MFA requires the use of multiple methods or devices to authenticate your identity when logging into University of Maryland accounts, services, or systems protected by the Central Authentication Service (CAS). MFA services for UMD are provided by Duo Security.
You can self-enroll in MFA by visiting the Multi-Factor Authentication Profile page. Step-by-step instructions on this process are available in the Enroll your Mobile Device in Multi-Factor Authentication article.
|If you intend to use Bypass Codes only to complete multi-factor authentication, contact your departmental IT representative or the Service Desk for assistance with enrollment.|
You can have multiple devices enrolled to use with MFA, though one of them must be set as the default device. In fact, DIT recommends having a backup authentication method in place, in the event you misplace your primary method. This backup method may be a copy of pre-generated bypass codes, a mobile device, Call Back, or a hardware token (see Overview of Multi-Factor Authentication and Login Methods to learn more about methods of authenticating).
After enrolling your first device, you will be able to manage your devices and methods at the Multi-Factor Authentication Profile. Review our step-by-step instructions for adding an additional device to your Duo profile.
It is highly recommended that you obtain Bypass Codes before removing or adding a new device to your Multi-Factor Authentication Profile.
UMD utilizes Duo to provide multi-factor authentication services. Duo supports the following devices and operating systems:
To learn more about devices supported by Duo, visit Duo's Guide to Two-Factor Authentication.
If you get a new device, you can add it to your list of enrolled MFA devices at the Multi-Factor Authentication Profile site as long as you still have a method of MFA authentication--such as your old device, or a bypass code--to access the MFA Profile site.
If you no longer have a method of MFA authentication to log into the Multi-Factor Authentication Profile site, and would like to add a new device, you will need to contact the Service Desk for assistance.
If you have two or more devices enrolled in MFA and one device is lost or stolen, you visit Multi-Factor Authentication Profile to remove it.
If you only have one device you will need to contact the Service Desk for assistance to have the device removed. You may need to undergo additional ID proofing steps to re-enroll in MFA.
Alternatively, a hardware token can be used to generate a passcode when traveling internationally or when disconnected from the internet.
If you continue to encounter problems, contact the Service Desk for assistance.