---
title: "Set up Multi-Factor Authentication (Duo)"
canonical: "https://tech.calpoly.edu/space/CPKB/3539066/Set%20up%20Multi-Factor%20Authentication%20(Duo)"
format: markdown
---
![DUO Logo Icon](media://b2eb31b0-86f9-4be4-8224-68c9b5f67c7a)

Students, staff, and faculty must use Duo multi-factor authentication (MFA) to access the My Cal Poly Portal, Cal Poly Canvas, Microsoft email and calendar, and all other web-based services that require a secure login.   
  
*(MFA is NOT required for Cal Poly shared club/department accounts.)*

> ⚠️ <span style="color: #bf2600">**IMPORTANT:**</span>** **
> ⚠️ 
> ⚠️ - <span style="color: #bf2600">**DO NOT CHOOSE FACE/TOUCH ID when you first enroll a device.**</span>
> ⚠️ - <span style="color: #006644">**Choose**</span><span style="color: #006644"> </span><span style="color: #006644">**Duo Mobile (Push)**</span> as the primary form of authentication.
> ⚠️ 
> ⚠️ **What if I already chose Face/Touch ID initially?**  
> ⚠️ If you’ve already set up Face/Touch ID as your first form of authentication, here’s how you can change that: 
> ⚠️ 
> ⚠️ 1. Log in to **My Cal Poly Portal **using the device that you set up with Face/Touch ID.
> ⚠️ 2. Click the **Personal Info** tab.
> ⚠️ 3. Under the **Authorized Devices** tab, click **Multi-factor Authentication**.
> ⚠️ 4. Click **Edit** to add a new device**. **See the following Knowledge Base article for more details – [Add a New Mobile Phone to My Duo Account](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/3571853).

> ✅ **NOTE:** After enrolling your primary device, [adding a secondary device](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/3571853) is highly recommended when using multiple devices (i.e., an iPhone and a laptop).

### Step 1 – Add a Primary Device (First-time setup)

<details>
<summary>click to view how to add your primary device...</summary>

1. When you first attempt to access the [My Cal Poly Portal](https://my.calpoly.edu) or a Cal Poly application (*that is MFA/Duo-enabled*), you will see a **Welcome to Duo Security** prompt. Click **Next**.
  
2. *Subsequent screens will present information about the importance of MFA. Click through those until the ****Select an option**** prompt appears…*
  
3. **Choose your preferred device type** below to view setup instructions:

  - **[Duo Mobile (Push)](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/1199309126)**** **<span style="color: #006644">**– RECOMMENDED**</span>: Approve Duo Push verification requests on iOS or Android devices or generate a one-time passcode from the Duo Mobile app.
  - **[Touch/Face ID](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/1182957880)**: <span style="color: #bf2600">** -  DO NOT CHOOSE AS PRIMARY**</span>: Use the fingerprint sensor on Apple MacBooks, Magic Keyboards, or iPhones.
  - **[Security key](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/1182957900)**: Tap a WebAuthn/FIDO2 security key. <u>[Requires Chrome, Safari, Firefox, or Edge](https://guide.duo.com/universal-enrollment#webauthn-supported-browsers)</u>.
  - **[Phone Call or Duo Mobile Passcode](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/1199309184)**: Receive a phone call or a one-time passcode.
  - **[Token](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/740556806)**: Use a hardware token.
</details>

### Step 2 – <u>[Add a Secondary Device](https://calpoly.atlassian.net/wiki/spaces/CPKB/pages/3571853)</u>

---