The Duo Mobile app makes authentication simple: just tap "Approve" on the login request sent to your Android device. You can quickly generate login passwords even without an internet connection or cellular service.
If you need help installing or using Duo Mobile, contact your organization's IT helpdesk or Duo admin.
Are you looking for Duo for your organization? More information on doublesMulti-Factor Authentication (MFA)solutions
Satisfied
- Changes to Duo Mobile
- Install Duo Mobile
- Activate Duo Mobile for the first time
- double press
- Duo push and notifications
- fingerprint verification
- Verified duo push
- passwords
- Add more accounts to Duo Mobile
- security check
- Third Party Accounts
- edit accounts
- mobiles Look-Duo
- adaptive view
- Dark Theme
- Troubleshooting
- Push troubleshooting
- Troubleshooting encryption
Changes to Duo Mobile
We've redesigned Duo Mobile to offer an updated login experience. Learn more about what's new in Duo Mobile version 4 in this video tutorial:
Install Duo Mobile
For the latest version of Duo Mobile, go toGoogle Play.
Supported platforms:The current version of Duo Mobile supports Android 8 and higher.
Duo does not offer official support for non-standard custom Android distributions such as OnePlus, LineageOS, or ColorOS, nor is Duo Mobile compatible with ChromeOS.
To see which version of Duo Mobile is installed on your device, go to AndroidIdeastap no menuto form, scroll down and tapmobiles Duo. The Application Information screen displays the version.
Activate Duo Mobile for the first time
If youSign up for Duo for the first timeand want to add an Android device or use Duo Push, you will see a QR code that you can scan with the Duo Mobile app to complete activation.
Launch Duo Mobile and tapcreate an account.
Tap to continue adding your first Duo account to Duo MobileUse a QR code.
Use your camera to scan the QR code displayed by the Duo sign-in in your browser. If you are asked to allow Duo Mobile to take photos and videos, please grant it.
Give the new account a name to finish adding it to Duo Mobile.
It's a good idea to take a few minutes to practice forwarding and rejecting Duo authentication requests if you've never used Duo before. TouchAgora-Praxisto step through some training screens like this one. If you are familiar with Duo Mobile to sign in to apps, tapJump.
Your newly added Duo account will appear in the accounts list. You can now respond to Duo-Push authentication requests or generate passwords to log into apps.
double press
If you authenticate with Duo Push, you will receive a login request on your phone, just pressto permitto authenticate
If you get an unexpected login prompt, tapdenyto reject the application. You will be asked if the login is suspicious. If you're not trying to sign in to a Duo-secured app or service and the prompt isn't recognized, tapSimto notify your organization's Duo admin. If you made a mistake or the login is not suspicious, tapNOdeny the request without reporting it.
Duo push and notifications
When the duo-push notification appears on the screen, tap on the indicated spot to see the available actions:to permitÖdeny.
Beatto permitin the notification to complete signing in to the Duo-protected app.
Tapping the push request notification itself (rather than tapping the notification actions) takes you to the full screen Duo Push on Duo Mobile.
If your phone is running Android 13 or later, you may need to enable duo push notifications.
To enable duo push notifications:
- Tap and hold the Duo Mobile app icon and select itapplication information. On the next Duo Mobile app information screen, tapnotifications. HebelAll notifications from Duo Mobilehold on
fingerprint verification
Duo Mobile also supports fingerprint verification for Duo Push-based logins as an additional layer of security to verify your user identity. If you're using a device with a fingerprint reader, you'll need to scan your finger each time you authenticate with Duo Mobile (if required by your administrator).
If you can't scan your fingerprint with the sensor, you can also approve Duo's authentication request with your device password (the same one you use on your Android lock screen).
Verified duo push
Your organization may want you to enter a verification code when approving a Duo Push request, which will appear in the universal Duo prompt on Duo Mobile. This protects you from approving sign-in requests you didn't make and helps protect your accounts and information.
You must have Duo Mobile version 4.16.0 or later installed on Android 8 or later to verify a Duo Push request with a code.
If your organization requires Duo-Push verification, the universal Duo Prompt will display a six-digit code on your screen when you use Duo-Push to log in to this app.
Enter the code shown on the Duo Mobile screen and tapCheck overto approve the login request.
If you enter an incorrect code, tapACCORDINGLYon your phone and return to the Duo Universal prompt where you can click or typeOther optionsto choose a different sign-in method, or try Duo Push again.
If you get a duo push prompt on your phone and don't try to log in to this app, tapI don't sign upto reject the application. You will be asked if the login is suspicious. TouchSimto notify your organization's Duo admin, or tapNOif you made a mistake or the login is not suspicious.
passwords
Tap an account to get a one-time passcode to log in. It is workingoverall, even in places where you don't have an internet connection or where you don't have cell service.
If the account is a Duo-protected app or service (ieRegistered this device with Duo and activated the app for Duo Push), the passcode displayed is valid until used. TouchUpdate passwordto generate a new duo password.
If the account is a third-party OTP account (i.e. youSigned in to another service like Gmail and added this device as an authenticator app), you will see a 30 second countdown indicator under the password. If you don't use this password before it expires, the account will be updated with a new password and the countdown will restart.
If you need to use the password displayed on Duo Mobile in another mobile app, tapCopyand paste it into the other application.
Add more accounts to Duo Mobile
To add additional accounts to Mobile Duo, tapAdd toin the top right corner of your account list to access the account type selector.
If the new account you want to add shows a QR code to scan with an authenticator app, tapUse QR codesinceAdd accountList. Scan the QR code with your camera to add the account to Duo Mobile.
You can also select the type of account you want to add from the list and then add that account by scanning a QR code or by entering an activation code that you received from this app.Learn more about adding third-party accounts to Duo Mobile
security check
Duo Mobile's security check compares your device's settings to Duo's recommended security settings and lets you know if settings on your device don't match.
This Android device has up-to-date software and all security settings recommended by Duo:
This Android device is a few Android versions behind the latest:
Tap a detected issue to learn more about that specific setting and how to update your device with the recommended settings.
Tap on the menu and go tosecurity checkon Duo Mobile to see the security status of your device at any time.
Third Party Accounts
Duo Mobile supports generating shortcodes for login to 3rd party TOTP accounts like Google and Dropbox.Learn more "
edit accounts
To make changes to an account in your account list, tap the account to expand it, then tap the three dots in the top-right corner of the account card to open account options.
BeatMotorto reorder your account list (appears if you have more than one Duo Mobile account). Use the up or down arrows that appear to the left of each account name (or tap and hold the icon on the right side of the account card) to change an account's position in the list. TouchCompletedwhen you're done reorganizing your accounts.
Beatrenameto change the name of an account. Enter a new account name and tapSave on computerto accept the new name.
Delete an account by tappingExtinguish. If you delete an account, you will no longer be able to use it to log in and it will also be removed from your Duo Mobile backup, so you will no longer be able to log inrestore somethingthis later. If you really want to delete this account, tapExtinguishin the confirmation message. TouchCancelif you don't want to delete the account.
Restore Backup
If your administrator has enabled the Duo Mobile backup and restore feature and you have already backed up your Duo protected accounts from the app to Google Drive, you can restore your accounts to a new Android device using the process-guided restore to Duo Mobile. You can also perform account recovery with a third party if you have previously opted for third party account recovery. Start the account recovery process by tappingI have existing accountson the Duo Mobile welcome screen.
Check out the full guide to Duo Restore for Android.
mobiles Look-Duo
adaptive view
The list of accounts in Duo Mobile adapts to you. Rotating your device to landscape also rotates your Duo Mobile account list.
The individual accounts shown in the list also change their appearance, showing full account information when you have only a few accounts and switching to a minimized account view when you have many accounts to minimize scrolling in the app.
Dark Theme
Duo Mobile dark theme depends on your Android system settings. There is no in-app option to enable dark theme. If your device has system-wide dark settings enabled, Duo Mobile will automatically switch to the dark theme.
You can enable dark theme on Android in several ways:
- OrIdeas→Show→Isand selectDark Theme.
- Open Android settings from the notification bar and tapDark Theme.
Troubleshooting
see theCommon Problems Guidefor more troubleshooting tips or visit thedual knowledge base. If you can't resolve your issue with Duo Mobile, contact your Duo administrator or your organization's technical support.
Push troubleshooting
If your phone is running Android 13 or later, you may need to enable duo push notifications.
To enable duo push notifications:
- Tap and hold the Duo Mobile app icon and select itapplication information. On the next Duo Mobile app information screen, tapnotifications. HebelAll notifications from Duo Mobilehold on
If you sign in to a Duo-secured app but don't get the expected Duo Push authentication prompt, try closing and reopening Duo Mobile. Duo Mobile checks for pending push requests each time it is opened. If that doesn't work, check them outDuo Knowledge Base for additional Android troubleshooting steps.
Troubleshooting encryption
Mobile device encryption helps protect the data on your device.
Duo considers your device encrypted if you enable password, PIN, or pattern authentication at startup. Without this setting, your device's encryption is less secure and you may not be able to access services or applications protected by Duo.
To enable encryption on your Android device:
- navigate toIdeas→Security→lock screen.
- Enable the password, PIN, or pattern to be asked for when starting the device.
- If you have a Samsung device, you will also need to enable "Secure Boot" or "Strong Protection" in your device settings and ask for a PIN when starting your device.
- Close and reopen Duo Mobile.
If, after completing the steps above, you're still having trouble with the full disk encryption error popping up on Duo Mobile, try disabling this setting and then re-enabling it. This can happen because some Android device manufacturers set a default password to encrypt the phone. While your phone can say it's encrypted, technically it's not fully encrypted until you set your own PIN/password/pattern at startup through your phone's settings. Encrypting with your own password is the most secure option.
Additional points to consider:
- On Samsung devices, "Secure Boot" or "Strong Protection" will be automatically disabled if you enable access permission.
- Some newer devices (e.g. Google Pixel) running Android 7.0 and higher support file-based encryption and can be expected to be encrypted when launching Duo without a PIN.
jump up
FAQs
How do I turn on two-factor authentication on my Duo Mobile? ›
To activate Duo on your device, open the Duo app on your smartphone, tap the “+” button, and use your smartphone to scan the QR code on the computer screen. On iPhone and Android, activate Duo Mobile by scanning the barcode code with the app's built-in scanner.
Where is the authentication code in Duo Mobile? ›Open the Duo Mobile app from your mobile device. In the Duo Mobile app, tap Show. You should see a six-digit code displayed, as shown in the example below.
How do you set up two-factor authentication on Android? ›- Open your Google Account.
- In the navigation panel, select Security.
- Under “Signing in to Google,” select 2-Step Verification. Get started.
- Follow the on-screen steps.
Duo Mobile combines the knowledge factor and possession factor of authentication to create the world's most trusted 2FA platform. Two other possession factors of authentication are HMAC-based One-Time Password (HOTP) and Time-based One-time Password (TOTP).
How can I retrieve my duo authentication code? ›Recovering Accounts Manually
Tap Scan QR code and scan the QR code from your third-party account 2FA setup screen, or, to recover a Duo-protected account, access the My Settings and Devices page from the Duo prompt to reactivate the account.
Clicking Activate Duo Mobile in the actions dropdown helps you get an existing device setup to complete secondary authentication. After answering some questions about your device, you will receive a new QR code to scan which will complete the activation process.
How do I set up duo authentication? ›- Step 1: Install Duo. Duo is available on Android phones and tablets. ...
- Step 2: Verify your phone number. You can skip phone number verification. ...
- Step 3: Connect your Google Account. To connect your Google Account, tap Agree. ...
- After you verify your number on Duo. ...
- Use Duo to call your contacts.
Currently, you can turn off 2-Step Verification after it's turned on automatically, but signing in with just a password makes your account much less secure. Soon, 2-Step Verification will be required for most Google Accounts.
How do I turn on two factor authentication on my Samsung? ›- Sign in to your Samsung account at account.samsung.com.
- Go to Security > Two-step verification, then click Authenticator app.
- Verify the phone number you'll use to receive verification codes.
The drawback is that users may lose flexibility with how they access their accounts. A system that requires a fingerprint scan to access can necessarily only be accessed on devices with hardware that supports that specific authentication factor.
What is an example of 2 factor authentication? ›
Using two knowledge factors like a password and a PIN is two-step authentication. Using two different factors like a password and a one-time passcode sent to a mobile phone via SMS is two-factor authentication.
Why is my duo authentication not working? ›Make sure you are running the latest version of Duo Mobile. If tapping “Open Duo Mobile” doesn't launch Duo Mobile, reboot your phone and try to authenticate again. If you have a personal profile and a work profile on your device, verify which profile Duo Mobile is installed on.
How can I login to Duo without QR code? ›Click Email me an activation link instead.
If you enroll in Duo from an Android or iOS device, instead of scanning a QR code tap the Take me to Duo Mobile button. This will launch Duo Mobile and complete activation of the account.
On the Activate Duo Mobile screen, tap the "Having Problems?" link. You will be sent an activation link instead. (You may have to scroll down to see this link.) In the text box, type an email address that you can access with your mobile device.
Can a two-factor authentication be hacked? ›A new study says that 2FAs are not safe and are being hacked with no intervention from the user. The attack is known as "Man-in-the-Middle". Two-factor authentication is considered the most effective security method, but a new study says it may not be as safe as it seems.
Should two-factor authentication be on or off? ›Treat 2-factor authentication as a supplement to strong passwords, not as a replacement. Two-factor authentication adds another security layer to the login process, reducing the chances of your account getting hacked.
Can you override two-factor authentication? ›Some platforms enable users to generate tokens in advance, sometimes providing a document with a certain number of codes that can be used in the future to bypass 2FA should the service fail. If an attacker obtains the user password and gains access to that document, they can bypass 2FA.
Why am I not getting my 2 step verification code Samsung? ›If you are not receiving a verification code via text message, make sure that you have a strong Wi-Fi or Mobile data connection and the number is not blocked on your device. If you are still not receiving the code, please check your device's OS version and Samsung account version before contacting Samsung Support.
How do I turn off two factor authentication on Android? ›- On your Android phone or tablet, open your device's Settings app Google. Manage your Google Account.
- At the top, tap Security.
- Under "Signing in to Google," tap 2-Step Verification. You might need to sign in.
- Tap Turn off.
- Confirm by tapping Turn off.
However, with advanced technology, 2FA methods are more convenient than ever. Passcode generators are more efficient than traditional passwords. Generators are the safer option because no two passcodes are the same. Max passcode entry prevents cybercriminals from hacking and accessing sensitive data.
What is the safest two-factor authentication? ›
- Google Authenticator. 4 Images. ...
- Microsoft Authenticator. 6 Images. ...
- LastPass Authenticator. 4 Images. ...
- Twilio Authy Authenticator. Authy. ...
- iOS 15, iPadOS 15, and macOS Monterey. 4 Images. ...
- Step Two is another Apple-centric 2FA app.
The only real drawback of 2FA is time. It takes time to set up and extra time to login. Also, one of the most common forms of backup — a code sent as a text message — isn't as secure as it should be. Hackers can steal your phone number and redirect codes so that they can access your accounts.
What is the difference between two-factor authentication and two-step verification? ›In the past, two-step verification was used to describe processes that used the same authentication factors, while two-factor authentication described processes that involved different factors, such as entering a password on a website and receiving a numerical code on a mobile device.
What are the 3 ways of 2 factor authentication? ›- Something you know (your password)
- Something you have (such as a text with a code sent to your smartphone or other device, or a smartphone authenticator app)
- Something you are (biometrics using your fingerprint, face, or retina)
Let's explore the most popular forms of 2FA that you can use to secure your accounts today: SMS, OTP, and FIDO U2F. Short message service (SMS) is commonly known as text messaging.
How do I authenticate a user in duo? ›...
Overview
- Navigate to Duo Admin Panel.
- Enter your Duo administrator account credentials.
- Complete two-factor authentication.
- Step 1: Install Duo. Duo is available on Android phones and tablets. ...
- Step 2: Verify your phone number. You can skip phone number verification. ...
- Step 3: Connect your Google Account. To connect your Google Account, tap Agree. ...
- After you verify your number on Duo. ...
- Use Duo to call your contacts.
How It Works. Once you've enrolled in Duo you're ready to go: You'll login as usual with your username and password, and then use your device to verify that it's you. Your administrator can set up the system to do this via SMS, voice call, one-time passcode, the Duo Mobile smartphone app, and so on.
How do I get my Google activation code for Duo Mobile? ›- Enter your phone number.
- Click Get verification code.
- Duo will send a code in a one-time SMS message to the number that you entered. (Carrier text-message rates may apply.)
- Enter the code that you received in the text message. If you don't receive a text message, click Resend.
If you're a business looking for the more secure option, Cisco Duo is the better option. Compared to Google Authenticator, it is designed for business use, offers better security, and has more options for the second form of authentication.