DUO Account Security
Enroll in or Make updates to Duo
Account security has never been more important as an increasing number of businesses and users are targeted by hackers. Password management has always been a weak point in systems that rely solely on a knowledge-based authentication factor (something you know). Passwords are reused across multiple systems, making all accounts vulnerable when a reused password is leaked.
When all is said and done, passwords are simply no longer reliable as the sole method of authentication to sensitive systems. A better security option is having two (or more) factors needed before gaining access to an account. These come from different categories:
- Something you know (password)
- Something you have (phone)
- Something you are (biometric, such as a thumbprint)
What is Duo Account Security?
The UofM Single Sign-On System (SSO) now includes Multi-factor Authentication (MFA) capabilities. This means that users protect their accounts by requiring a second means to authenticate in addition to their password. Passwords alone have become increasingly easy to hack and MFA substantially reduces the threat of unauthorized access to accounts.
The ITS Security team has implemented MFA using a product from Duo Security, which allows users to use their phones as a second factor for authentication. Users can use the Duo Mobile app to enroll their smartphone or tablet to receive online push notifications, or generate a one-time passcode. Other methods of second factor authentication are available with Duo.
Am I required to enroll in Duo Account Security?
As of February 2021, all students, faculty and staff are required to enroll in Duo Account Security to protect their accounts.
How do I enroll or change my devices in Duo Account Security?
To enroll in Duo or to see your settings, login to https://iam.memphis.edu/duo. If you are setting up your account, you will be guided through the process of registering your device(s). Once you have enabled Duo, you will be prompted to authenticate with your second factor the next time you log in to any SSO-protected web resource. New hires are guided through the enrollment process during orientation.
After at least one device is registered with Duo, you can also manage devices via the Duo Device Management dashboard. Initiate a Duo authentication request, then select the "Other options" link. Choose "Manage Devices" at the bottom of the menu to see, edit, and add your devices in Duo.
We strongly recommended that you register more than one device in Duo in case there is an issue with your primary device.
If you change devices, even if you keep the same phone number, that device needs to be registered with Duo to work. Register the new device at the above link.
Where can I get help with Duo Account Security?
Please review the Documentation and Support resources below.
How can I give feedback on the Duo Account Security service?
The ITS Security team would appreciate any feedback that you might have regarding your experience using Duo or registering devices within iAM. Suggestions for improving the service can be submitted via the ITS Suggestion Box.
Frequently Asked Questions
Why is this service necessary?
Threats such as social engineering and phishing increase the risk of an individual
inadvertently sharing their username and password. MFA helps protect critical University
resources by requiring an additional piece of information or factor during login that
a hacker will not have access to. Even if a password is suspicious for an account,
the account cannot be used to access critical or important University information.
What methods are supported by Duo MFA?
- Duo App - When paired with the Duo app installed on a smartphone or tablet, Duo can send
a push message to the app. The user only has to approve the push to login. The Duo
app is free and can be downloaded from the Apple Store or Google Play. Note: The Duo application may be restricted in some international countries, and the client
may need to download the Duo Mobile APK App directly from Duo website.
- Passkeys - A passkey is an authentication method that uses your device to verify your identity.
A passkey might use your device’s fingerprint scanner or camera to identify you. For
guidance on using passkeys with Duo, view the passkey creation guide.
- One-time passcodes - The Duo app can also be used to generate one-time passcodes in the event that the
device does not have an WiFi or cellular data connection.
- Duo tokens - Duo tokens can be used to generate a code or token when an individual has no usable
phone options or if traveling internationally. The token will need to be kept near
or on the person to whom it is assigned, as it will be needed whenever you attempt
to login a system protected by Duo. The price for a Duo token is $20. More info below.
- Bypass codes - A bypass code allows you to log in using Duo when you do not have access to your
registered device. For example, if you lose your phone, you can still access your
account using a bypass code. UofM Duo users have access to a list of single-use bypass
codes in iAM. These bypass codes can be saved in a secure location offline in case
you ever need to log in without access to a registered device. All bypass codes can
be used only once and only for your account.
- Accessing Your Bypass Codes:
1. Log in at iam.memphis.edu.
2. Click Duo Account Security.
3. Click the Bypass Codes button.
4. Write down one or more bypass codes and save them in a secure location.
Students can also request a bypass code to be sent to their personal email address. You must have a personal email address registered in Banner to use this option. Generating a bypass code in this way will reset any previous bypass codes, including those stored in iAM. For instructions on finding your bypass codes or sending one to yourself via email, visit the Duo Bypass Code Self-Service webpage.
If you are unable to generate a bypass code for yourself, the ITS Help Desk can provide a temporary bypass code for account holders.
- Accessing Your Bypass Codes:
Please see the Duo Account Security documentation for further assistance with Duo MFA methods.
When do I have to use Duo?
Duo is required whenever you log on to a website or online service protected by our
Single Sign-On (SSO) authentication service, such as the myMemphis portal, eCourseware,
email, and others. It is not required to log on to your local computer.
Do I have to do this every time I log on?
You will have to use Duo MFA the first time you log on to a website behind our SSO
authentication service. You will not be prompted to use Duo on other sites if you
already have an active logon session to another site. If you restart your browser
or computer, you may be prompted to use Duo again. You can also use the "Remember
me" option at the bottom of the Duo screen to remember your Duo session on that device
for a seven day period.
Who is required to use multi-factor authentication?
As of February 2021, all students, faculty and staff are required to use Duo MFA to
secure their access to University computer resources and mitigate the risk of University
data being exposed in the event of suspicious activity.
What is a Duo Token?
The Duo token is a small, thumb-sized device that generates 6-digit codes or tokens
to be used during Duo sign-on. The device requires no internet connection, no phone
number, and is suitable for situations where the mobile app or phone cannot be used,
such as in secure areas or when traveling.

There will be a 5–7 day processing period for tokens. The user will be notified when their token is ready for pickup. The Duo token must be picked up in person by the requestor from Administration Building Room 100, no exceptions. It cannot be picked up by someone else other than the original requestor.
Duo tokens are available for $20 and can be charged to a departmental index #. Tokens that are lost or damaged are subject to a $20 replacement fee.
Duo tokens must be assigned to specific user accounts and cannot be shared. For faculty and staff, a Duo token can be requested via the Duo Token Request form.
Students can order a Duo Token on the student Duo Fob Request web page.
What if I don't have access to my registered phone?
To ensure uninterrupted account access, we recommend users enroll multiple Duo authentication
methods (for example, a laptop passkey, a mobile device, and a tablet). You should
also keep a secure list of bypass codes in case none of your devices are available.
My phone has an international number. Why am I having trouble using Duo?
International phone numbers should be entered in the correct format: The plus sign
(+) followed by the country code and full number with no spaces or dashes. Example:
+911234567890.
If you are experiencing problems setting up Duo with an international number, refer
to the Duo Account Security documentation for more information. For further assistance, please contact the ITS Service Desk
at 901.678.8888.
I travel frequently and don't always have cell service. How can I use the Duo service?
The Duo app, installed on a smartphone or tablet, can be used to generate a one-time
passcode even when the device does not have an internet connection. Please see the
"Using the Duo Mobile Application in location with poor cell coverage or no WIFI"
section of the Duo Account Security documentation. If you are traveling internationally, you can also request a Duo token to use in
cases where taking your smartphone or tablet are not safe or feasible.
Why can't I receive an email as a second factor?
The Duo MFA service does not support email as a second factor.
I use the Duo services at another University. Do I need to install a different app?
You can use the same app but will need to add your UofM account. Simply open your
existing app and press the (+) icon to scan the barcode during account setup in iAM.
Duo isn't working for me. How can I get help?
Please see the full UofM Duo Account Security documentation or contact the ITS Service Desk at 901.678.8888.
Documentation and Support
Please review the resources below for guidance on using Duo. For further assistance, contact the ITS Service Desk at umtech@memphis.edu or call 901.678.8888.
Note: If you cannot log into iAm, you will need to contact the Service Desk for assistance at 901.678.8888.
Infographics:
Documentation:
UofM Duo Account Security Full documentation (PDF)
Duo official documentation: iOS and Android
UofM Duo Passkey Creation Guide (PDF)
Note: Access to this service may be limited in compliance with sanctions announced by the Office of Foreign Assets Control.
