2FA (two factor authentication) is based on principle of something you have and something you know.
CSU reference: http://duo.colostate.edu
The Cisco DUO and Microsoft Authenticator apps both work now and will continue to work. They are created for iOS and Android, so you need a smartphone to use them. Which means that if your phone is broken or lost, you’ll need to contact the CSU Helpdesk to transfer the app unless you prepare ahead of time.
If you are travelling, or accident prone like I am, it’s a great idea to make sure you have a “backup” plan.
-
Best option: set up a tablet or old phone with the DUO or Microsoft Authenticator app.
- https://netid.colostate.edu/duo.aspx
- Register device
- Techie option: purchase a Yubikey from Ramtech or directly from Yubikey and leave it in your computer – it’s a device that when you touch it, sends the validation code. Requires some set up, but it’s then in your computer and ready to go. Costs $30-100.
- “It’s on my keychain” option – purchase the DUO hardware token from Ramtech and put it on your keychain.
-
CSU Helpdesk option: Enter a bypass codes
- Call CSU Helpdesk when you are logging in. 970-491-7276. They will need you to prove who you are, then they will give you a bypass code
- Enter the bypass code by using the ‘Other options’ option
- Probably not a good idea to do this each time you need to log in, but this is great if you have a new phone
As always, let us know if you would like some assistance setting this up!
Mike and Andy
_____________________
Sreve Lovaas, December 2024:
A reminder: as of next Wednesday, December 18, the option to receive a phone call for Duo two-factor authentication will no longer be available. If you've already taken care of this, please disregard the rest of this message.
Required Action:
If you currently use phone calls for Duo authentication, please choose your new method before December 18:
-
Options for authentication:
- Option A: Download and set up the Duo Mobile App on your smartphone
- Option B: Use a USB Security Key. Limited quantities of Yubikeys and Feitian keys are available for purchase at RAMTech in Fort Collins, the Pueblo bookstore, or through Kuali shop catalogs. You can also purchase Yubikey, Feitian, or other brands of security keys online.
- Option C: A smartphone can also be used as a Security Key and does not require downloading an application.
- Option D: Purchase a Duo Hardware Token from RAMTech at Fort Collins.
If you need help setting up your new authentication method, submit a help request to the Division of IT Help Desk.
Why this change?
- Phone call authentication is responsible for the bulk of Duo account compromises.
- Removing this option improves overall security by promoting more secure authentication methods.
Please ensure your new authentication method is set up before December 18 to maintain uninterrupted access to Duo-protected systems like email, Banner, the GlobalProtect VPN and more.