Multi-Factor Authentication (MFA) Methods

Multi-Factor Authentication (MFA) Methods

Authentication Methods

It is very helpful to add additional authentication methods. This way if you’re having trouble logging in, you can easily switch to a different method. Currently, there are five methods: Duo Mobile app, Passcode, Phone Call, U2F Authenticator, & Cisco AnyConnect.

If you’re ever having trouble logging in (for instance: don’t have your smartphone, don’t have a wireless connection for your smartphone, or forgot your Duo Hardware Token) switch to a different authentication method. Click Cancel and choose one of your other methods.

Go to https://my.logon.ucla.edu and Sign In. This will bring up the authentication screen:

 Adding an additional authentication method

To add an additional authentication method, click Cancel and then click Add a new device. Shibboleth will first need to confirm it’s you. Choose an authentication method to gain access. Then, choose your device type on the What type of device are you adding? screen. Click Continue and enter the required information.

 Automating an authentication method

It’s also very helpful to automate a preferred authentication method. This will speed things up when you’re logging in. To set this up, click My Settings & Devices. Choose your Default Device. Then click the pull-down menu next to When I log in: and choose Automatically send this device a Duo Push.


 

Authentication Using Duo Mobile app 

Tap on the notification on your smartphone or tablet to open the Duo Mobile app. Tap on Approve.

 In many instances what actually happened is the user simply missed the notification. In this scenario, if the user opens their Duo Mobile app they will see their push waiting for them. If #1 does not work, refresh the Duo Mobile app with pending pushes by doing a swipe-down from the top or your smartphone screen. This works very similarly to the email program. You do a swipe down, and you see the twirly at the top spinning to indicate a refresh is underway. Then, the push appears and all is well. If neither #1 or #2 works, return to the website and have the push resent from there.

For iPhone 6S, iPhone 6S Plus, and iPhone 7 users: force touch the notification. This will bring up an Approve button. Tap approve. No need to open the Duo Mobile app.

For Apple Watch users: press approve on the Duo Mobile app on your watch.

 

Authentication Using Passcodes

 

Authentication by Phone Call

Your smartphone, cell phone or landline will ring. You answer and hit any key. You're done!

 

Authentication by U2F Authenticator

Insert the U2F into a USB port (if it's not already there). Press the button on the U2F. You're done.

 

Authentication with Cisco AnyConnect

How you log in from home (or while away at a conference) using the Cisco AnyConnect VPN will depend on your Authentication Method:

For more information: Authenticating Using Multi-Factor Authentication on the Campus VPN

After entering your password in Cisco AnyConnect, tap Approve in the Duo Mobile app to complete your VPN login.

 What to do if you do not receive the Push notification:

        1. In many instances what actually happened is the user simply missed the notification. In this scenario, if the user opens their Duo Mobile app they will see their push waiting for them.

        2. If #1 does not work, refresh the Duo Mobile app with pending pushes by doing a swipe-down from the top or your smartphone screen. This works very similarly to the email program. You do a swipe down, and you see the twirly at the top spinning to indicate a refresh is underway. Then, the push appears and all is well.

        3. If neither #1 or #2 works, it might be due to a weak Digital Cellular or WiFi connection for the smartphone. Instead, switch input methods. Open your Duo Mobile app and tap the key icon. This generates a use-once passcode. This works even with no network connection. Enter your password in Cisco AnyConnect followed by / and your passcode. For instance: mypassword/123456

 Enter your password in Cisco AnyConnect followed by "/" and your passcode. For instance: "mypassword/123456"
After entering your password in Cisco AnyConnect, answer your phone and hit any key to complete your VPN login
After entering your password in Cisco AnyConnect, Press the button on the U2F to complete your VPN login