What is Duo?
Duo is the Single Sign-On (SSO) and two-factor authentication service that secures most campus resources, including Gmail, Box, and Banner. It protects students, faculty, and staff from phishing and other identity-based attacks.
What is two-factor authentication?
Two-factor authentication (2FA) confirms your identity using two things: your password, plus something physical you have or are, such as your phone, your computer's fingerprint or face sensor, or a security key. If someone steals your password, they still cannot log in without that second factor.
Your authentication methods
- Duo Push (recommended): Approve a notification in the Duo Mobile app and enter the 3-digit verification code shown on your screen. Works on any iPhone, Android phone, or iPad over Wi-Fi or cellular data. The app is free, and you do not need a credit card or payment method to install it. Duo Mobile confirms each approval with Face ID, Touch ID, or your fingerprint unlock, so that unlock method needs to be turned on for your phone.
- Touch ID or Windows Hello (no phone needed): Approve sign-ins with the fingerprint, face, or PIN you already use to unlock your computer. Touch ID works on a Mac, and Windows Hello works on a Windows PC, in the Chrome or Edge browser. This method is set up per computer, and it does not work in Firefox. For step-by-step setup, see Setting up each sign-in method below.
- Security key or passkey: A hardware security key or a passkey saved on your device. The most phishing-resistant option, and it works with no internet connection. See Setting Up a Security Key.
Setting up Duo (new users)
- Log into an Emerson resource that uses Duo, such as gmail.emerson.edu, with your Emerson email and password.
- At the Welcome to Duo Security screen, click Get started.
- At First, add a device, choose your method. We recommend Touch ID or Windows Hello (on your computer, in Chrome or Edge) or Duo Mobile for phones. You can also use a Security key.
- Follow the steps for your chosen method in Setting up each sign-in method below.
You can add more devices later, and we recommend setting up a second method as a backup.
Setting up each sign-in method
Use these steps to add or switch methods at any time. You can register more than one, and we recommend setting up a second method as a backup.
Prefer to watch first? This short video walks through managing your own devices, including setting up Touch ID and Duo Push. It is filmed on a Mac and iPhone, but the steps are nearly identical on Windows.
Set up Duo Mobile
Duo Mobile is free, and you do not need a credit card or any payment method to install it. On an iPhone, if the App Store asks you to add a payment method, choose None and continue; you will not be charged. Google Play does not require a payment method to download free apps. If you would rather not use a phone at all, Touch ID or Windows Hello lets you approve sign-ins on your computer with no app and no phone.
- Install the Duo Mobile app from the App Store (iPhone) or Google Play (Android).
- Open a private or incognito browser window, go to gmail.emerson.edu, and log in.
- At the Duo prompt, click Other options, then Manage devices, and verify your identity.
- Click Add a device and choose Duo Mobile.
- Enter your phone number, check the box to agree, and click Continue, then Next at the Download Duo Mobile screen.
- When the QR code appears, open Duo Mobile, tap the + in the top right, and scan it. If you cannot scan it, click Get an activation link instead.
- Turn on Face ID, Touch ID, or fingerprint unlock on your phone if it is not already on. See Face ID, Touch ID, and fingerprint unlock below.
Once Duo Mobile is activated, Duo Push becomes your default sign-in method.
Face ID, Touch ID, and fingerprint unlock
This section applies to anyone using the Duo Mobile app. It does not apply if you sign in with Touch ID on a Mac, Windows Hello, or a security key.
Duo Mobile confirms every approval with the face or fingerprint unlock on your phone. If that is turned off, the notification still arrives, but the app cannot finish the approval and the sign-in will not complete. This is the most common reason Duo Mobile opens to a screen with no Approve button.
On an iPhone or iPad:
- Open Settings, tap Face ID & Passcode (or Touch ID & Passcode), and enter your passcode.
- Tap Set Up Face ID or add a fingerprint, and follow the prompts.
- Go back to Settings, scroll down to Duo Mobile, and make sure Face ID is turned on there as well.
On an Android phone:
- Open Settings, then Security (the exact name varies by manufacturer).
- Set up Fingerprint or Face unlock and follow the prompts.
If your phone's face or fingerprint sensor is broken and cannot be set up, use Touch ID on a Mac, Windows Hello on a Windows PC, or a security key instead. Contact the Help Desk and we will get you set up.
Set up Touch ID or Windows Hello (no phone needed)
You can approve sign-ins right on your computer using the fingerprint, face, or PIN you already use to unlock it. This uses Touch ID on a Mac and Windows Hello on a Windows PC. Set it up on each computer you use regularly, because this sign-in method lives on the specific computer where you create it.
Please read these three points first. They prevent the most common problems:
- Use Chrome or Edge, not Firefox. Firefox on Windows cannot use Windows Hello and will instead show a QR code or ask for a USB security key. If you see a QR code when you expected a fingerprint or PIN prompt, you are in Firefox. Switch to Chrome or Edge.
- When Windows asks where to save your passkey, choose "This Windows device" or "Windows Hello." Do not choose "Google Password Manager" (that version only works in Chrome and not in other browsers), and do not choose a phone or a QR code option.
- Set it up on each computer you use. A Touch ID or Windows Hello sign-in is tied to the one computer where you created it. If you work from more than one machine, repeat these steps on each.
Windows Hello on a Windows PC
You will need Windows Hello already turned on in Windows (a fingerprint, face, or PIN). Most Emerson laptops already have this. Use Chrome or Edge for these steps.
- Open a new private window (in Edge, New InPrivate window; in Chrome, New Incognito Window). Close any other private windows first.
- Go to gmail.emerson.edu and log in with your Emerson email and password.
- At the Duo prompt, click Other options, then Manage devices, and verify your identity.
- Click Add a security key (or Add a device, then the security key or passkey option).
- A Windows box titled Save your passkey appears. Choose This Windows device or Windows Hello. If it offers another location such as Google Password Manager or a phone, use the Change or More choices link to select the Windows device option instead.
- Confirm with your Windows Hello fingerprint, face, or PIN. That is it.
After this, signing in to Emerson sites in Chrome or Edge on that computer will prompt for your Windows Hello fingerprint, face, or PIN.
Touch ID on a Mac
Touch ID works on a Mac with a Touch ID sensor, in Chrome.
- On the Mac you want to set up, open a private or incognito Chrome window and go to gmail.emerson.edu, then log in.
- At the Duo prompt, click Other options, then Manage devices, and verify your identity.
- Click Add a device and choose Touch ID.
- Follow the prompt and use your fingerprint to confirm.
Set up a security key or passkey
Security keys and passkeys are the most phishing-resistant option and work with no internet connection. To add one, follow the same path: Other options > Manage devices > Add a device > Security key. For details, see Setting Up a Security Key With Duo.
Using Duo Push
When you sign in, a 3-digit code appears on your screen. Open the Duo Mobile app, tap the login request, and enter that code to confirm it is really you. This ensures that only you can approve your own sign-ins.
Duo Mobile then asks you to confirm with Face ID, Touch ID, or your fingerprint. If that unlock method is turned off on your phone, the approval cannot complete. See Face ID, Touch ID, and fingerprint unlock.
Only approve a request you started. If you receive a Duo notification, code, or call you did not initiate, deny it and contact the Help Desk immediately.
Troubleshooting Duo Mobile
This section applies to the Duo Mobile app on a phone or tablet. Reinstalling the app removes your Emerson account from it and means you have to set it up again, so work through the steps below before you delete anything.
Duo Mobile is stuck on "Checking device health"
When you start a sign-in on the same phone that has Duo Mobile, the app opens and briefly shows Checking device health while Duo confirms your phone's security settings. It normally clears within a few seconds and takes you straight to the approval screen. If it stays on that screen, work through these in order:
- Turn off Low Power Mode and plug the phone in. A yellow battery icon means Low Power Mode is on, and it can stop the check from finishing.
- Connect to Wi-Fi, or move somewhere with a stronger cellular signal.
- Turn off any VPN, iCloud Private Relay, ad blocker, or content blocker. These can stop the app from reaching Duo.
- Install any pending iOS or Android updates, then update Duo Mobile in the App Store or Google Play.
- Check that your date and time are set automatically. On an iPhone this is Settings > General > Date & Time > Set Automatically.
- Force close Duo Mobile, then start the sign-in again from the beginning.
The app opens with no Approve button, or nothing happens when I tap the notification
The usual cause is that Face ID, Touch ID, or fingerprint unlock is turned off on your phone. Duo Mobile uses it to confirm the approval, and without it the sign-in cannot complete. Follow the steps in Face ID, Touch ID, and fingerprint unlock, then try signing in again.
If that is already set up and working, try signing in from Safari or Chrome rather than from inside another app's built-in browser. Some apps open links in a window that Duo cannot hand off to properly.
I never receive the push notification
- Check that notifications are allowed. On an iPhone this is Settings > Notifications > Duo Mobile > Allow Notifications.
- Turn Wi-Fi off and use cellular data instead, or switch airplane mode on and back off. Phones sometimes get stuck deciding which connection to use.
- Run the app's own test. In Duo Mobile on an iPhone, tap Edit at the top left of the accounts list, tap your Emerson account, then tap Get Started under Missing Notifications? The app checks each step and tells you what to fix.
None of this worked
Reply to your ticket or call the Help Desk at (617) 824-8080. Tell us what you see on screen and which of the steps above you have tried, and we will get you back in. Please do not delete and reinstall the app again in the meantime, since that only adds another setup step.
Managing your devices
To add, remove, or update a device at any time:
- Open a private or incognito browser window and go to gmail.emerson.edu, then log in.
- At the Duo prompt, click Other options.
- Click Manage devices and verify your identity.
- Click Add a device and follow the prompts.
We recommend registering more than one device so you are never locked out if one is lost or unavailable.
How "Trust this browser" works
After you authenticate, your browser remembers you for that application for up to 30 days, so you are not prompted every time. Trust is applied per application: the first time you sign into each application on a device, you complete Duo once for that application, then it remembers you independently. This limits the damage if one account is ever compromised.
Clearing your browser cache, or signing out of an application (for example, "Sign out of all accounts" in Gmail), will require you to authenticate again. Emerson lab and classroom computers wipe their profiles nightly, so they always require Duo.
Using Duo internationally
Methods that do not depend on a US phone number work anywhere in the world:
- Duo Push works over Wi-Fi, so you can use it abroad even without cellular service.
- Touch ID, Windows Hello, and security keys work locally on your device with no internet connection at all.
Frequently asked questions
Do I need a credit card or payment method to download the Duo Mobile app?
No. Duo Mobile is free, and you do not need a payment method on file to install it. On an iPhone, when the App Store asks for a payment method, choose None and continue. Google Play does not require a payment method to download free apps. If you would rather not use a phone at all, Touch ID (Mac) and Windows Hello (Windows PC) let you approve sign-ins on your computer with no app and no phone.
Do I have to use Face ID or a fingerprint with Duo Mobile?
Yes. Duo Mobile confirms each approval with the face or fingerprint unlock on your phone, so that unlock method has to be turned on or approvals will not complete. If your phone's sensor does not work, use Touch ID on a Mac, Windows Hello on a Windows PC, or a security key instead, none of which involve your phone. Contact the Help Desk and we will set one up with you.
What happens if I get a new phone?
Touch ID, Windows Hello, and security keys are tied to your computer or key, not your phone, so they keep working. To restore Duo Mobile on a new phone, install the Duo Mobile app, then go to Manage devices > Add a device > Duo Mobile and follow the prompts. If you have a registered backup method such as a security key, Touch ID, or Windows Hello, use it to verify your identity, then add the new phone.
If you have a new phone, a new number, and no backup method, contact the Help Desk at (617) 824-8080. We will verify your identity, remove the old device, and help you set up the new one.
What if I am locked out or have no available method?
Email helpdesk@emerson.edu from your Emerson account or the personal email we have on file, or call (617) 824-8080 during business hours. We will verify your identity and help you regain access, and we strongly recommend using that opportunity to add a second method.
What if I have no internet or cell reception?
Touch ID, Windows Hello, and security keys work with no connection at all, so they are the best choice when you may be offline. Duo Push works over Wi-Fi. If you know you will be offline, such as on a flight, log into the applications you will need in advance and choose Remember me for 30 days. We recommend this before time-sensitive events such as course registration.
Why is Duo asking me for a bypass code?
When Duo detects an unusual sign-in, it may require a more secure method in a process called step-up authentication, which uses Verified Duo Push. This can happen when you connect from a new network, appear to travel an unrealistic distance in a short time, or receive many push requests quickly. Using a third-party VPN is a common trigger, because it makes your connection appear to come from somewhere else. If you cannot complete the step-up, email helpdesk@emerson.edu to verify your identity and request a short-term bypass code, then add Duo Mobile, Touch ID, or Windows Hello so this does not happen again.
Can I register multiple devices?
Yes, and we recommend it. With a backup method, you can still sign in if your primary device is lost, broken, or out of battery. Add devices any time through Other options > Manage devices > Add a device.
How does this work with a shared mailbox or drive?
In most cases you should not share passwords. For Google Drive, share a folder with specific people instead of sharing an account. For Gmail, set delegates so each person signs in with their own account and Duo, then opens the shared mailbox. Password sharing for your personal Emerson account is not permitted.
Students use the lectern computer to present and Duo wastes class time. What can I do?
Have students connect their own laptops to the laptop station, or cast wirelessly in rooms that support it, rather than logging into the lectern computer. Alternatively, collect links to student projects in a shared Google Doc ahead of time and present from your own authenticated session.
I am getting a "System Error" telling me to contact the Help Desk.
This usually happens when your computer's IP address changes between loading the page and submitting your password, which Duo treats as a possible hijacked session. It is often caused by a VPN or by how your ISP routes your connection. Turn off any third-party VPN and try again. If you need a VPN to reach Google or other services from outside the US, use Emerson's VPN instead, which routes traffic back to Boston.
Have any questions?
Contact the Help Desk at (617) 824-8080 or submit a ticket.