Duo 2-Step Authentication | California State University, Bakersfield (2024)

What is 2-Step Authentication?

California State University, Bakersfield employs 2-Step Authentication to bolster the security of your CSUB account and safeguard university data, systems, and services. Utilizing the hosted Duo security cloud-based two-factor authentication service, this system enhances protection.

The initial layer of security (something you know) consists of your CSUB user ID and password. The second layer (something you have) involves a smartphone. This additional layer ensures heightened security for your account and university-related information, systems, and services.

CSUB’s 2Step process involves two steps: initially logging in with your password (something you know), followed by verification through your smartphone (something you have).

Currently, CSUB’s 2Step is implemented across various services including Microsoft Office 365 (Outlook, Word, etc.), MyCSUB, Canvas, and PeopleSoft.

To be able to manage your devices on your Duo account, visit the CSUB 2Step page. You can also call the CSUB Service Center at 661-654-HELP(4357).

Remember to NEVER share your Duo code with anyone requesting it, whether they contact you through phone, text, or email.

Duo Verified Push

Multifactor authentication (MFA) adds an additional layer of security to your account by requiring an approval from another factor (like your smart phone or hardware token) to login. However, hackers have started a new method, known as MFA fatigue, to try and gain access to your accounts. MFA fatigue works by bombarding your device with texts, calls, or push notifications to grant them access to your accounts. To stay one step ahead of these hackers, we’re introducing Duo’s Verified Push to help keep your accounts and information secure.

What is Verified Push?

Verified Push is Duo’s additional security against MFA fatigue. It works by sending a push notification to your device with a 4-digit passcode to login. If you are not currently attempting to login to a CSUB service, you can click the “I’m not logging in” button to report the attempt as fraudulent and notify the Information Security team.

You can activate your mobile push notifications by logging into the CSUB 2Step management portal, or by contacting the Service Center at 661-654-HELP(4357).

Duo 2-Step Authentication | California State University, Bakersfield (1)

How do i login with verified push?

Logging in with Verified Push follows the same process as logging in with regular push notifications.

  1. Enter your CSUB email and password:

    Duo 2-Step Authentication | California State University, Bakersfield (2)

  2. The Duo Universal Prompt will appear on your computer and ask you to verify the login with Duo Mobile. You can also select the “Other options” to use a hardware token.

    Duo 2-Step Authentication | California State University, Bakersfield (3)

  3. In the Duo Mobile app, you will receive the Verified Push notification asking you to enter the 4-digit code shown on your screen. If you receive this message when you are not trying to access a CSUB resource, click the “I’m not logging in” button to report the attempt as fraudulent.

    Duo 2-Step Authentication | California State University, Bakersfield (4)

  4. Enter the 4-digit code shown on the screen in your device and click the "Verify” button to finish the authentication process. Once you’ve successfully authenticated, Duo Mobile will approve the login and you can access CSUB resources as you normally would.

    Duo 2-Step Authentication | California State University, Bakersfield (5)

What if i authenticate with texts or phone calls?

Duo Verified Push is not available for authentication with texts or phone calls. We recommend using the Duo Mobile app to take full advantage of these security features.

The Duo Mobile app is completely safe to use. CSUB and the Office of Information Security is committed to making the Duo Mobile app the quickest and most secure way to verify your identity with multifactor authentication. The app uses hardly any data and does not give the university any access or visibility into your phone.

Duo Mobile cannot read your emails, track your location, or see your browser history.

2Step Hardware Fob

If you do not have access to a smartphone, using a hardware fob offers a dependable alternative to Duo Push authentication. Users can authenticate logins by generating unique codes directly from the device itself. This method provides a tangible and reliable means of authentication, irrespective of internet connectivity or smartphone dependence. By pressing a button on the fob, users can generate a one-time passcode, enhancing the security of their login process. This approach is particularly advantageous for those who prefer a physical token for authentication or operate in environments where smartphone usage may be impractical or restricted.

If you'd like to get set up with a hardware fob for Duo authentications, you can call the Service Center at 661-654-HELP(4357). You can also create a request on ServiceNow using the 2Step Fob Request.

Duo Code Phishing

Remember to NEVER share your Duo code with anyone requesting it, whether they contact you through phone, text, or email.

Below is an example of attackers successfully tricking a student into giving them their Duo authentication code. Once they got the code they were able to login to the student's email and send out phishing emails to a majority of campus.

Duo 2-Step Authentication | California State University, Bakersfield (6)

Duo 2-Step Authentication | California State University, Bakersfield (2024)

FAQs

How do I get the Duo QR code? ›

When you enroll in Duo for the first time and choose to add an Android device or use Duo Push, you're shown a QR code to scan with the Duo Mobile app to complete activation. Launch Duo Mobile and tap Set up account. To proceed with adding your initial Duo account to Duo Mobile, tap Use a QR code.

How to get Google activation code for Duo Mobile? ›

On your Android device, enter your phone number and make sure it's correct. Tap Agree. Duo will send a code in a one-time SMS message to the number that you entered. (Carrier text-message rates may apply.)

How to reactivate Duo Mobile on a new phone? ›

On Duo Central, choose your secondary device from the device list and authenticate. Next, choose, "Text message passcode." Enter the code texted to you, and click “Verify.” Click "I have a new phone" next to the device you want to reactivate.

How to install duo authentication? ›

  1. Enrolling Your Phone or Tablet in the Duo Universal Prompt. ...
  2. Step One: Welcome Screen. ...
  3. Step Two: Choose Your Authentication Device Type. ...
  4. Step Three: Type Your Phone Number. ...
  5. Step Four: Choose Platform. ...
  6. Step Five: Install Duo Mobile. ...
  7. Step Six: Activate Duo Mobile. ...
  8. Step Seven: Configure Device Options (optional)

Why do colleges use Duo Mobile? ›

Duo Security is a multifactor authentication service that provides additional security for access to university and personal data. Students, faculty and staff use Duo Security for websites with confidential information and for Office 365 applications such as Outlook for Email.

How do I create a Duo code? ›

1. Use your smartphone to generate passcodes from the Duo Mobile app. To use, simply open the app and press the gray icon in the upper right-hand side of the app for iOS and Android (pointed by the red arrow in the image below) or the Generate Passcode button on Microsoft OS devices.

How do I login to Duo? ›

Once you've enrolled in Duo you're ready to go: You'll login as usual with your username and password, and then use your device to verify that it's you. Your administrator can set up the system to do this via SMS, voice call, one-time passcode, the Duo Mobile smartphone app, and so on.

Why won't Duo Mobile work for my device? ›

Some phones may have trouble determining whether to use the WiFi or cellular data channel when checking for push requests, and simply turning the phone to airplane mode and back to normal operating mode again often resolves these sort of issues, if there is a reliable internet connection available.

Can you use Duo without a phone number? ›

So, if you are signed into a standard Google account, just head over to duo.google.com now and sign in with an account without a phone number linked, rather than being asked to add it to your account.

How do I add a phone number to duo authentication? ›

Administrators:
  1. Log in to the Duo Admin Panel and click Users in the left sidebar.
  2. Select a user by clicking their username. ...
  3. Select the type of device and provide the phone number.
  4. Click the Add Phone button.

What is Google Duo called now? ›

The Google Duo app and icon are now Google Meet . To make video calls and have meetings in one app, use Google Meet . Existing video calling features from Google Duo are here to stay. If you used Google Duo or Meet at no cost today, you don't need to pay for the new experience.

How can I access my Duo without my phone? ›

If you have a hardware token, you can use it to generate a passcode. You can also use a security key. If your organization allows SMS passcodes as an authentication method and you received the passcodes before the authentication device went offline, you can use them to complete 2FA.

How can I use my Duo Mobile on my new phone without old phone? ›

Download the Duo Mobile app on your new device. Open Duo Mobile and tap Continue on the welcome screen. Duo Mobile locates your backed-up Duo-protected accounts in your restored backup and restores them to the app on your device. When complete, you're taken to the accounts list in the app.

How do I get Google Authenticator on my new phone without my old phone? ›

To set up Google Authenticator on your new phone without your old phone, simply install the app and then scan the QR code from your Google Account. If you have another phone with the app set up, you can also scan a QR code from that device.

How to set up Duo Mobile Texas State University? ›

How to Enroll a New Device to my Duo Account
  1. Go to Duo Enrollment.
  2. Enter your NetID and password, then click Login.
  3. You'll be taken to the Duo start screen. Click Next.
  4. Click Next.
  5. Click Next.
  6. Select an option to log in to Duo. NOTE: It is recommended to use the Duo Mobile (app) option, which we used for this example.

How do I add UCLA to my Duo Mobile? ›

Open the Duo Mobile application on your device. Click on the [+] button at the top-right of the screen. Using your device's Duo Mobile application, scan the QR Code found on your web browser's window. The UCLA Logon Multi-Factor Authentication service has now been added to your new device's Duo Mobile application.

How to set up Duo Mobile Ithaca College? ›

From your computer or tablet, visit https://www.ithaca.edu/duo/device and log in with your Netpass username and password.
  1. Click Start Setup to begin the Duo enrollment.
  2. Select the type of device you will use to verify your authentication (mobile phone, tablet, landline).
  3. Click Continue.

Top Articles
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6271

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.