Duo Two-Factor Authentication (2FA) Overview

Duo Two-Factor Authentication (2FA) helps protect you against online attacks designed to gain unauthorized access to your Odin account and information. Duo 2FA is required for Single Sign-on (SSO) for all employees.


Table of Contents


How Duo 2FA Works

Duo 2FA adds a second layer of security when you sign in to certain systems, such as PSU's Single Sign-On (SSO) or Virtual Private Network (VPN). To access a protected system, you’ll combine your Odin account information with a secondary credential delivered through your phone, mobile device, hardware token, or security key. This prevents anyone else from signing in with your account, even if they know your password.

  1. You enter your Odin account username and password as usual.

  2. You are prompted to authenticate using your phone or other method to verify your identity.

  3. You are securely signed in to your account.

Enter your username and password, verify your identity using a second method, then you'll be signed in to your account.

Start Using Duo 2FA

To use Duo 2FA, you must first enroll. After enrolling a device, you will automatically receive certain protections for PSU systems based on whether you are a PSU student or employee. 

  • PSU employees automatically receive protections for SSO and the VPN

  • PSU students automatically receive protection for the VPN. To receive the Odin password extension benefit, students must also add protection to SSO.

Enroll in Duo 2FA With a Mobile Device and the Duo App

Instructions can be found in our Enroll and Manage Settings in Duo Two-Factor Authentication (2FA) article.

Add Duo Protections to Single Sign-on (SSO)

Instructions can be found in our Update Protections in Duo Two-Factor Authentication (2FA) article.

Recommendations

For most people, we recommend using a mobile device with the Duo Mobile app installed as the best method of two-factor authentication. Using the Duo Mobile app on a smartphone or tablet gives you the greatest number of options when you sign in to a protected system. Most people find the push notification the most convenient option.

Push Notification

With the Duo Mobile app, you can use the Send me a Push method of authentication and select Approve on the login request sent to your device.

Using a Duo Token

PSU Employees may use a Duo Token as an authentication method, available from the Helpdesk. With a Duo Token, you can generate a passcode, even when you don’t have cell service or an internet connection.

Other Options

Refer to Enroll and manage settings in Duo Two-Factor Authentication (2FA) for details on your other device and authentication options.