Duo Verified Push and Risk-Based Authentication

Overview

Beginning this fall, UAH will begin implementing Duo Verified Push and Risk-Based Authentication, to protect campus accounts against unauthorized access. This update changes how Duo authentication works when logging into Single Sign-On (SSO) web services — including myUAH, Canvas, and Google Workspace.

  • What's Changing: When logging into SSO services via a web browser, Duo Push notifications may now ask you to enter a 3-digit code shown on your computer screen into your Duo Mobile app.
  • What's Staying the Same: Logging into your office desktop/computer, hardware tokens, phone calls, SMS passcodes, and biometric logins (Touch ID / Face ID) remain completely unchanged.

Why We're Making This Change

Phishing and account takeover attempts targeting UAH students, faculty, staff, and affiliates have become increasingly sophisticated. A primary factor driving this update is combating "MFA Fatigue" (Push Harassment).

When bad actors obtain a user's password, they often flood the user's phone with repeated login notifications in hopes the user will tap Approve simply to stop the phone from buzzing. With Duo Verified Push, an attacker cannot access your account merely by spamming your phone. Because the 3-digit verification code appears only on your web browser screen, an attacker won't have the code needed to complete the login attempt.

 

Don't Worry — Nothing Is Wrong with Your Account!

If you receive a 3-digit code prompt, it does not mean your account has been hacked or that you did something wrong. It simply means Duo is running a routine security check or noticed a minor change in your login details (like a new browser or Wi-Fi network).

 

How Duo Verified Push Works

Instead of simply tapping Approve on your mobile device, you will match the number displayed on your computer screen.

Traditional Duo Push (Old) Verified Duo Push (New)

You tap Approve on your phone screen to complete your login.

You enter the 3-digit code shown on your browser screen into the Duo app.

(Image: Traditional Duo Push prompt showing Approve / Deny buttons)

(Image: Verified Duo Push prompt showing 3-digit code entry field)

Step-by-Step Login Instructions

  1. Enter your UAH ChargerID and password on the UAH login web page as usual.
  2. If prompted for a Verified Push, a 3-digit code will appear on your browser screen.
  3. Open the Duo Mobile notification on your phone, type the 3-digit code, and tap Verify.

When to Expect a 3-Digit Code

Verified Push is paired with Risk-Based Authentication to ensure security without creating unnecessary friction in your daily routine. You will not have to enter a 3-digit code every single time you log in.

Duo remembers your trusted devices and will only require a 3-digit code:

  • Once every 7 days on your primary computer and web browser.
  • When unusual login behavior is detected, such as logging in from a new computer, an unfamiliar web browser, an off-campus network, or a new geographic location.

CRITICAL SECURITY WARNING

Never enter a 3-digit code if you are not actively trying to log in.

OIT will NEVER ask you to enter or share a 3-digit code via phone call, text message, or email. If you receive a Duo notification on your mobile app when you are not trying to log in:

  1. Tap "I'm not logging in" inside the Duo Mobile app to report the fraudulent login attempt.
  2. Immediately change your UAH ChargerID password.

     

  3. Contact the OIT Help Desk to alert security staff.

     

What Do You Need to Do?

  • If you already use the Duo Mobile app: Ensure your app is updated to the latest version on your mobile device. You're all set!
  • If you use SMS, Phone Calls, or Hardware Tokens: No action is required; your login method will work exactly as it does today.
  • If you do not currently use the Duo Mobile app: OIT strongly encourages installing the free Duo Mobile app on your smartphone, as it is the fastest and most secure authentication method. If you have a device incapable of running the app, a limited number of hardware tokens are available.

Still Need Help?

If you have questions about Duo Verified Push or need assistance setting up the Duo Mobile app, please contact the OIT Help Desk.