Two-step Login with Duo Authentication Methods


MethodsBenefitsDisadvantages
Touch ID This is a great secondary method for those who have a device compatible with this biometric feature, such as MacBooks. This requires the use of a fingerprint and fingerprint sensors are highly sensitive and will require the use of a consistent finger. This may not be a viable option for those who do not have compatible devices. This option is less secure than others. 
Security Keys (U2F)This is a good primary for those without a smart device who will only need to login from a computer. This is inserted in your USB port and requires you to press a button to send a passcode to the computer..This requires that you purchase a device. This device will only work on a computer with access to a USB port.
Duo Mobile Push ApprovalThis is the best primary device for most people. Use your smartphone or tablet to get an approval notification when you login through the Duo Mobile App. Thanks to its simplicity and reliability, all it takes is a single tap.This requires the use of your personal device, and requires an active internet connection. You will need to download the Duo Mobile App on your enrolled device. This may not be viable if you work somewhere that does not allow personal devices, like a testing center or corrections facility.
Duo Mobile Generated PasscodesThis is a great secondary method if you do not have an internet connection on your device. It allows you to generate a code you can use to login from the Duo Mobile App.This requires the use of your personal device. This may not be viable if you work somewhere that does not allow personal devices, like a testing center or corrections facility.
Hardware Token PasscodesThis is a great primary for those without a smart device. They are thumb-sized plastic devices that generate codes you enter after your NetID password to access Rutgers services. Tokens have an expected battery life of two years. Lost tokens can be replaced. This requires that you purchase a device. For students, it is $6.00. Hardware tokens also have non-replaceable batteries and need to be replaced every two years. Hardware tokens are small and may get lost easily. 
SMS PasscodesThis is a a good secondary option for users with a texting-capable phone that is not a smart device. You will be texted a code that you can use to login. This option is recommended for flip phones. This method has a cost associated with it for the University. This requires the use of your personal device, and requires an active cellular connection. This may not be viable outside the United States or if you work somewhere that does not allow personal devices, like a testing center or corrections facility.
Phone Call ApprovalThis is a a great secondary option for users without a texting capable phone that is not a smart device. You will receive a phone call with a prompt to approve your login.This method has a cost associated with it for the University. This requires the use of your personal device, and requires an active cellular connection. This may not be viable outside the United States or if you work somewhere that does not allow personal devices, like a testing center or corrections facility.

This is the sequence of authentication methods that Duo uses when you first log in. If you don't have a particular authentication method setup, then Duo automatically selects your next available option.

  1. Touch ID
  2. Security keys
  3. Duo Mobile push approval
  4. Duo Mobile generated passcodes
  5. Hardware token passcodes
  6. SMS passcodes
  7. Phone call approval

For more detailed information, please visit the Duo Support page regarding Duo Authentication Methods