Reminder of upcoming security update: DUO two factor authentication
Posted on Tuesday 21 July 2026
We recently shared information on how we will be strengthening account security through an update of our Duo Two Factor Authentication (2FA) process over the coming months.
We will be introducing Duo Verified Push and discontinuing SMS (text message) as an authentication method. SMS authentication is vulnerable to attacks, by switching this off, we greatly increase the security of University accounts.
How will this affect me?
Verified push users
If you currently use Duo Mobile push notifications, the process in which you receive an alert to your smartphone and are asked to Approve or Deny log in access, you will transition to a new Verified Push method detailed below. Verified Push will be enabled for all Duo Mobile app users at the same time.
- When using the new Verified Push method, a 3-digit code will appear on your device login screen. You will be prompted to enter this code into the Duo Mobile app on your phone. Once entered, your login will be verified and complete. Verified Push greatly reduces the risk of illegitimate second factor pushes being authenticated.
SMS switch off
If you currently use the SMS function for notifications, in which text messages are sent by Duo Security to deliver single-use passcodes, you will need to download the Duo Mobile app to use Verified Push SMS will no longer be used.
- If you currently use SMS because your device doesn't support the app, IT Services will contact you directly to provide alternative authentication options. The SMS switch off will be carried out over a period of time. This means that some users will lose access to SMS before others. SMS authentication is vulnerable to attacks such as SIM swapping. By switching this off, we greatly increase the security of University accounts.
Who is NOT affected by these changes?
Users who use a hardware token as their two factor authentication will see no change to their authentication process and are not affected.
By implementing these changes, we are moving towards more secure approval methods to match industry standards. Such changes are necessary not only to bring the University in line with recommended security standards, but also to protect the University from attacks.
Next steps
Please ensure that your Duo Mobile app is up to date via the App Store or Google Play Store.
Find more information about how we use Duo at the University here
If you have any questions please visit the IT webpages.
We will share more details and specific timelines as the rollout date approaches.