Multi-Factor Authentication

Multi-Factor Authentication (MFA) is required for faculty, staff, and students to access the following systems:

  • mail.duke.edu
  • Sakai
  • Duke Box
  • VPN (virtual private network)
  • DukeHub
  • Working@Duke

Protect your Duke accounts using Multi-factor authentication (MFA), also called advanced or two-step authentication. MFA provides an additional layer of security when logging in or performing transactions online and at Duke.

When logging in using MFA, a user is required to authenticate their identity using a second factor, typically via a phone or separate passcode.

MFA is required for many Duke services, including Work@Duke, Duke Health VPN, and clinical systems. Other services (such as email, DukeHub, Sakai, and Box) require MFA for access off the Duke network. If desired, you can further protect your identity by opting in to additional account requirements on the MFA registration site.

The IT Security Office strongly recommends using multi-factor authentication when using all NetID protected services.  It is especially recommended for access to critical systems or systems storing sensitive data per the ITSO Security Standards. 

Please visit https://idms-mfa.oit.duke.edu/mfa/help for further information and instructions on how to sign up.