Enroll and Manage Settings in Duo Two-Factor Authentication (2FA)

To get started using Duo Two-Factor Authentication (2FA), you must enroll a primary device. For the best experience, we recommend using a mobile device with the Duo Mobile app. We also recommend that you enroll more than one device in Duo 2FA. This ensures that if your primary device is lost or unavailable, you'll have a backup that allows you to connect without needing to contact the OIT Help Desk.


Table of Contents


Enroll Your Primary Device

You can enroll in Duo 2FA by signing in to the Odin Account Manager (OAM) at oam.pdx.edu

  1. Select Set up Duo / Manage Duo Settings.

  2. Select Click to continue.
    Note: Hardware tokens can't be used as your only authentication device, but can be added as a secondary option later.

  3. Continue to enroll devices using the appropriate set of directions below.

Mobile Device with the Duo Mobile App

  1. Select your country and enter your phone number.
    Note: Use the number of a smartphone, landline, or mobile phone that you'll have with you when you're signing in.

  2. Confirm your number by selecting Send me a passcode or Call my Phone. Input the 6-digit code that was sent to your device.

  3. Confirm you have downloaded Duo Mobile by selecting Next.

  4. Activate Duo Mobile by scanning the barcode on your screen using the app's built-in barcode scanner.
    Note: After you scan the barcode, select the Continue button. If you can't scan the barcode, select Get activation link instead and follow the instructions.

  5. After scanning the QR code, confirm activation by selecting Continue under Added Duo Mobile.

  6. Select Security Token to enroll that type of device; otherwise, select Skip for now.

  7. Set-up should now be complete, and you may select Login with Duo to continue.

Mobile Device without the Duo Mobile App or Landline

  1. Select Phone Number from the list of options.

  2. Select your country and enter your phone number.
    Note: Use the number of a smartphone, landline, or mobile phone that you'll have with you when you're signing in.

  3. Check the This is a landline box and select Continue.

  4. Enter an extension if needed and select Add extension, or select Skip this step.

  5. Confirm your number by selecting Yes, it’s correct.

  6. Continue adding additional devices as needed.

Reconnect Trusted Device After Changing Phone

  1. Sign-in to the Odin Account Manager (OAM) at oam.pdx.edu.

  2. When prompted, select ‘Other Options’.

  3. Select Text Me New Codes or Call me

  4. Enter the code sent via text message to your phone, or, answer the call and select 5

  5. Select Manage Duo Settings

  6. Select Click to continue

  7. Select ‘Other Options

  8. Select Manage devices

    1. You will be prompted to confirm your identity again with Duo authentication. Repeat steps two through four.

  9. For the device you are wanting to replace, select the option I have a new phone in the device selection box.

  10. Once selected, follow the set-up steps for your new device.

Hardware Token

Hardware tokens can't be used as your only authentication device, but can be added as a secondary option later. To start using a hardware token, it must first be linked to your Odin account at the OIT Help Desk.

PSU employees who are required to use Duo 2FA can request a Duo hardware token at the OIT Help Desk. Replacement hardware tokens will be available for purchase.

Note: Tokens can get "out of sync" if you press the button too many times in a row and don’t use the generated passcodes to sign in. If your token stops working, please contact the Helpdesk. 

To learn more about generating a passcode with a Duo hardware token, visit the following article on Duo website’s Guide to Two-Factor Authentication: Using Duo with a hardware token.

YubiKey Security Key

For instructions on how to enroll and use a YubiKey security key, see YubiKey and Duo Two-Factor Authentication (2FA).

Add Optional Duo Protections 

After enrolling a device, you will automatically receive certain protections for PSU systems based on whether you are a PSU student or employee.

  • PSU employees automatically receive protections for Single Sign-On (SSO) and the Virtual Private Network (VPN).

  • PSU students automatically receive protection for the Virtual Private Network (VPN). To receive the Odin password extension benefit, students must also add protection to Single Sign-On (SSO). Instructions can be found at Update protections in Duo Two-Factor Authentication (2FA).

Configure Duo to Remember You on Trusted Devices

On trusted devices, you can configure Duo to remember you for 30 days. To do this:

  1. Sign in to the Odin Account Manager (OAM) at oam.pdx.edu.

  2. Select Manage Duo Settings.

  3. You will be prompted to confirm your identity with Duo authentication..

  4. After authentication, you will be asked “Is this your device?” Selecting “Yes, this is my device” will have Duo remember your authentication choice for 30 days.

Screenshot of the Is this your device dialog box with options to select yes or no.

Manage your Devices

You can add or remove a device at any time after enrolling in Duo 2FA. You also have the option of changing a device profile's name or changing your default device. To manage your devices, follow these steps:

  1. Sign in to the Odin Account Manager (OAM) at oam.pdx.edu.

  2. Select Manage Duo Settings.

  3. You will be prompted to confirm your identity with Duo authentication. Instead, select Other options, then Manage Devices.

  4. You will be prompted to authenticate again. This time, continue with authentication.

  5. You can now choose the action you'd like to perform:

    • Change a device’s profile name.

    • Change your default device.

    • Enroll another device.

    • Remove a secondary device.