Two-Factor Authentication: Frequently Asked Questions

Why is MSU implementing Two-Factor Authentication?

Cyber attacks and information breaches are becoming a major concern for higher education. Attempts to compromise user accounts through sophisticated phishing, social engineering, and brute-force password attacks have escalated and pose a significant threat to the security of online data.

The Office of the Provost has determined that a two-factor authentication requirement for user logins is necessary in order to better protect the online identity and personal information of MSU students and employees as well as to secure the university's research, intellectual property, and institutional data.


What is Two-Factor Authentication (2FA)?

2FA adds another layer of security when logging in to MSU systems. The first factor required to log in is something you know, i.e. your NetID/NetPassword.  The second factor is something you have, typically your smartphone or tablet. Therefore, even if an attacker is able to get your NetID/NetPassword, he should not be able to log in to your account because he does not have your second factor.

MSU uses a product called Duo for two-factor authentication. For more information about Duo, please visit their website.


What are my authentication method options with 2FA/Duo?

There are two options for authenticating with 2FA/Duo. The recommended option is to receive a push notification to your mobile device. Note that is not a text, but is generated via the Duo Mobile app. The second option is to enter a passcode. See the "What is a Duo passcode?" question below for information on how to get a passcode.


Am I required to use 2FA with every CAS login?

Once you choose the Duo authentication method, check the box next to "Remember me for 24 hours." You will not have to use 2FA for 24 hours in that browser on that computer.


What is a Duo passcode?

A passcode is generated by Duo for authentication. The passcode is used as the 2FA authentication method in specific situations such as:

  • You normally use the Duo Mobile app for a “Push” notification to your device but you don’t have your mobile device with you.

  • You don’t have a mobile device and need a hardware token (fob) to generate a passcode.

  • You are at a location where there is no cellular or wireless service to your device, so the “Push” notification will not work.

There are three methods available to obtain a passcode.

  1. Go to 2fa.msstate.edu and click “Generate a Two-Factor Authentication Passcode." This passcode is valid for 24 hours.

  2. Access the Duo mobile app on your device and tap the arrow icon next to Mississippi State University. This passcode is good for one-time use.

  3. Generate a passcode through a hardware token/fob. This passcode is also good for one-time use. Contact the ITS Service Desk to request a hardware token.


What is autopush?

If autopush is selected during your setup, you will receive a message on your device to approve your authentication attempt automatically during the Central Authentication System (CAS) login. This is not the recommended method of 2FA.


What happens if I do not have my mobile device to log in?

Go to 2fa.msstate.edu and click "Generate a Two-Factor Authentication Passcode." This passcode is good for 24 hours.


What if I get a new smartphone or device?

If your phone number has not changed, go to duo.msstate.edu and click Add/Manage Device. Click "Enter a Passcode." (See “What is a DUO Passcode?” in the FAQ above to learn how to generate one.)  Click “Device Options," then click “Reactivate DUO Mobile." This will display a QR code for you to scan with the Duo Mobile App on your new phone. Tap the “+” button, and scan the QR code.

If you have a new phone number or tablet. Go to duo.msstate.edu and click "Add/Manage Device." Click “Enter a Passcode." (See “What is a DUO Passcode?” in the FAQ above to learn how to generate one.) Click “Add another device," then follow steps 6 – 11 in our Enrolling in Two-Factor Authentication article to set up your new device.


Can I have the Duo Mobile app on more than one device?

When enrolling in Duo, you are able to add multiple devices.


Is Duo required for VPN or was.msstate.edu?

Duo is required for both Employee and Departmental logins to the VPN and for login to was.msstate.edu.

Duo is not currently required for Student login to the VPN.


I have a mobile device, but my camera is broken. Can I still use my device?

Yes. Instead of activating Duo Mobile by scanning the QR code, click the link for “Or, have an activation link emailed to you instead." You will receive an email that will allow you to set up your device.

Details

Article ID: 1513
Created
Mon 1/7/19 1:35 PM
Modified
Mon 1/7/19 1:36 PM