desk at 217-244-7000 or consult@illinois.edu.
Push Notification from the Duo Mobile App | Email Notification |
---|---|
Other Topics
Remove a device
NetID Center
Click the trash can button to delete a device.
Note: You may not remove your device if you only have one set up. If you wish to remove it, first add another then delete the original. You will be given a chance to confirm or cancel the removal of the device. Once the device is deleted, it can no longer be used to approve DUO requests.
Duo Universal Prompt
Click on the Edit button, then click on Delete.
Note: The delete option will only appear if you have another device listed. If you wish to remove it, first add another then delete the original. You will be given a chance to confirm your selection.
New phone number
You'll need to authenticate before you will be able to manage your devices. If you have another MFA device such as a hardware token you can use that, or you can send yourself a temporary passcode here.
- If you do not have a recovery email address registered - or have access to that email address - you will need to contact your campus help desk.
- Once you're in, please update your recovery information via the NetID Center.
Instructions on how to use your temporary passcode can be found in this help article: Multi-Factor Authentication (MFA), Troubleshooting.
Duo Remembered Devices Feature
Duo Remembered Devices Feature
Depending on which Duo Prompt you are seeing, the remembered devices feature will be referred to as one of the following:
- A prompt asking you 'Is this your device?'
- A checkbox with the label 'Remember me for 24 hours'
Do not trust the browser when using a public or shared computer! This could leave your Duo session available to other users. Trust the browser only when you access applications from your own computer.
If accessing Microsoft365 (Outlook, Word, Excel, etc.) or Shibboleth (Canvas, Box, Zoom, Moodle, etc.) or the NetID Center:
If you're authenticating with MFA for the first time in your browser, you will see the below screen after you authenticate:
Once the trusted session cookie expires (after 24 hours), you will see the below screen when authenticating. The remembered devices feature is enabled by default, but you can uncheck the checkbox shown below to disable it if desired:
If accessing some AITS Applications (Banner, HR Reporting, My UI Info, Direct Deposit, etc.):
The remembered devices feature is enabled by default, but you can uncheck the checkbox shown below to disable it if desired:
Set your default (favorite) device
NetID Center
If you authenticate with more than one device, you can specify the default by selecting the blue star icon:
You can also choose the default behavior when you authenticate via a UI Verify Duo Prompt:
Duo Universal Prompt
The first time you access the Duo Universal Prompt for a given application, it will evaluate your registered devices and automatically select the most secure option available to you, using this ordered preference (ordered from most to least secure):
- FIDO2 Security Key
- Duo Mobile push approval
- Yubikey passcode
- Duo Mobile generated passcode
- Hardware token passcode
- SMS passcode
If you want to try a different method than the one selected for you, you can click on 'Other options' to get a list of your available authentication methods:
When you successfully authenticate, the Duo Universal Prompt remembers the authentication method used and defaults to that method for future logins to that application. If you want to try a different method than the one used last, click 'Other options' to get a list of your available authentication methods.
Automatic Duo Push
If you explicitly choose Duo Push authentication or it is automatically selected on your behalf during a first-time authentication, Duo will automatically send the push notification to your device without any action needed by you. During future authentications, Duo will continue to send the push notification automatically if that remains your default authentication method.
Change the display name of your device
NetID Center
Clicking Rename will allow you to change the display name of your phone (tokens cant be renamed).
- Click the plus button to open the device settings.
- Click Rename
- Type in the desired device name and click Save.
Duo Universal Prompt
Click on the Edit link for the device you want to rename, then click on Rename.
See Also
- Multi-Factor Authentication (MFA), Introduction
- Multi-Factor Authentication (MFA), How to Use
- Multi-Factor Authentication (MFA), Enrollment
- Multi-Factor Authentication (MFA), Device Management
- Multi-Factor Authentication (MFA), Troubleshooting
- Multi-Factor Authentication (MFA), Hardware Tokens and Security Keys