Duo Multi-Factor Authentication (MFA)
Emory University and Emory Healthcare use Multi-Factor Authentication (MFA) to help protect our users’ access, data, and IT systems against unauthorized access and cyber threats. MFA is managed by Emory University’s Office of Information Technology (OIT) in partnership with Emory Digital. Emory uses Duo Security as its MFA platform, with Duo Verified Push as the primary recommended authentication method.
Attention: Fall 2026 Duo Policy Changes
Emory is strengthening its Multi-Factor Authentication (MFA) policy to better protect Emory users, systems, and data. If you are still using SMS/Text or Passcodes for your Duo MFA, please read more about the change here (https://it.emory.edu/security/two_factor/2026rollout.html.)
Why Emory implemented Duo MFA
Cyber-attacks on higher education and health care are increasingly sophisticated and frequent. Passwords alone have proved to be an ineffective means to protect Emory user access, data, and IT systems. Multi-factor authentication uses more than one factor (like passwords) to vet the user, because passwords can be stolen and reused. Therefore, as long as the user properly uses MFA, their access should be protected from most attacks. For this reason, MFA technologies have been widely adopted across all types of industries and are standard practice whenever there is something digital that matters.
How can I safely use Duo MFA?
Threat actors want to steal your password and trick you into completing an MFA challenge for them, so they can steal your access and data or perform actions as you. Therefore, never respond to an MFA challenge that you did not initiate. This is the single most important thing you can do to safely use Duo MFA and protect your digital access and assets.
How Duo works
After you provide your Emory NetID and password, Duo confirms your identity with a second factor - something you have. The supported methods are (in order of preference):
- Duo Verified Push (recommended) - a Verified Push code appears on your Emory application login screen; you enter the code in the Duo Mobile app to approve.
- Platform Passkey (Windows Hello for Business or Apple Touch ID).
- Roaming Passkey (browser-based passkey, iOS password manager).
- Hardware Passkey (YubiKey) - an Emory-approved USB / NFC hardware key that supports passkeys.
- Legacy methods supported
- SMS and Duo passcode may be supported for some users until eliminated this fall (see Attention: Fall 2026 Duo Policy Changes below). If this option appears for you, you can use it until it is eliminated, but it is not recommended. New users should not set up these methods, and existing users should transition when they can to the recommended Duo Verified Push or a passkey method.
Recommended first-time enrollment (Duo Mobile)
We highly recommend performing your first-time enrollment from a regular computer, or better yet your assigned Emory device, rather than a mobile device. Here is the initial setup for Duo Mobile for users who can use a smartphone or smart tablet:
Alternative first-time Duo enrollment (Passkeys)
If you don’t have or cannot use a smartphone or smart tablet, perform initial enrollment using a supported passkey method:
- Passkey Enrollment
- Security Key (Yubikey) Enrollment
- Mac OS Touch ID Enrollment
- Windows Hello Enrollment
Additional Duo method enrollment
When you have time, you are encouraged to register an additional device or MFA method in case there is an issue. You can register multiple devices and choose which one to use at login.
