2026 MFA policy rollout
Attention: Fall 2026 Duo Policy Changes:
Emory is strengthening its Multi-Factor Authentication (MFA) policy to better protect Emory users, systems, and data. As part of this change, SMS text passcodes and time-based passcodes (Duo Mobile passcodes and Duo hardware tokens) will be retired by the end of 2026 because they are more vulnerable to phishing. Duo Verified Push and passkeys methods (Windows Hello, Touch ID, Face ID, YubiKey, or most passkey in your browser or password manager) will continue to work. Duo Verified Push is Emory’s recommended free MFA method and should be the best for the of majority users. Otherwise, if you cannot use Duo Verified Push, you will need to setup a passkey method this fall to comply with the new policy that goes into effect this fall. For users only using MFA methods that are going away (SMS and Passcodes), we will be sending emails with more details.
Some methods are being retired. Do not rely on these going forward:
- Text message (SMS) passcode - being retired; usable only during enrollment.
- Duo Mobile passcode (a one-time code you generate in the Duo Mobile app) - being retired along with SMS.
- Phone call (“Call Me”) - already retired.
Use Duo Verified Push, a passkey, or a YubiKey instead.
