Multi-Factor Authentication (MFA), Migrating from SMS Text Message

If you use SMS passcodes when signing in to university resources with Duo, you will need to select a different option before October 30.

SMS passcodes are the least secure option when using Multi-Factor Authentication and the university is removing the SMS option beginning October 30 to help better protect university resources from cyber criminals. MFA also helps protect personal information, such as access to direct deposit.

Duo Mobile Icon and images of the token keys available. What you need to do:

Determine whether you will use the Duo mobile app on a tablet or smartphone or use a token (key) that you plug in to your PC or laptop.

If you select the Duo Mobile app option, download it and install it on your smartphone or tablet.


Download Image for Google Play Store to get Duo Mobile app

If you select the token, you can obtain one from the WebStore.

Faculty and staff who do want to use a token should contact their department for instructions on acquiring a token.

Choosing a Device

  1. Duo Mobile App  - With the Duo Mobile app, you will simply receive a push notification to approve authentication requests, instead of typing in a code.
    • You can use a tablet in lieu of a smartphone.
    • One advantage of using the Duo Mobile app is that you can receive push notifications over Wi-Fi. This is helpful when you're in an area where you cannot get a cellular signal, or when traveling abroad.
    • You can also use the Duo Mobile app even if you are offline and have no access to data, via the Duo Mobile passcode option.
  2. Hardware Token / Security Key - These can be a good option if you do not want to use your smartphone for authentication. Information on hardware tokens can be found at this help article: Multi-Factor Authentication (MFA), Hardware Tokens and Security Keys.
    • Staff members can inquire with their department to see if a hardware token can be purchased for them.
    • The Duo Mobile Prompt adds support for FIDO2/WebAuthn security keys. This enables users to bring their own, although it is the user's responsibility to ensure compatibility.
    • Hardware tokens and security keys can also be used while offline.

Once you have made your choice and either have the token in hand or have the app installed you can change your second factor as registered in the NetID Center to your new option following the enrollment steps below.

Enrollment

There are two ways to enroll in multi-factor authentication:

 

Support

If you have any issues with setting up or changing your Multi-Factor Authentication please contact the ITS Help Desk be emailing techsupport@uis.edu, calling (217)206-6000, or stopping in the Lower Level Lounge of the Brookens Building. 

FAQ

Why did the university eliminate SMS passcodes as an option in Duo for Multi-factor Authentication?

While SMS-based authentication was once common, it is now considered less secure* due to vulnerabilities like SIM swapping and phishing.

 Using other factors such as a key or app offers a more robust and industry-standard approach to securing access, aligning with best practices used by financial institutions, government agencies and peer universities. The university handles sensitive data that requires strong protection like personal information, academic records and research information.

*The National Institute of Standards and Technology (NIST) has deprecated SMS as a secure MFA method since their 2017 revision of Special Publication 800-63.

 

Is the university’s data really sensitive enough to justify this change?

Yes. University systems contain confidential student, faculty and research data. Protecting this information is a legal and ethical responsibility, and stronger authentication methods help prevent breaches and identity theft.

 

Why not require Multi-factor Authentication only for accounts with sensitive data?

Security is most effective when applied consistently. Selective enforcement creates gaps that attackers can exploit. A unified approach ensures that all users benefit from stronger protection and simplifies support and policy enforcement.

 

What if I don’t have access to a smartphone?

We understand that not everyone has access to the same technology. The university offers alternative authentication options such as hardware tokens. Please contact the Help Desk to explore these options.

 

Why is there a limit on Multi-factor Authentication bypass codes?

Limits on bypass codes help prevent abuse and maintain system integrity. Unlimited bypass codes can undermine security benefits. Bypass codes are one-time solutions available from the Help Desk to use as a last resort if no other method of MFA is available. If you’re experiencing issues, the Help Desk can assist with temporary access and explore long-term solutions.

Was this helpful?
0 reviews