{"id":18400,"date":"2024-02-29T09:22:23","date_gmt":"2024-02-29T16:22:23","guid":{"rendered":"https:\/\/in.nau.edu\/its\/?page_id=18400"},"modified":"2024-09-05T13:21:24","modified_gmt":"2024-09-05T20:21:24","slug":"2024-duo-updates","status":"publish","type":"page","link":"https:\/\/in.nau.edu\/its\/2024-duo-updates\/","title":{"rendered":"Security Updates to Duo in 2024"},"content":{"rendered":"<h3 style=\"text-align: center;\">Security Updates to Duo in 2024<\/h3>\n<p style=\"text-align: center;\"><span style=\"color: #808080;\"><em>To protect against recent cyber threats, NAU is enhancing Duo Two-Step Verification protections for the NAU community.\u00a0<\/em> <\/span><\/p>\n<hr \/>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-60px not-in-view\">\n<div class='shortcode-column-container'><!-- shortcode-column -->\n<div class=\"shortcode-column shortcode-column--count-2\">\n    \n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h5>NAU Computers now requiring Duo authentication for login<\/h5>\n<h6 style=\"opacity: 60%;\">August 2024<\/h6>\n<hr \/>\n<h6><a href=\"#first\">Scroll to<\/a><\/h6>\n<\/div><\/div>\n\n<\/div>\n\n<!-- shortcode-column -->\n<div class=\"shortcode-column shortcode-column--count-2\">\n    \n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h5>Three-digit code now required for Duo Two-Step Verification<\/h5>\n<h6 style=\"opacity: 60%;\">May 2024<\/h6>\n<hr \/>\n<h6><a href=\"#second\">Scroll to<\/a><\/h6>\n<\/div><\/div>\n\n<\/div>\n<\/div>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h6 id=\"first\" style=\"opacity: 60%;\">August 2024<\/h6>\n<h4>NAU Computers now requiring Duo authentication for login<\/h4>\n<p data-pm-slice=\"1 1 &#091;&#093;\">Beginning on August 16th of 2024, NAU computers will require authorization through Duo to complete the login process. After you enter your NAU username and password on your device\u2019s login screen, a Two-Step Verification prompt will be sent to your authorized Duo device for approval. Once you approve this prompt, you can finish logging into your device.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<h5>Why is ITS making this change?<\/h5>\n<p>Work from home, remote work, and hybrid work have changed the threat landscape when protecting University systems and assets. While on-prem systems are typically stored in controlled access environments with security above that of consumer-grade, our new landscape does not reflect this same level of protection. With more individuals spread worldwide, ITS must adapt our security practices to meet these new threats and increase our diligence to protect the campus community.<\/p>\n<p>As the world has shifted to more remote and hybrid work different vulnerabilities and attack vectors have become more prevalent. By requiring Two-Step Verification at desktop logon, we can better protect information that is stored or accessible locally on workstations, better protect network shares and other systems and assets that do not currently support Two-Step Verification before access, assist with protection of sensitive information in the event of lost or stolen devices, and help protect from attacks such as keylogging.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<h4>Frequently asked questions &amp; use cases<\/h4>\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will I need to Two-Step every time I login to my workstation or just the first time I login for the day?\n_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will I need to Two-Step every time I login to my workstation or just the first time I login for the day?\n <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>University community members will have an opportunity to select a checkbox during the login process to &ldquo;Remember&rdquo; their login, or until an environmental variable change requires a refresh of your credentials. Environmental changes that can impact your ability to be remembered include but are not limited to, joining a different wireless access point such as moving between offices or buildings, joining the VPN, or restarting your device.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will you still be able to use a Two-Step fob to login if you do not have a mobile device that can support Duo?\n_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will you still be able to use a Two-Step fob to login if you do not have a mobile device that can support Duo?\n <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">Yes, Two-Step fobs will be usable for logging into workstations in a similar fashion as it would be with logging into CAS or other Microsoft services.<br>\n<\/span><\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"What should I do if I forget or lose my phone or Two-Step fob?\n_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>What should I do if I forget or lose my phone or Two-Step fob?\n <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">In the event that you forget your Two-Step authentication devices or if it is lost or stolen, you may call into the ITS Service Desk at 928-523-3335 to request a Two-Step Bypass code to use for the day. This code will allow you to access the workstations as well as other systems protected by Two-Step Verification.<br>\n<\/span><\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will I still need to authenticate with Duo into Outlook, Teams, CAS, and other services?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will I still need to authenticate with Duo into Outlook, Teams, CAS, and other services? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<div><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">Yes, at this time, you will still be required to Two-Step Verification into all other services and apps in the same way you do today. While we are working to improve some of these experiences in the future, the products currently do not talk to each other to pass along the Two-Step Verification.<br>\n<\/span><\/div>\n<div><\/div>\n<div><hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\"><\/div>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will I need to authenticate with Duo if I remote into my workstation?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will I need to authenticate with Duo if I remote into my workstation? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<div>Yes, Two-Step Verification is required for all interactive logon operations to workstations.<\/div>\n<div><\/div>\n<div><hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\"><\/div>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will I still be able to use biometrics to log into my system?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will I still be able to use biometrics to log into my system? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>On Windows devices, Cisco Duo does not currently support Windows Hello, and you will not be able to utilize facial or fingerprint recognition.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<p>On MacOS devices, Cisco Duo does not support fingerprint recognition on the initial logon of the system but will support subsequent authentications to unlock any existing session.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"How will this affect students?\u00a0_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>How will this affect students?\u00a0 <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<div>\n<div class=\"elementToProof\">Classrooms and labs across campus will also be required to utilize Two-Step Verification at logon. Students will have the option to enable a short duration &ldquo;Remember Me&rdquo; option when logging into classroom and lab computers.<\/div>\n<\/div>\n<div><\/div>\n<div><hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\"><\/div>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will this affect servers or non-standard accounts?\n_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will this affect servers or non-standard accounts?\n <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">No, at this time, this change will not impact any servers or non-standard accounts. In the future, we will be evaluating remote and terminal services to determine if it is appropriate and prudent to deploy these same Two-Step Verification requirements to those systems and services.<br>\n<\/span><\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Will this impact personal or BYOD devices?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Will this impact personal or BYOD devices? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<div>\n<div>No, at this time, this change will only impact University-owned and managed Windows and Mac workstations. However, it is imperative that any work that you do for the University is protected at the same levels. Local storage of university data on non-University owned and managed systems is not permitted. In the coming months, ITS will be further evaluating the utilization of BYOD systems to access University systems and data.<\/div>\n<\/div>\n<div><\/div>\n<div><hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\"><\/div>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<\/div><\/div>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h6 id=\"second\" style=\"opacity: 60%;\">May 2024<\/h6>\n<h4>Three-digit code now required for Duo Two-Step Verification<\/h4>\n<p>Beginning in late May of 2024, NAU employees (including student employees) and NAU Affiliates (including retirees and emeritus) must enter a three-digit verification code when logging into NAU services requiring Duo Two-Step Verification. Upon login, you&#8217;ll see a three-digit code in the Duo login prompt in your web browser and a push notification from Duo on your verified device to enter the code you&#8217;re given before allowing access.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<h5>Why is this happening?<\/h5>\n<p>Recently, NAU has observed cybercriminals in the higher-education landscape attempting to gain access to users&#8217; accounts through a social engineering technique known as &#8220;MFA Fatigue&#8221;. This technique involves a malicious entity spamming a user with login attempts and subsequent Duo prompts until a user slips focus on the action and unintentionally approves an unauthorized prompt.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<h4>Frequently asked questions &amp; use cases<\/h4>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Can I still complete a verification from my Apple Watch?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Can I still complete a verification from my Apple Watch? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Yes, you can still complete a verification request from your Apple Watch.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"I teach in multiple classrooms, what does that mean for me?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>I teach in multiple classrooms, what does that mean for me? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>These updates will not impact the functionality of &lsquo;Remember me&rsquo; when you transition between classrooms. However, you will need to physically carry your phone or Two-Step fob with you every time you visit a classroom.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"I currently use a Two-Step fob device. What can I expect?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>I currently use a Two-Step fob device. What can I expect? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>This change only affects users who utilize the push verification functionality. If you use a fob, you won&rsquo;t notice any changes to your login behavior.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<\/div><\/div>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h5>Questions or concerns?<\/h5>\n<p>If you have a question or concern regarding this change, <strong><a href=\"http:\/\/in.nau.edu\/its\/help\">contact the ITS Service Desk<\/a><\/strong> and reference the updates to MFA for NAU employees.<\/p>\n<\/div><\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Updates to Duo in 2024 To protect against recent cyber threats, NAU is enhancing Duo Two-Step Verification protections for the NAU community.\u00a0 &nbsp;<\/p>\n","protected":false},"author":608,"featured_media":18401,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","ring_central_script_selection":"","footnotes":""},"class_list":["post-18400","page","type-page","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/18400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/users\/608"}],"replies":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/comments?post=18400"}],"version-history":[{"count":55,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/18400\/revisions"}],"predecessor-version":[{"id":19378,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/18400\/revisions\/19378"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/media\/18401"}],"wp:attachment":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/media?parent=18400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}