Duo MFA Enrollment & Usage Guide

Duo logo

Protecting your account starts with Duo Mobile. Duo adds an extra layer of security to your university account by verifying your identity during login and helping keep your personal and university information safe.

All users must complete Duo Multi-Factor Authentication (MFA) enrollment before accessing Montclair systems.

Never share Duo codes

Duo codes are like your house keys — if someone else has them, they can walk right in.

What is MFA?

MFA (Multi-Factor Authentication) is a security process that requires users to provide two or more forms of verification to access an account or system. By requiring multiple factors, MFA makes it harder for hackers to gain unauthorized access to your account, even if they have your password. 

These factors typically fall into three categories:

  1. Something You Are

    Biometrics such a fingerprint or facial recognition

  2. Something You Know

    A password or PIN

  3. Something You Have

    A phone, security hardware key/token, or authentication app (Duo)

Setting up Duo

Setting up Duo is a quick process (about 5–10 minutes) that uses your computer to start and your mobile device to finish securing your account.

 

Before you begin setting up Duo, make sure you have the following:

  • A computer or laptop to start the setup process
  • Your smartphone or mobile device
  • Your NetID and password
  • The Duo Mobile app downloaded on your phone
  • A stable internet or cellular connection

Getting Started

  1. Go to a Montclair service such as NEST or Workday.
  2. Sign in using your NetID and password.
  3. After logging in, the Duo setup screen will appear.
  4. On the Welcome screen, select Get Started.

Recommended

You can add additional devices for MFA, such as another phone or tablet. Adding a backup device is recommended in case your primary device is unavailable.

  • Select the device(s) you would like to use for Duo authentication.
  • If you plan to add multiple devices, you can add them during this step.
  • Make sure Duo Mobile (Recommended) is selected.

Note: Duo also supports hardware security keys (such as YubiKey or FIDO2 devices), but the University currently does not provide them. Users would need to purchase their own at this time.

  • Enter your mobile phone number, including the area code.
  • No parentheses or dashes are needed.

Review your number and confirm it is correct.

  • Select Send me a passcode.
  • Enter the code sent to your phone.

If you have not already installed Duo Mobile, you will be prompted to download it.

  • Open the Duo Mobile app on your phone.
  • Scan the QR code displayed on the screen, or choose to receive an activation link instead.
  • Select Continue to complete setup.
  • You are now enrolled in Duo.

If you have any issues during setup, please contact the IT Service Desk for assistance.

Guides & Resources

Duo Resource Card

Your quick reference for staying secure with two-factor authentication. One side walks you through setting up Duo step by step, while the other side shares helpful tips for using it smoothly and keeping your accounts protected.

Duo Resource PDF

Everything you need to know about securing your accounts with Duo Push. Learn why Duo Push is recommended, get step-by-step setup instructions if you’re new, and find out who to contact if you don’t yet have it. A comprehensive guide to make two-factor authentication simple, fast, and effective.

Duo Visual Guide

Explore everything you need to know about securing your accounts with Duo Push—now in a step-by-step visual format.

ServiceNow Knowledge Base Articles

Here you will find helpful guides that provide answers, step-by-step instructions, and solutions to common questions and issues. Access is available through the link provided.
 

Faculty/Staff PortalStudent Portal

 

 

Frequently Asked Questions

Understanding Duo MFA

Duo adds an extra layer of security to your account to make sure it’s really you logging in.

Here’s how it works:

  • You enter your NetID and password when signing into a university system (such as email, Canvas, or NEST).
  • Duo sends a login request to your registered device as a push notification or provides a verification option.
  • You approve the request on your phone or enter a passcode.
  • Once verified, you are securely signed in.
  • Protects your account even if your password is stolen or guessed
  • Blocks unauthorized users from logging in without your approval
  • Sends real-time alerts when someone tries to access your account
  • Helps detect and stop suspicious login attempts early
  • Keeps email, Canvas, and other university systems secure
  • Reduces the risk of phishing-related account takeovers
  • Adds an extra layer of protection beyond just a password
  • Helps protect your personal and academic information
  • Required for accessing university systems securely
  • Without Duo verification, you cannot access your account

Using Duo

You will need to contact the IT Service Desk to let them know that the option isn’t available for you.

Yes. You can register more than one device with Duo and choose a preferred method during login.

Yes. Duo can be installed on supported tablets and used as an additional authentication device.

No. Changing your password does not require you to re-enroll in Duo.

You may need to set up Duo again on that device before it can be used for authentication.

You can update or change devices used for Duo authentication after setup.

Common actions:

  • Add a new phone or tablet
  • Replace a lost or upgraded device
  • Set a default authentication method

If you cannot access your device, use the Duo Knowledge Base or contact the IT Service Desk.

Account Access & Recovery

Duo MFA is required to protect university accounts and systems from unauthorized access. Passwords alone can be stolen, guessed, or leaked in phishing scams, so Duo adds an extra layer of security to confirm it’s really you logging in.

It helps:

  • Protect your personal and university data
  • Prevent unauthorized access to systems like email, Canvas, and NEST
  • Reduce the risk of phishing and account takeovers
  • Ensure only verified users can access university resources

Because of this added security, Duo is required for all logins to university systems.

Duo is required for most university systems that contain sensitive or personal information.

Yes. Duo is required for all users accessing protected university systems.

No. Duo is used only to verify login attempts and does not monitor personal activity.

If you get a new phone but keep the same phone number, you will still need to update Duo so it recognizes your new device.

Steps:

  • Download the Duo Mobile app on your new phone.
  • Log in and follow the prompts to reactivate Duo on the new device.
  • Approve the setup using an existing Duo method if you still have access (old phone, passcode, or backup option).
  • Once the new phone is working, remove the old device from your Duo account.

If you cannot access your old phone or Duo method:

  • Contact the IT Service Desk to reset your Duo device and re-enroll your new phone.

Even though your number stays the same, Duo is tied to the device, not just the phone number.

If your phone number changes, you will need to update your Duo account so you can continue logging in.

Steps:

  • If you still have access to your old number or a registered device, log in and go to your Duo settings to add a new phone number or device.
  • Download and set up Duo Mobile on your new phone.
  • Confirm the new device during the enrollment process.
  • Remove the old phone number or device once the new one is working.

If you no longer have access to your old number or device:

  • Contact the IT Service Desk to have your Duo account reset or updated.
  • They will verify your identity and help you re-enroll your new phone.

You will not be able to complete Duo login until a working device or number is set up.

Security

If you ever receive a Duo push notification you didn’t request, it could mean someone is trying to access your account without permission. That’s where the Fraud button comes in.

When you see a Duo push on your phone that you did not initiate, tap “Deny” and then select “It seems fraudulent.” This action alerts the INFOSEC team and helps us investigate potential threats to your account and campus systems.

You should then reset your NetID password immediately. If an attacker can make a fraudulent Duo request, that means they know your login credentials already.

Why It Matters:

Using the Fraud button helps stop cyberattacks early and protects not only your account, but the whole university community.

Do not approve the request unless you are actively signing in. If the request is unexpected, deny it and secure your account if needed.

Change your password immediately and review your recent account activity.

This can happen if multiple login attempts are made or if a session is not fully completed.

If you shared your Duo codes with a scammer, your account may be at risk of unauthorized access.

Do the following immediately:

  • Change your NetID password right away.
  • Report the incident so your Duo account can be reviewed or reset.
  • Monitor your account for any unusual activity or login alerts.

If you notice any unexpected Duo prompts or logins, report them immediately.

Access & Travel

Yes. Duo can be used while traveling as long as you have internet access or an alternate authentication method available.

You may still be able to use offline passcodes generated in the Duo Mobile app.

Most Duo options require an internet connection, but not all require WiFi specifically.

  • Duo Push: Requires WiFi or mobile data
  • Passcodes from Duo Mobile app: Does not require WiFi once generated

Yes, if you have previously generated passcodes in the Duo Mobile app.

Having Trouble With Duo?

Information Technology Division

Montclair State University’s Division of Information Technology is responsible for all enterprise information technologies across campus including: Enterprise Technology Services (ETS), Enterprise Application Services (EAS), Technical Support Services (TSS) and Information Security. The Division of Information Technology works closely with college/school/division technology coordinators and resources to optimize selection, deployment and integration of enterprise and local technologies to meet campus-wide information and processing needs.

Contact Information

For Duo setup help, device changes, or login issues, refer to the Duo Knowledge Base articles or contact the IT Service Desk.