Setting up Duo Mobile MFA

Multi-Factor Authentication (MFA) adds a second layer of security to your SJSUOne account by verifying your identity using a second factor provided through the free Duo Mobile app. Duo can prevent someone from logging into your account, even if they know your password. To activate Duo MFA for your SJSUOne account you will need to scan a QR code on a screen using your phone. You will need two devices to complete this process.

  1. Install the Duo Mobile app on your phone or tablet
  2. Set up your SJSU account, using your computer or a second mobile device. The first time you log in to one.SJSU, a series of prompts will guide you through the self-service Duo Mobile MFA enrollment process.
  3. Set up Duo Restore to make it easy to move to a new mobile phone in the future

You will need to install Duo Mobile on one device, and sign in to one.sjsu.edu on another device.

Set up Duo Mobile on your Smartphone

Note: If you do not have a smartphone or do not want to install DUO on your phone, you may contact the IT Service Desk (408-924-1530) to request a hardware token (key fob). Requesting a key fob will take more time than the self-service Duo Mobile app activation process.
IMPORTANT: To set up two-factor authentication with DUO, you will need two devices -- one to show a QR code and one to scan the QR code.
  1. Go to The Spartan App Portal at One.SJSU
  2. Click the "Sign In" button on the top right side of the screen under the search bar
    • SJSUOne Homepage
  3. Enter your SJSU ID and password on the SJSU Single-Sign On page
  4. Click "Sign In" at the bottom of the page
    • SJSU Sign In Portal
  5. A prompt to set up DUO will pop up:
    • Duo Security Setup Prompt
  6. On the “What type of device are you adding?” page, select the type of device you’re enrolling (“Mobile Phone” or “Tablet”)
  7. Click the "Continue" button
  8. If you are enrolling a mobile phone for Duo Mobile you will have to do the following steps (If you are enrolling a tablet for Duo Mobile, skip to step 10):
    • Enter your phone number (including area code)
    • Check the box to confirm that the number is correct
    • Click the "Continue" button
  9. Select the type of device (iOS or Android)
  10. Click the "Continue" button
  11. On your device for Duo Mobile, download and install the “Duo Mobile” application from the app store
  12. On the computer/device logging in to SJSU, Click the “I have Duo Mobile” button
  13. On your device for Duo Mobile, open the newly-installedDuo Mobile application and tap the “Add/Setup Account” button on the upper right corner. You may need to allow the application to access the camera on your device
  14. In the Duo Mobile app, click “Use QR code”
  15. Move your camera to scan the QR code shown on the computer screen in the Duo Mobile camera view.
  16. Click the "Continue" button
  17. You will see a message that says “Account Linked”
  18. Click “Send Me a Push” and a push notification will be sent to your device
  19. On your device, tap “Approve” 
When you complete your Duo Mobile enrollment: You will be prompted by OKTA to provide a security question and a secondary email.

Choose a security question from the drop down menu, or make your own question then provide an answer.

The secondary email should match the email you used when you applied. If you need to update your secondary email, you must first complete all OKTA steps.

Click “Create Account.” You will be able to access MySJSU.

For instructions on changing  your secondary email, see Set My Preferred Email Address.

Congratulations! You are now enrolled in DUO two-factor authentication and your SJSUOne ID account is fully activated.

Setup recovery with Duo Restore

If you have an iPhone or iPad, Duo uses iCloud Backup and iCloud Keychain to back up your Duo Mobile app and restore it when you set up a new phone🔗. Please ensure your phone is backing up to iCloud so you can restore to a new phone without losing your Duo Mobile.

Android phones and tablets need to enable Duo Restore in the Duo Mobile app🔗. When choosing a Google Account to back up to, choose the personal Google Account you used to activate your phone when you purchased it. When installing on a new phone set up with the same personal Google Account, you can choose to restore your Duo settings from that account.

Enable/Disable Auto-Push for MFA

Would you like to speed up your login time with multi-factor authentication? Turn on auto-push to automatically be prompted by the authentication method of your choice in the Duo Mobile app.

To turn on auto-push, follow the steps listed below:

  1. Visit the Multi-Factor Authentication Profile page.
  2. Enter your SJSU ID and password in the username and password fields. Click Login.
  3. Before Authenticating with MFA, Click My Settings & Devices under Settings.
    • Duo Mobile Settings Button
  4. Duo will ask you to complete your multifactor process. Please complete your multi-factor authentication as you normally would
  5. Under Default Device, select your default device from the drop-down menu.
  6. Under When I log in, select the Automatically send this device a Duo Push option.
    • Duo Mobile Push Selection
  7. Click Save.

 

Support

Login support is provided by the IT Service Desk. You may:
Because login and MFA are security services, the IT Service Desk must confirm your identity before providing assistance.