Duo Multi-Factor Authentication (MFA)
Emory University and Emory Healthcare use Multi-Factor Authentication (MFA) to help protect users, data, and IT systems against cyber threats. MFA is managed by Emory University’s Office of Information Technology (OIT) in partnership with Emory Digital. Emory uses Duo Security as its MFA platform, with Duo Verified Push as the primary recommended authentication method.
Attention: Fall 2026 Duo Policy Changes:
Emory is strengthening its Multi-Factor Authentication (MFA) policy to better protect Emory users, systems, and data. As part of this change, SMS text passcodes and time-based passcodes (Duo Mobile passcodes and Duo hardware tokens) will be retired by the end of 2026 because they are more vulnerable to phishing. Duo Verified Push and passkeys methods (Windows Hello, Touch ID, Face ID, YubiKey, or most passkey in your browser or password manager) will continue to work. Duo Verified Push is Emory’s recommended free MFA method and should be the best for the of majority users. Otherwise, if you cannot use Duo Verified Push, you will need to setup a passkey method this fall to comply with the new policy that goes into effect this fall. For users only using MFA methods that are going away (SMS and Passcodes), we will be sending emails with more details.
Why is Emory implementing Multi Factor Authentication?
Attacks on higher education and health care computers and networks are increasing in sophistication. Passwords alone have proved to be an ineffective means to mitigate the current threat to our information resources. Multi-factor authentication decreases the risk of compromises and data breaches by requiring Multi factors to confirm your identity – something you know (your password) and something you have (e.g., app push, text, or call to your mobile phone or landline). It is now common in online banking and other high-security applications. For example, if you have ever received a code via text message and had to use it to log into a website, you have used Multi-factor authentication.
How Duo works
After you sign in with your Emory NetID and password, Duo confirms your identity with a second factor - something you have. Your options:
- Duo Verified Push (recommended) - a 3-digit code appears on your login screen; you enter it in the Duo Mobile app to approve.
- Roaming Passkeys (Browser based Passkey, IoS password manager)
- Windows Hello for Business, Touch ID
- Security key / YubiKey - an Emory-approved hardware key.
Note: Text message (SMS) is not an accepted verification method. It may only be used during initial enrollment. The retired “Phone Call” option is also no longer available.
You can register multiple devices (up to 100 per method) and choose which one to use at login. Manage everything from the Emory Duo Self-Service Portal.
