Skip to main content

Multi-Factor Authentication (MFA)

MFA En Español

All UMD and University System of Maryland community members must use multi-factor authentication to log into all university resources that use CAS. Some major systems that use CAS are ELMS-Canvas, Payroll and Human Resources (PHR), Testudo, Terrapin Express, Box, and library services.

What is multi-factor authentication? Multi-factor authentication requires the use of two of the three authentication factor categories: something you know, something you have, and something you are. This adds a layer of security because hackers will need more than just a password to use your accounts. In order to log in, you will need:

  1. Your Directory ID and password
  2. Either a mobile device, a hardware token, a phone that can receive voice calls, or a one-time use code 

Here's how to enroll in multi-factor authentication:

Step 1. Enroll a device and a backup device/print one time use codes:

Step 2. Enable multi-factor authentication for all CAS logins.

 


Frequently Asked Questions (FAQs)

Yes, you are welcome to visit Terrapin Tech in 0100 Patuxent Building for hands-on support or to contact the IT Service Desk at 301.405.1500 or itsupport@umd.edu for assistance. Hours of Operation

  • ELMS
  • Testudo
  • Terrapin Express
  • Payroll and Human Resources (PHR)
  • Box
  • MyDRL
  • MyUHC
  • Library services
  • Any other system that uses CAS (Central Authentication Service)

UMD is using Duo as our multi-factor authentication solution. It is incorporated into CAS, and you will be able to use it to log in using mobile devices, hardware tokens, or one-time use codes. Get more information about how Duo works.

Yes. After self-enrollment, you will be able to add additional devices and login methods

By default, every time you log into CAS. We strongly recommend you select the “Remember me for 24 hours” option in the Duo login. Doing so will require that you only need to authenticate with Duo once every 24 hours on each device or Web browser you use to log into CAS. 

We highly recommend that you enable “Auto Push,” a feature that will automatically send a login verification to your mobile device after you enter your correct Directory ID and password in CAS.

The following devices should be supported: iPhone, iPad, Android phones and tablets, Windows phones and tablets, cellphones, and hardware tokens. To learn more about specific device support, visit http://guide.duosecurity.com/.

If you get a new device, you can add it to your list of devices. You can do this while you still have your old device. If you no longer have your old device, you will need to remove it or have it removed by an administrator. Contact the IT Service Desk at 301.405.1500 for assistance.

We recommend you install the Duo app on a second device such as a tablet and enroll that device in Duo as well, or you can print a list of 10 one-time use codes, which are valid for 180 days. Please keep those codes in a safe location that only you have access to such as your wallet (but never with your password!). Get more information on how to generate one-time use codes.

Yes, more information about Duo's accessibility options are at https://duo.com/docs/accessibility.

Back to Top