Duo Mobile on Android - Guide to Duo security with two-factor authentication (2023)

The Duo Mobile app makes authentication simple: just tap "Approve" on the login request sent to your Android device. You can quickly generate login passwords even without an internet connection or cellular service.

If you need help installing or using Duo Mobile, contact your organization's IT helpdesk or Duo admin.

Are you looking for Duo for your organization? More information on doublesMulti-Factor Authentication (MFA)solutions

Satisfied

  • Changes to Duo Mobile
  • Install Duo Mobile
  • Activate Duo Mobile for the first time
  • double press
    • Duo push and notifications
    • fingerprint verification
    • Verified duo push
  • passwords
  • Add more accounts to Duo Mobile
  • security check
  • Third Party Accounts
  • edit accounts
  • mobiles Look-Duo
    • adaptive view
    • Dark Theme
  • Troubleshooting
    • Push troubleshooting
    • Troubleshooting encryption

Changes to Duo Mobile

We've redesigned Duo Mobile to offer an updated login experience. Learn more about what's new in Duo Mobile version 4 in this video tutorial:

Duo Mobile on Android - Guide to Duo security with two-factor authentication (1)

Install Duo Mobile

For the latest version of Duo Mobile, go toGoogle Play.

Supported platforms:The current version of Duo Mobile supports Android 8 and higher.

Duo does not offer official support for non-standard custom Android distributions such as OnePlus, LineageOS, or ColorOS, nor is Duo Mobile compatible with ChromeOS.

To see which version of Duo Mobile is installed on your device, go to AndroidIdeastap no menuto form, scroll down and tapmobiles Duo. The Application Information screen displays the version.

Activate Duo Mobile for the first time

If youSign up for Duo for the first timeand want to add an Android device or use Duo Push, you will see a QR code that you can scan with the Duo Mobile app to complete activation.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (2)

Launch Duo Mobile and tapcreate an account.

(Video) Duo Two Factor Authentication Setup

Duo Mobile on Android - Guide to Duo security with two-factor authentication (3)

Tap to continue adding your first Duo account to Duo MobileUse a QR code.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (4)

Use your camera to scan the QR code displayed by the Duo sign-in in your browser. If you are asked to allow Duo Mobile to take photos and videos, please grant it.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (5)

Give the new account a name to finish adding it to Duo Mobile.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (6)

It's a good idea to take a few minutes to practice forwarding and rejecting Duo authentication requests if you've never used Duo before. TouchAgora-Praxisto step through some training screens like this one. If you are familiar with Duo Mobile to sign in to apps, tapJump.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (7)

Your newly added Duo account will appear in the accounts list. You can now respond to Duo-Push authentication requests or generate passwords to log into apps.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (8)

double press

If you authenticate with Duo Push, you will receive a login request on your phone, just pressto permitto authenticate

Duo Mobile on Android - Guide to Duo security with two-factor authentication (9)

If you get an unexpected login prompt, tapdenyto reject the application. You will be asked if the login is suspicious. If you're not trying to sign in to a Duo-secured app or service and the prompt isn't recognized, tapSimto notify your organization's Duo admin. If you made a mistake or the login is not suspicious, tapNOdeny the request without reporting it.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (10)

Duo push and notifications

When the duo-push notification appears on the screen, tap on the indicated spot to see the available actions:to permitÖdeny.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (11)

Beatto permitin the notification to complete signing in to the Duo-protected app.

Tapping the push request notification itself (rather than tapping the notification actions) takes you to the full screen Duo Push on Duo Mobile.

(Video) How To Use Instant Restore for Duo Mobile (Android) | Recover Duo-Protected Accounts

If your phone is running Android 13 or later, you may need to enable duo push notifications.

To enable duo push notifications:

  • Tap and hold the Duo Mobile app icon and select itapplication information. On the next Duo Mobile app information screen, tapnotifications. HebelAll notifications from Duo Mobilehold on

fingerprint verification

Duo Mobile also supports fingerprint verification for Duo Push-based logins as an additional layer of security to verify your user identity. If you're using a device with a fingerprint reader, you'll need to scan your finger each time you authenticate with Duo Mobile (if required by your administrator).

If you can't scan your fingerprint with the sensor, you can also approve Duo's authentication request with your device password (the same one you use on your Android lock screen).

Verified duo push

Your organization may want you to enter a verification code when approving a Duo Push request, which will appear in the universal Duo prompt on Duo Mobile. This protects you from approving sign-in requests you didn't make and helps protect your accounts and information.

You must have Duo Mobile version 4.16.0 or later installed on Android 8 or later to verify a Duo Push request with a code.

If your organization requires Duo-Push verification, the universal Duo Prompt will display a six-digit code on your screen when you use Duo-Push to log in to this app.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (12)

Enter the code shown on the Duo Mobile screen and tapCheck overto approve the login request.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (13)

If you enter an incorrect code, tapACCORDINGLYon your phone and return to the Duo Universal prompt where you can click or typeOther optionsto choose a different sign-in method, or try Duo Push again.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (14)

If you get a duo push prompt on your phone and don't try to log in to this app, tapI don't sign upto reject the application. You will be asked if the login is suspicious. TouchSimto notify your organization's Duo admin, or tapNOif you made a mistake or the login is not suspicious.

passwords

Tap an account to get a one-time passcode to log in. It is workingoverall, even in places where you don't have an internet connection or where you don't have cell service.

If the account is a Duo-protected app or service (ieRegistered this device with Duo and activated the app for Duo Push), the passcode displayed is valid until used. TouchUpdate passwordto generate a new duo password.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (15)

If the account is a third-party OTP account (i.e. youSigned in to another service like Gmail and added this device as an authenticator app), you will see a 30 second countdown indicator under the password. If you don't use this password before it expires, the account will be updated with a new password and the countdown will restart.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (16)

If you need to use the password displayed on Duo Mobile in another mobile app, tapCopyand paste it into the other application.

(Video) Getting Started with Duo Security

Add more accounts to Duo Mobile

To add additional accounts to Mobile Duo, tapAdd toin the top right corner of your account list to access the account type selector.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (17)

If the new account you want to add shows a QR code to scan with an authenticator app, tapUse QR codesinceAdd accountList. Scan the QR code with your camera to add the account to Duo Mobile.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (18)

You can also select the type of account you want to add from the list and then add that account by scanning a QR code or by entering an activation code that you received from this app.Learn more about adding third-party accounts to Duo Mobile

security check

Duo Mobile's security check compares your device's settings to Duo's recommended security settings and lets you know if settings on your device don't match.

This Android device has up-to-date software and all security settings recommended by Duo:

Duo Mobile on Android - Guide to Duo security with two-factor authentication (19)

This Android device is a few Android versions behind the latest:

Duo Mobile on Android - Guide to Duo security with two-factor authentication (20)

Tap a detected issue to learn more about that specific setting and how to update your device with the recommended settings.

Tap on the menu and go tosecurity checkon Duo Mobile to see the security status of your device at any time.

Third Party Accounts

Duo Mobile supports generating shortcodes for login to 3rd party TOTP accounts like Google and Dropbox.Learn more "

edit accounts

To make changes to an account in your account list, tap the account to expand it, then tap the three dots in the top-right corner of the account card to open account options.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (21)

BeatMotorto reorder your account list (appears if you have more than one Duo Mobile account). Use the up or down arrows that appear to the left of each account name (or tap and hold the icon on the right side of the account card) to change an account's position in the list. TouchCompletedwhen you're done reorganizing your accounts.

Beatrenameto change the name of an account. Enter a new account name and tapSave on computerto accept the new name.

Delete an account by tappingExtinguish. If you delete an account, you will no longer be able to use it to log in and it will also be removed from your Duo Mobile backup, so you will no longer be able to log inrestore somethingthis later. If you really want to delete this account, tapExtinguishin the confirmation message. TouchCancelif you don't want to delete the account.

Restore Backup

If your administrator has enabled the Duo Mobile backup and restore feature and you have already backed up your Duo protected accounts from the app to Google Drive, you can restore your accounts to a new Android device using the process-guided restore to Duo Mobile. You can also perform account recovery with a third party if you have previously opted for third party account recovery. Start the account recovery process by tappingI have existing accountson the Duo Mobile welcome screen.

(Video) Getting Started with Duo Security (with voiceover)

Check out the full guide to Duo Restore for Android.

mobiles Look-Duo

adaptive view

The list of accounts in Duo Mobile adapts to you. Rotating your device to landscape also rotates your Duo Mobile account list.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (22)

The individual accounts shown in the list also change their appearance, showing full account information when you have only a few accounts and switching to a minimized account view when you have many accounts to minimize scrolling in the app.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (23)

Dark Theme

Duo Mobile dark theme depends on your Android system settings. There is no in-app option to enable dark theme. If your device has system-wide dark settings enabled, Duo Mobile will automatically switch to the dark theme.

Duo Mobile on Android - Guide to Duo security with two-factor authentication (24)

You can enable dark theme on Android in several ways:

  • OrIdeasShowIsand selectDark Theme.
  • Open Android settings from the notification bar and tapDark Theme.

Troubleshooting

see theCommon Problems Guidefor more troubleshooting tips or visit thedual knowledge base. If you can't resolve your issue with Duo Mobile, contact your Duo administrator or your organization's technical support.

Push troubleshooting

If your phone is running Android 13 or later, you may need to enable duo push notifications.

To enable duo push notifications:

  • Tap and hold the Duo Mobile app icon and select itapplication information. On the next Duo Mobile app information screen, tapnotifications. HebelAll notifications from Duo Mobilehold on

If you sign in to a Duo-secured app but don't get the expected Duo Push authentication prompt, try closing and reopening Duo Mobile. Duo Mobile checks for pending push requests each time it is opened. If that doesn't work, check them outDuo Knowledge Base for additional Android troubleshooting steps.

Troubleshooting encryption

Mobile device encryption helps protect the data on your device.

Duo considers your device encrypted if you enable password, PIN, or pattern authentication at startup. Without this setting, your device's encryption is less secure and you may not be able to access services or applications protected by Duo.

To enable encryption on your Android device:

  1. navigate toIdeasSecuritylock screen.
  2. Enable the password, PIN, or pattern to be asked for when starting the device.
  3. If you have a Samsung device, you will also need to enable "Secure Boot" or "Strong Protection" in your device settings and ask for a PIN when starting your device.
  4. Close and reopen Duo Mobile.

If, after completing the steps above, you're still having trouble with the full disk encryption error popping up on Duo Mobile, try disabling this setting and then re-enabling it. This can happen because some Android device manufacturers set a default password to encrypt the phone. While your phone can say it's encrypted, technically it's not fully encrypted until you set your own PIN/password/pattern at startup through your phone's settings. Encrypting with your own password is the most secure option.

Additional points to consider:

  • On Samsung devices, "Secure Boot" or "Strong Protection" will be automatically disabled if you enable access permission.
  • Some newer devices (e.g. Google Pixel) running Android 7.0 and higher support file-based encryption and can be expected to be encrypted when launching Duo without a PIN.

jump up

(Video) Two Factor Authentication (2FA) with Duo

FAQs

How do I turn on two-factor authentication on my Duo Mobile? ›

To activate Duo on your device, open the Duo app on your smartphone, tap the “+” button, and use your smartphone to scan the QR code on the computer screen. On iPhone and Android, activate Duo Mobile by scanning the barcode code with the app's built-in scanner.

Where is the authentication code in Duo Mobile? ›

Open the Duo Mobile app from your mobile device. In the Duo Mobile app, tap Show. You should see a six-digit code displayed, as shown in the example below.

How do you set up two-factor authentication on Android? ›

Allow 2-Step Verification
  1. Open your Google Account.
  2. In the navigation panel, select Security.
  3. Under “Signing in to Google,” select 2-Step Verification. Get started.
  4. Follow the on-screen steps.

Is Duo Mobile two-factor authentication? ›

Duo Mobile combines the knowledge factor and possession factor of authentication to create the world's most trusted 2FA platform. Two other possession factors of authentication are HMAC-based One-Time Password (HOTP) and Time-based One-time Password (TOTP).

How can I retrieve my duo authentication code? ›

Recovering Accounts Manually

Tap Scan QR code and scan the QR code from your third-party account 2FA setup screen, or, to recover a Duo-protected account, access the My Settings and Devices page from the Duo prompt to reactivate the account.

How do I get a QR code for Duo Security? ›

Clicking Activate Duo Mobile in the actions dropdown helps you get an existing device setup to complete secondary authentication. After answering some questions about your device, you will receive a new QR code to scan which will complete the activation process.

How do I set up duo authentication? ›

Set up Google Duo
  1. Step 1: Install Duo. Duo is available on Android phones and tablets. ...
  2. Step 2: Verify your phone number. You can skip phone number verification. ...
  3. Step 3: Connect your Google Account. To connect your Google Account, tap Agree. ...
  4. After you verify your number on Duo. ...
  5. Use Duo to call your contacts.

Is two factor authentication automatically on? ›

Currently, you can turn off 2-Step Verification after it's turned on automatically, but signing in with just a password makes your account much less secure. Soon, 2-Step Verification will be required for most Google Accounts.

How do I turn on two factor authentication on my Samsung? ›

  1. Sign in to your Samsung account at account.samsung.com.
  2. Go to Security > Two-step verification, then click Authenticator app.
  3. Verify the phone number you'll use to receive verification codes.

What is a downside of requiring users to use an authentication factor like Duo Mobile? ›

The drawback is that users may lose flexibility with how they access their accounts. A system that requires a fingerprint scan to access can necessarily only be accessed on devices with hardware that supports that specific authentication factor.

What is an example of 2 factor authentication? ›

Using two knowledge factors like a password and a PIN is two-step authentication. Using two different factors like a password and a one-time passcode sent to a mobile phone via SMS is two-factor authentication.

Why is my duo authentication not working? ›

Make sure you are running the latest version of Duo Mobile. If tapping “Open Duo Mobile” doesn't launch Duo Mobile, reboot your phone and try to authenticate again. If you have a personal profile and a work profile on your device, verify which profile Duo Mobile is installed on.

How can I login to Duo without QR code? ›

Click Email me an activation link instead.

If you enroll in Duo from an Android or iOS device, instead of scanning a QR code tap the Take me to Duo Mobile button. This will launch Duo Mobile and complete activation of the account.

What happens if you don't have an activation code for Duo Mobile? ›

On the Activate Duo Mobile screen, tap the "Having Problems?" link. You will be sent an activation link instead. (You may have to scroll down to see this link.) In the text box, type an email address that you can access with your mobile device.

Can a two-factor authentication be hacked? ›

A new study says that 2FAs are not safe and are being hacked with no intervention from the user. The attack is known as "Man-in-the-Middle". Two-factor authentication is considered the most effective security method, but a new study says it may not be as safe as it seems.

Should two-factor authentication be on or off? ›

Treat 2-factor authentication as a supplement to strong passwords, not as a replacement. Two-factor authentication adds another security layer to the login process, reducing the chances of your account getting hacked.

Can you override two-factor authentication? ›

Some platforms enable users to generate tokens in advance, sometimes providing a document with a certain number of codes that can be used in the future to bypass 2FA should the service fail. If an attacker obtains the user password and gains access to that document, they can bypass 2FA.

Why am I not getting my 2 step verification code Samsung? ›

If you are not receiving a verification code via text message, make sure that you have a strong Wi-Fi or Mobile data connection and the number is not blocked on your device. If you are still not receiving the code, please check your device's OS version and Samsung account version before contacting Samsung Support.

How do I turn off two factor authentication on Android? ›

Turn off 2-Step Verification
  1. On your Android phone or tablet, open your device's Settings app Google. Manage your Google Account.
  2. At the top, tap Security.
  3. Under "Signing in to Google," tap 2-Step Verification. You might need to sign in.
  4. Tap Turn off.
  5. Confirm by tapping Turn off.

Which two-factor authentication method is the safest? ›

However, with advanced technology, 2FA methods are more convenient than ever. Passcode generators are more efficient than traditional passwords. Generators are the safer option because no two passcodes are the same. Max passcode entry prevents cybercriminals from hacking and accessing sensitive data.

What is the safest two-factor authentication? ›

Let's check out the six best 2FA apps for securing your online accounts.
  1. Google Authenticator. 4 Images. ...
  2. Microsoft Authenticator. 6 Images. ...
  3. LastPass Authenticator. 4 Images. ...
  4. Twilio Authy Authenticator. Authy. ...
  5. iOS 15, iPadOS 15, and macOS Monterey. 4 Images. ...
  6. Step Two is another Apple-centric 2FA app.
Sep 24, 2022

What are the downsides of two step verification? ›

The only real drawback of 2FA is time. It takes time to set up and extra time to login. Also, one of the most common forms of backup — a code sent as a text message — isn't as secure as it should be. Hackers can steal your phone number and redirect codes so that they can access your accounts.

What is the difference between two-factor authentication and two-step verification? ›

In the past, two-step verification was used to describe processes that used the same authentication factors, while two-factor authentication described processes that involved different factors, such as entering a password on a website and receiving a numerical code on a mobile device.

What are the 3 ways of 2 factor authentication? ›

Understanding Two-Factor Authentication (2FA)
  • Something you know (your password)
  • Something you have (such as a text with a code sent to your smartphone or other device, or a smartphone authenticator app)
  • Something you are (biometrics using your fingerprint, face, or retina)

What are the three types of two-factor authentication? ›

Let's explore the most popular forms of 2FA that you can use to secure your accounts today: SMS, OTP, and FIDO U2F. Short message service (SMS) is commonly known as text messaging.

How do I authenticate a user in duo? ›

These user accounts allow your end-users to log in to Duo-protected services and applications with two-factor authentication.
...
Overview
  1. Navigate to Duo Admin Panel.
  2. Enter your Duo administrator account credentials.
  3. Complete two-factor authentication.
Jan 26, 2023

How do I set up duo verification? ›

Set up Google Duo
  1. Step 1: Install Duo. Duo is available on Android phones and tablets. ...
  2. Step 2: Verify your phone number. You can skip phone number verification. ...
  3. Step 3: Connect your Google Account. To connect your Google Account, tap Agree. ...
  4. After you verify your number on Duo. ...
  5. Use Duo to call your contacts.

How do I authenticate with Google duo? ›

How It Works. Once you've enrolled in Duo you're ready to go: You'll login as usual with your username and password, and then use your device to verify that it's you. Your administrator can set up the system to do this via SMS, voice call, one-time passcode, the Duo Mobile smartphone app, and so on.

How do I get my Google activation code for Duo Mobile? ›

Set up Google Duo for web
  1. Enter your phone number.
  2. Click Get verification code.
  3. Duo will send a code in a one-time SMS message to the number that you entered. (Carrier text-message rates may apply.)
  4. Enter the code that you received in the text message. If you don't receive a text message, click Resend.

Is Duo Mobile the same as Google Authenticator? ›

If you're a business looking for the more secure option, Cisco Duo is the better option. Compared to Google Authenticator, it is designed for business use, offers better security, and has more options for the second form of authentication.

Videos

1. How To Use Instant Restore for Duo Mobile (iOS) | Recover Duo-Protected Accounts
(Duo Security)
2. Intro to Duo Security | Two Factor Authentication
(UTD Info Tech)
3. Activitating DUO Mobile
(DoIT Training at Stony Brook University)
4. 2-Step Verification (Duo Mobile)
(MyCalStateLA)
5. How to add a second device with Duo 2-Factor Authentication
(UAB IT)
6. Duo Multi-Factor Authentication Setup Walkthrough
(ASUB ITS)
Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated: 04/28/2023

Views: 5563

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.