Duo authentication changes

From Research Computing Center Wiki
Jump to navigation Jump to search

Duo Phone Call and SMS Text Verification Retirement Sept.17, 2026

To enhance security and reduce phishing attempts, Enterprise Information Technology Services (EITS) is updating Duo multi-factor authentication (MFA) methods for all Duo users at the University of Georgia. These changes are part of EITS’ ongoing efforts to better protect UGA accounts.

As part of these improvements, EITS will remove the two less secure verification methods, SMS text messages and phone calls, and introduce more secure authentication options to safeguard UGA accounts.

What is Changing?

Beginning September 17, 2026, SMS text messages and phone calls will no longer be available as verification methods in Duo for students, faculty and staff. These methods are being retired because they are less secure.

The same change will go into effect for Departmental MyID accounts on November 5, 2026. Beginning on that date, SMS text messages and phone calls will no longer be available as Duo verification methods for Departmental MyIDs.

SMS text messages and phone calls were removed as verification methods for UGA retirees and owners of IT administrative accounts this summer.

New Secure Authentication Options

Effective Summer 2026, users have access more secure options, including:

  • Duo Mobile app (push notifications and passcodes)
  • Platform authenticators (such as fingerprint or facial recognition on your device)
  • Roaming authenticators (such as USB security keys)
  • Duo Desktop authentication (Duo authentication for your computer)
  • Duo Hard Tokens (physical keychain devices that provide a Duo code)

Why This Change Is Happening

This change will remove two less secure MFA options in Duo while introducing more secure methods for logging in to UGA systems. These updates align Duo MFA with current security best practices and support enhanced protection for UGA systems and data.


How will these changes affect access to GACRC clusters and servers

Prior to these changes most users who has a mobile phone registered with Archpass Duo were offered three options when then ssh into e.g. Sapelo2.

After September 17, most users will only see one option, as illustrated below:

[shtsai@localhost ~]$ ssh shtsai@sapelo2.gacrc.uga.edu
(shtsai@sapelo2.gacrc.uga.edu) Password: 
(shtsai@sapelo2.gacrc.uga.edu) UGA DUO authentication is required for SSH/SCP access to
GACRC systems.

UGA DUO is a two-factor authentication service which
requires a password (one factor) and a code, phone,
or device (second factor) to successfully authenticate.

If you are not enrolled in the UGA DUO service please
visit the UGA DUO service self-service portal to enroll
and configure or manage your DUO enabled devices.

https://archpass.uga.edu

For additional help with UGA DUO authentication or to
report an issue please visit:

https://uga.teamdynamix.com/TDClient/3190/eitsclientportal/KB/Category/23825/ArchPass-powered-by-Duo
Duo two-factor login for shtsai

Enter a passcode or select one of the following options:

 1. Duo Push to XXX-XXX-1234

Passcode or option (1-1): 1
Success. Logging you in...
Success. Logging you in...
Last login: Wed Sep  2 13:42:52 2026 from 172.22.72.26
[shtsai@ss-sub4 ~]$ 

At the prompt

Passcode or option (1-1):

you can either enter 1 to receive a Duo push to the app on the mobile phone, or open the Duo app in the mobile phone and enter the 6-digit code displayed in the app into the prompt above. For example, if the Duo app in the mobile phone shows "Passcode 401321", you could enter

Passcode or option (1-1): 401321

Users who do not have a mobile phone registered with Archpass Duo, or who cannot or prefer not to install the Duo app on the mobile have the option to use a hard token for Duo authentication.

Users who do not have a mobile phone registered for Duo push and who opt to use a hard token for Duo authentication will see something like this when they ssh into Sapelo2:

[shtsai@localhost ~]$ ssh shtsai@sapelo2.gacrc.uga.edu
(shtsai@sapelo2.gacrc.uga.edu) Password: 
(shtsai@sapelo2.gacrc.uga.edu) UGA DUO authentication is required for SSH/SCP access to
GACRC systems.

UGA DUO is a two-factor authentication service which
requires a password (one factor) and a code, phone,
or device (second factor) to successfully authenticate.

If you are not enrolled in the UGA DUO service please
visit the UGA DUO service self-service portal to enroll
and configure or manage your DUO enabled devices.

https://archpass.uga.edu

For additional help with UGA DUO authentication or to
report an issue please visit:

https://uga.teamdynamix.com/TDClient/3190/eitsclientportal/KB/Category/23825/ArchPass-powered-by-Duo
Duo two-factor login for shtsai

Enter a passcode or select one of the following options:

Passcode:

Entering the passcode provided by the hard token will enable Duo authentication.


Additional Information

To update your Duo Verification method, visit the Duo Self-Service portal.

For assistance in updating your method, contact the EITS Help Desk.

For more information about these updates, available authentication methods and step-by-step resources, visit the EITS Major Initiatives page: Duo Verification Methods Improvements.