Multi-factor authentication (MFA)
Multi-factor authentication (MFA) provides an extra layer of protection to help keep your UQ account secure by verifying it's really you when you sign in to UQ systems and services.
MFA, also known as two-factor authentication (2FA), requires two separate forms of verification:
- Something you know - your UQ username and password.
- Something you have –- such as your mobile phone or another registered authentication method.
Even if someone obtains your password, MFA makes it significantly more difficult for them to access your account.
UQ uses Okta as its standard multi-factor authentication service.
When accessing a UQ system that requires MFA, you'll usually be prompted to verify your identity using one of the authentication methods registered to your UQ account.
A small number of users may still require Duo for specific systems or specialised access scenarios. If Duo is required, you'll be advised by your support team or the application owner.
Modern scams can be highly sophisticated, making it difficult to know what is real and what is fake. For an overview, read Email scams.
Activating Okta MFA for the first time
Most people will use Okta Verify on a mobile phone to authenticate when signing in to UQ systems.
If you're using a personal laptop or desktop computer, you can approve authentication requests using Okta Verify on your mobile device.
Staff using a UQ-managed Windows or Mac device are encouraged to enable Okta FastPass. FastPass allows you to authenticate using the built-in security features of your device, such as:
- Windows Hello
- Face ID
- Touch ID
- Device PIN
This provides a faster sign-in experience and reduces the need to approve requests on your mobile phone.
Additional authentication options are also available, including passkeys and hardware security keys (YubiKeys), depending on your account type.
If you cannot use Okta Verify on your mobile device, please contact the ITS Service Desk.
Accessibility
If you have an accessibility or mobility-related requirement:
- Students: Complete the MFA student accessibility request, or contact AskUs.
- Staff and alumni: Contact the ITS Service Desk.
Once you have a YubiKey, follow the instructions to set up Okta MFA with a YubiKey.
Multiple accounts
If you will be activating MFA for multiple UQ accounts (e.g. a staff account and a student account), follow the instructions for activating multiple accounts.
Managing Okta devices and other features
Okta ‘My Settings’ enables you to manage your registered MFA devices and access additional MFA settings and features.
From items on the left-hand menu you can select:
- Personal information: view your name and email address/es
- Display language: set your preferred language for Okta (English is used by default)
- Security methods: register new phones/devices or remove phones/devices from Okta Verify MFA
- Recent activity: view your recent Okta MFA authentication activity
Frequently asked questions (FAQs)
Setting up Okta MFA
- How do I complete my initial MFA setup with Okta?
- How do I set up synced passkeys for Okta MFA?
- How do I set up Google Authenticator or other TOTP authenticator apps?
- How do I setup Okta MFA with a self-use YubiKey?
- How do I activate MFA for multiple accounts?
- How do I register a new phone or device for Okta MFA?
- How do I remove a phone or registered device from Okta Verify?
- How do I MFA in a location without mobile coverage?
- How do I generate a temporary access code for MFA?
- What if I can’t scan the Okta QR code?
- What is Windows Hello and how do I activate it?
- Why am I receiving prompts for Duo?
- Can I use my Apple Watch for MFA with Okta Verify?
- Can I set up MFA if my device is not compatible with Okta, or if I want to use another TOTP app?
Lost or damaged devices
About Okta MFA
- What's the difference between Okta, Okta Verify and Okta FastPass?
- Does multi-factor authentication (MFA) use my data on my smartphone?
- Why do I need to use multi-factor authentication (MFA)?
- What devices or methods can I use for multi-factor authentication (MFA)?
- Do I need to use Okta MFA every time I log in?
- Why don't all UQ sites use MFA?
- Current Country Blocklist
- Okta Data Residency
Activating Duo MFA for the first time
Okta is UQ's standard MFA service.
A small number of UQ systems and specialised access scenarios continue to use Duo authentication.
Most users do not need to install or use Duo.
If you've been instructed to use Duo, follow the appropriate setup instructions below.
Follow the instructions to activate MFA on your mobile device using Duo
Follow the instructions to activate MFA on your mobile device using another app
Accessibility
If you have an accessibility or mobility-related requirement:
Students: Complete the MFA student accessibility request or contact AskUs.
Staff and alumni: Contact the ITS Service Desk.
Once you have a YubiKey, follow the instructions to set up MFA with a YubiKey.
Multiple accounts
If you will be activating MFA for multiple UQ accounts (e.g. a staff account and a student account), follow the instructions for activating multiple accounts.
Managing devices and other features
The MFA Management portal enables you to manage your registered MFA devices and access additional MFA settings and features.
You can:
- Register new phones or devices to use for MFA
- Generate a temporary MFA passcode if you forget your MFA device
- Register for MFA in nominated laboratories
- Review your recent MFA authentication activity.
Frequently asked questions (FAQs)
Setting up MFA
- How do I activate Duo MFA for the first time on my mobile device?
- How do I register a new phone or device for Duo MFA?
- How do I set up Duo MFA if my device is not compatible with Duo, or if I want to use another app?
- Why can't I find or download the Duo Mobile app on the app store?
- How do I set up Duo MFA with a YubiKey?
- How do I activate Duo MFA for multiple accounts?
- How do I Duo MFA if I don't have a smartphone, or don't want to use my personal device?
- What happens if I don't register a device for Duo MFA?
- How do I resolve errors when enrolling my phone number?
- How do I set up Duo MFA in China using a Huawei smartphone?
- How do I set up a Duo token using the MFA portal?
General use
- How do I MFA if I go between my student and staff accounts?
- How do I MFA if I have run out of credit on my phone?
- What do I do if I've lost the paper/printout of my MFA temporary passcode?
- Can I change the authentication method I use?
- How do I generate an MFA passcode using the Duo app?
- How do I MFA in a location without mobile coverage?
- What should I do if I receive an unexpected Duo login request?
- How do I remove my UQ account in the Duo Mobile app?
- How do I change my default device for Duo?
- How do I MFA if I forget my device?
Lost or damaged devices
- What do I do if I've lost my phone or MFA-enabled device?
- What do I do if my YubiKey or Duo token is lost, stolen or damaged?
Problems logging in
- What do I do if I can't see the option to enter a passcode for MFA?
- I'm not receiving push notifications from Duo. How do I fix this?
- What do I do if my Duo token code isn't working?
- What do I do if I've clicked 'Trust this browser', but I'm still asked to log in?
- How do I generate a temporary bypass code for MFA?
MFA in labs
- How do I use MFA inside labs?
- How do I log in with MFA in a lab where I can't use my phone?
- How do I use the shared MFA tokens inside a lab?
- I manage a lab. What MFA arrangements are required?
- How do I unregister from a shared MFA lab token?
- I received an email stating my MFA lab access will expire in 1 month. What should I do?
MFA in exams
Using MFA overseas
- Can I use MFA when travelling overseas?
- I receive an 'Access denied' or failed login message when trying to MFA from overseas. What should I do?
About MFA
- What devices or methods can I use for MFA?
- Why do I need to use MFA?
- What is Duo verified push?
- What changes will I see with the new Duo MFA prompt?
- Do I need to use MFA every time I log in?
- Why don't all UQ sites use MFA?
- Does MFA use my data on my smartphone?
- How does Duo store my data?
- Why does the Duo Mobile app need access to my camera?
- What is Duo Instant Restore and how do I use it?