Multi-factor Authentication

Duo Multi-factor Authentication

UNE requires Multi-factor Authentication (MFA) as a second layer of security to your online accounts. Verifying your identity using a second factor (like your phone or other mobile device) prevents anyone but you from logging in, even if they know your password. You will have already had similar experiences when using myGov, Apple ID, Google account and banking apps.

Rollout Progress

UNE has completed the rollout for the entire staff and affiliate cohort with a few special case accounts remaining, having our staff and affiliate members protected by MFA will improve the University's security immensely. We're currently in the process of expanding Multi-Factor Authentication to more services and applications we use which will protect staff, affiliate, and student data. Once the rollout has been completed, we will begin taking steps towards enrolment for the student cohort. At present, there is no set date for when this will occur.

How It Works

Three steps to stronger authentication

The University of New England (UNE) has selected the Duo Security service as the preferred service for MFA throughout the technology infrastructure. This is one of the most widely used MFA services globally and is recognised for its simplicity in implementation and use. When you log into an application that is enabled for MFA (contains sensitive information), you will need to respond to a Duo prompt.

  1. Enter UNE username and password as usual
  2. Use your phone to verify your identity
  3. Securely logged in

Image showing relationship between UNE and DUO to provide the solution for Multi-factor authentication

MFA Fatigue

An MFA fatigue attack – also known as MFA Bombing or MFA Spamming – is a social engineering cyber-attack strategy where attackers repeatedly push Multi-Factor Authentication requests to the target victim’s email, phone, or registered devices. The goal is to coerce the victim into confirming their identity via notification, thus authenticating the attackers attempt at entering their account or device. This generally implies that your account has been compromised, if this occurs on your UNE staff account please reset your UNE password as soon as possible and reach out to IT Support. As MFA has not been rolled out to students as of yet, this attack method does not apply to their student accounts. However, this does apply to personal accounts that have MFA enabled.

Please do not re-use passwords for different online accounts, if you do you could become the victim of a domino effect of compromised accounts.

More information can be found in the below video or on our CISO Corner Blog.

Frequently Asked Questions

What is MFA?

Multi-factor Authentication (MFA) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more pieces of evidence that can only be known or held by the user. These are generally defined as:

  • Something you know (password or Personal Identity Number)
  • Something you have (a security token or a smart device)
  • Something you are (a facial recognition, swipe pattern or fingerprint)

This approach not only increases the strength of the user authentication process, but also removes the ability of cyber-attackers to steal authentication credentials for resale.

There is more detail in this Pulse article

What is Duo Mobile?

Duo Mobile is a mobile application (app) that you install on your smartphone or tablet to generate passcodes for login or receive push notifications for easy, one-tap authentication on your mobile device.

Does installing Duo Mobile give up control of my smartphone?

No. Duo Mobile has no access to change settings on your phone. Duo Mobile cannot read your emails, it cannot see your browser history, and it requires your permission to send you notifications. Lastly, Duo Mobile cannot remotely wipe your phone.

The visibility Duo Mobile requires is to verify the security of your device, such as OS version, device encryption status, screen lock, etc. We use this to help recommend security improvements to your device and you always are in control of whether or not you take action on these recommendations

Does the authentication process use up my phone internet data?

Almost none, Duo Push authentication requests require a minimal amount of data -- less than 2KB per authentication.

For example, you would only consume 1 megabyte (MB) of data if you were to authenticate 500 times in a given month.

This is roughly equivalent to loading one webpage on your smartphone.

Can Duo see my password?

No. Your password is only verified by your organisation and never sent to Duo.

Duo provides only the second factor, using your enrolled device to verify it’s actually you who is logging in.

How will problems with authentication be managed? 

Support will be available through UNE IT Support.

What if I cannot, or do not want to use my personal device? 

UNE's preferred method of authentication is Duo Push.  Staff are encouraged to use their mobile device for MFA to provide a quicker, safer and more secure authentication option (read more about why).

UNE Staff can request a DUO Security token as an alternative to using a mobile device if their smart phone is incompatible or they are unwilling to use their personal device.The security token can be used to generate a One Time Passcode (OTP) which you will need to enter into the login screen when prompted.

You will be required to complete an online request form that will require a valid reason for not using your mobile device and approval from a cost centre approver. Once approved the security token can be collected from UNE campus. When you collect your security token you will be required to validate your identity and your security token will be registered against your user credentials.

There is no charge for the initial issue of an approved DUO Security token.  It is the responsibility of the individual staff to ensure the safety and security of this token.  The tokens are not to be shared between staff members or used for any other purpose.

If you enrol your mobile device after being issued a security token, the security token will be disabled and must be returned to the UNE IT Service Desk for reissuing to another user.

Replacement of Tokens

If the DUO Security token is lost, broken or stolen, there will be a charge for the replacement DUO Security token (currently $30).  The cost of the replacements token will be borne by the individual.

Would Duo Mobile need access to my mobile number?

Duo Mobile may use your mobile number in order to authenticate the device during initial set-up. UNE would not use your number for any other purpose.

Duo Mobile Privacy Information

UNE Privacy Notice – Multi-factor Authentication

Privacy: Personal information is collected to ensure UNE systems and data assets stay secure.  The personal information provided will be managed in accordance with the Privacy and Personal Information Protection Act 1998 NSW (PPIP Act) as outlined in the UNE Privacy Management Plan. You can view further information about the management of your personal information via this Privacy Notice and raise any questions or concerns with the UNE Privacy Officer via privacy@une.edu.au.

Why does Duo Mobile app need access to my camera?

When using MFA for the first time and enrolling your device the Duo Mobile app will use your camera to scan a QR code displayed on the screen.

What if I lose my phone?

Please contact IT Support and we can assist you with enrolling your replacement device into our DUO MFA service.

Do I need a smartphone to use two-factor authentication?

No, having a smartphone makes for an easier and more secure experience with Duo Push.

Read about why Duo Push is the best authentication method

However,  there is an alternative Duo Security Token than can be supplied.  To order your Duo Security Token please complete the Request a Security token for MFA form

How will I know when I am required to use MFA?

You will receive emails in the lead up to the date that you will need to enrol in Duo.

On the enrolment day you will receive an email with a link and easy to follow on screen steps.

Guide to Two-Factor Authentication · Duo Security

What is the recommended Multi Factor Authentication method?

If you have a smartphone or or tablet, we recommend Duo Push, as it is quick, easy-to-use, and secure.

Read about why Duo Push is the best authentication method

Can I use one method of authentication at home and another at work?

If you have access to the “My Settings & Devices” link (the self-service portal) at the Duo Prompt and are currently able to authenticate with a device, you may:

Add additional devices

  • Designate your “default” device that receives authentication requests in addition to your preferred authentication method
  • Deactivate Duo Mobile if you got a new phone but kept your number
  • Change the name of your device (ex. “Personal Cell” or “Work Phone”)
  • Remove a device

Learn more about managing your devices

I live in a mobile phone blackspot, will the Security Token still work there?

Yes the Duo Security Token will still work.  However, the computer that you are trying to access will need to have access to the internet.

Privacy - where is the data about authentication stored and does it include geographic markers

Duo Mobile Privacy Information

UNE Privacy Notice – Multi-factor Authentication

Privacy: Personal information is collected to ensure UNE systems and data assets stay secure.  The personal information provided will be managed in accordance with the Privacy and Personal Information Protection Act 1998 NSW (PPIP Act) as outlined in the UNE Privacy Management Plan. You can view further information about the management of your personal information via this Privacy Notice and raise any questions or concerns with the UNE Privacy Officer via privacy@une.edu.au.

How will Multi-function Authentication change my user experience? 

When logging in to an application that is protected by Duo, you will still enter your username and password. After inputting your login information, Duo requires you to complete a method of second-factor authentication. Duo does not replace or require you to change your username and password. Think of Duo as a layer of security added to your pre-existing login method.

Why do we need Multi-factor Authentication?

Login credentials are more valuable than ever and are increasingly easy to compromise. Over 90% of breaches today involve compromised usernames and passwords.

Two-factor authentication enhances the security of your account by using a secondary device to verify your identity. This prevents anyone but you from accessing your account, even if they know your password.

Will Duo work with Microsoft Office on my home PC?

DUO works with Microsoft Office 365 but does not work with Office 2016 or Office 2013 without additional technical configuration. Earlier versions of Microsoft Office are not supported.

If you don’t have Office 365 at home, we recommend you claim your free license for up to five Microsoft Office 365 installations at home.  Contact UNE IT Support for more information.

What will the enrolment process look like for me?

Watch this video Guide to Multi-factor Authentication-Enrolment Guide on our vendors web page to get a feel for the process.

Why do I have to setup a passcode on my phone?

To prevent a criminal from accessing your personal information and UNE's sensitive
information from a lost/stolen phone, a passcode or equivalent is required on the device being used for MFA.

What are the tax implications from using your own phone for MFA at work?

For any questions relating to tax, please seek advice from a qualified tax agent.

What if I plan on travelling overseas?

Duo does not operate in all countries. If you intend on travelling overseas to any of the countries linked below and require access to your UNE account at the time, please contact our IT Support team.

The list of countries where Duo does not operate can be found here.

Privacy

Personal information is collected to ensure UNE systems and data assets stay secure.  The personal information provided will be managed in accordance with the Privacy and Personal Information Protection Act 1998 NSW (PPIP Act) as outlined in the UNE Privacy Management Plan. You can view further information about the management of your personal information via this Privacy Notice and raise any questions or concerns with the UNE Privacy Officer via privacy@une.edu.au.

Download the UNE Privacy Notice - Multi-factor Authentication