Understanding Duo Authentication Device Options

Overview

Pitt Passport supports several authentication methods beyond Duo Push, including phishing-resistant options like passkeys, platform authenticators, and FIDO2 security keys. This article describes every available method, its requirements, and when to use it. For step-by-step setup instructions, see Setting Up Multifactor Authentication with Duo.

Multifactor authentication, provided by Duo Security, adds another layer of security to your online accounts when using Pitt Passport by requiring multiple “factors” to verify your identity when you log in to a service:

  • Something you know: A password, PIN, or personal security questions.
  • Something you have: A mobile phone, security key, or smart card that generates or receives a one-time code or serves as a physical key.
  • Something you are: Biometric authentication such as fingerprints or facial recognition.
Recommendation: Enroll at least one phishing-resistant method.
Platform authenticators, FIDO2 security keys, and 1Password passkeys are all phishing-resistant — they cryptographically verify you are signing in to the real Pitt Passport site, not a look-alike. We recommend enrolling at least one of these methods in addition to Duo Push. See the comparison table below to decide which is right for you.

How These Methods Compare

Use this table to decide which methods to enroll. We recommend having at least two methods from different categories so that losing one device does not lock you out.

Authentication methods compared by security, convenience, and resilience
Consideration Platform Authenticator FIDO2 Security Key 1Password Passkey Duo Push SMS / Phone Call
Phishing-resistant YES YES YES PARTIAL NO
Works offline YES YES YES PASSCODE ONLY NO
Survives device loss PARTIAL YES YES NO PARTIAL
Syncs across devices ECOSYSTEM ONLY NO YES NO N/A
Nothing to purchase YES NO YES YES YES

Authentication Options

Select a section below to expand its requirements and setup details.

How to Enroll

For Duo Push (smartphone setup): Follow the step-by-step instructions in Setting Up Multifactor Authentication with Duo.

For passkeys, platform authenticators, and security keys:

  1. Sign in to Pitt Passport from a trusted network.
  2. Navigate to Security Info and select Add sign-in method.
  3. To register a FIDO2 key, choose Security key. To register Touch ID, Face ID, Android biometrics, or Windows Hello, choose Passkey.
  4. Follow the on-screen prompts. You will verify with your current method first.
  5. Repeat to add additional methods. We recommend enrolling at least two methods from different categories.
  6. Test each method by signing out and signing back in, selecting the new authenticator at the prompt.

If you travel internationally, passkeys and security keys are especially important — they work without cellular service or network connectivity. See Technology Guidelines and Tips for International Travel for travel-specific MFA guidance.

Print Article

Related Articles (6)

The authentication options available when logging into Duo
Drop-In Support provides hands-on help for the personal devices of students, faculty, and staff.
What do do if your Duo hardware token stops working
Provides information on Platform Authenticationfor DUO and how to fix potential issues with using only Platform Authentication
Get started with multifactor authentication, provided by Duo Security.
This notification from Duo is designed to protect you from unauthorized changes to your account.

Related Services / Offerings (2)

IT SERVICE DELIVERY AND SUPPORT Pitt Digital provides Drop-In Support to provide hands-on help for the personal devices of students, faculty, and staff.
IDENTITY AND ACCESS MANAGEMENT Duo provides multifactor authentication to add another layer of security to your online accounts.