This site requires JavaScript to be enabled
An updated version of this article is available

2FA: Log in to WebAccess using Two-Factor Authentication

588 views

9.0 - Updated on 08-20-2024 by Chris Ritzko (cxr167)

8.0 - Updated on 08-20-2024 by Dustin Wilt (drw5258)

7.0 - Updated on 02-28-2023 by Dustin Wilt (drw5258)

6.0 - Updated on 02-28-2023 by Dustin Wilt (drw5258)

5.0 - Updated on 05-24-2022 by Kim D (kad959)

4.0 - Updated on 05-28-2021 by Eileen Mershon (ejm5988)

3.0 - Updated on 12-03-2019 by Eileen Mershon (ejm5988)

2.0 - Updated on 06-27-2019 by Eileen Mershon (ejm5988)

1.0 - Authored on 03-07-2019 by Eileen Mershon (ejm5988)

Article Intended For

Penn State faculty, staff, students, and other affiliates currently enrolled in two-factor authentication (2FA).

Introduction

Each time you authenticate your log in to WebAccess, you have the opportunity to select the device and the method you would like to use.  The choices you see on the 2FA Authentication Required screen reflect the devices you've enrolled.

This article includes the following information:

General Instructions for Authentication

What to Do If You Receive an Authentication Request You're Not Expecting

Specific Instructions for Each Method of Authentication (including which are available for each device)

 

Step-by-Step Instructions

General Instructions for Authentication

  1. Navigate to the website or service you wish to log in to.

NOTE: If you have already logged in to another resource using WebAccess today, you may not be required to log in again in order to gain access to other WebAccess protected sites.

  1. On the WebAccess log in screen, enter your user ID (Example: abc123) and password to log in to your Penn State Access Account; then click Log In

The 2FA Authentication Required screen is displayed. A drop-down list shows the devices you have enrolled for 2FA, using the nicknames you chose when you enrolled them.

  1. Choose the method you would like to use to authenticate:
  1. From the drop-down list of your enrolled devices, select the device to which you would like the 2FA service to send an authentication request and the method you would like to use.

OR

  1. If you have used one of your enrolled devices to generate a passcode, or have been provided a passcode by the IT Service Desk, enter it in the box provided.

  1. Click Log In.  If you selected one of your enrolled devices, rather than entering a passcode, use the device to complete the authentication process.

See Specific Instructions, below, for more details about using each method.

What to Do If You Receive an Authentication Request You're Not Expecting

When should I deny a request?

If you receive a phone call or Duo Push authentication request when you're not trying to log in to the requesting service, you should deny the request.

When should I report a fraudulent request?

Reporting a fraudulent request will lock your account. So, before you report an authorization phone call or Duo Push notification as fraud, see knowledge base article 2FA: I got a Request to Authenticate When I Wasn't Trying to Log In to learn about other reasons you may receive an unexpected authorization request.

NOTE:  If you deny a Duo Push notification, the app will immediately prompt you to identify the request as either a mistake or fraud.  If you're not familiar with the other reasons for an unexpected authentication request, choose Mistake, and review the above referenced knowledge base article. 

Specific Instructions for Each Method of Authentication

The list below indicates the method(s) of authentication that are available for each type of device. 

Click one of the following links to navigate to the section of this article that describes how to use the specific device and method you're interested in.

Smartphone - Duo Mobile app installed and active

Smartphone - Duo Mobile app not installed or not active

Basic Cellphone

Landline

Tablet with Duo Mobile app installed and active

Duo Token

Apple Watch

Use Duo Push to Authenticate

Device Requirement:  The Duo Push method can be used with the following enrolled devices:

Additional Requirements

Instructions:

On the phone or tablet you're using for authentication:

  1. Make sure the screen is unlocked (unless you wish to authenticate using your Apple Watch, in which case your phone must be locked).

On the device you're using to log in to the site you want to access (laptop, desktop, phone, or tablet):

  1. Navigate to the website or service you wish to log in to.
  2. On the WebAccess log in screen, enter your user ID (Example: abc123) and password to log in to your Penn State Access Account; then click Log In.

The 2FA Authentication Required screen is displayed.  A drop-down list shows the devices you have enrolled for 2FA, using the nicknames you chose when you enrolled them.

  1. If it's not already selected, select the smartphone or tablet you wish to use to authenticate from the drop-down list of enrolled devices.

If you have previously downloaded and activated the Duo Mobile app, Duo Push will already be selected as the default method of authentication.

NOTE:  If Duo Push is not displayed as an option, you may need to re-activate Duo Mobile.  See knowledge base article 2FA: Activate or Re-Activate DUO Mobile on my Smartphone to Receive 2FA Push for additional information.

  1. Click Log In.

A log in request is sent to your authentication device. 

On the device you're using to authenticate (your smartphone, tablet, or Apple watch):

  1. A log in request notification is displayed on your screen.  It shows the name of the resource requesting authentication (in this case, WebAccess), and offers the option to Approve or Deny the request.

Follow the on-screen instructions to approve the request.  The website you're logging in to appears as soon as you approve the authentication request.

Use a Duo Passcode to Authenticate

Device Requirement:  The Duo Passcode method can be used with the following enrolled devices:

Additional Requirements

Instructions:

On the device you're using to log in to the site you wish to access (laptop, desktop, phone, or tablet):

  1. Navigate to the website or service you wish to log in to.
  2. On the WebAccess log in screen, enter your user ID (Example: abc123) and password to log in to your Penn State Access Account; then click Log In.

The 2FA Authentication Required screen is displayed.  A drop-down list shows the devices you have enrolled for 2FA, using the nicknames you chose when you enrolled them.

On the device you wish to use to authenticate (your smartphone or tablet):

  1. Open the Duo Mobile app. 

On your Android or iPhone:

  1. If Penn State is the only account you have linked to Duo Mobile, a Duo passcode is displayed on your screen as soon as you open the app on your Android or iPhone.

  

  1. If you have more than one account linked to Duo Mobile on your Android or iPhone, tap the down-arrow ( Image of down arrow ( downward pointing caret ) ) next to your Penn State account to expand it and show your Duo passcode.

On your Windows phone:

Tap the green key symbol  or Generate Passcode , depending on your version of Windows.

On the device you're using to log in to the site you wish to access (laptop, desktop, phone, or tablet):

  1. In the Passcode box on the 2FA Authentication Required screen, enter the six-digit code generated by Duo Mobile.

  1. Click Log In.

The website you're logging in to appears.

If it doesn't, return to the Duo app on your phone and tap the refresh symbol ( Image of refresh symbol (chasing arrows) ) to generate a new passcode.  Enter the new passcode in the Passcode box on the 2FA Authentication Required screen, and try again.  If you're not logged in at this point, call the IT Service Desk for assistance.

 

Use a Phone Call to Authenticate

Device Requirement:  The phone call method can be used with the following enrolled devices:

Additional Requirements:

Instructions:

On the device you're using to log in to the site you wish to access (laptop, desktop, phone, or tablet):

  1. Navigate to the website or service you wish to log in to.
  2. On the WebAccess log in screen, enter your user ID (Example: abc123) and password to log in to your Penn State Access Account; then click Log In.

The 2FA Authentication Required screen is displayed.  A drop-down list shows the devices you have enrolled for 2FA, using the nicknames you chose when you enrolled them.

  1. If it's not already selected, select the phone you wish to use to authenticate from the drop-down list of enrolled devices.

  1. Select Phone Call to indicate the method of authentication you wish to use, and click Log In.

The 2FA service generates a phone call to the phone you selected.

  1. Answer the phone call and follow the instructions you hear to approve the authentication request.

The website you're logging in to appears as soon as you approve the authentication request.

 

Use SMS Text Passcode to Authenticate

Device Requirement:  The SMS text passcode method can be used with the following enrolled devices:

 

Additional Requirements

Instructions:

On the device you're using to log in to the site you wish to access (laptop, desktop, phone, or tablet):

  1. Navigate to the website or service you wish to log in to.
  2. On the WebAccess log in screen, enter your user ID (Example: abc123) and password to log in to your Penn State Access Account; then click Log In.

The 2FA Authentication Required screen is displayed.  A drop-down list shows the devices you have enrolled for 2FA, using the nicknames you chose when you enrolled them.

  1. Select the phone on which you wish to receive a text message from the drop-down list of enrolled devices.

 

  1. Click Send text with Passcodes to My Cellphone (just below the box that says Passcode).

The 2FA service sends a text message with 10 one-time use passcodes to the phone you selected. 

  1. On the 2FA Authentication Required screen on the device you're using to log in, enter one of the passcodes from the text message in the Passcode box, and click Log in.

The website you're logging in to appears.

NOTE:  You may use the remaining passcodes for future log-ins.  Each passcode may be used for one log in.  Each time you select the same phone for authentication, a hint just above the link you clicked in Step 4, above, indicates which of the remaining passcodes should be used next.

 

Use a Hardware Generated Passcode to Authenticate

Device Requirement

On the device you're using to log in to the site you wish to access (laptop, desktop, phone, or tablet):

  1. Navigate to the website or service you wish to log in to.
  2. On the WebAccess log in screen, enter your user ID (Example: abc123) and password to log in to your Penn State Access Account; then click Log In.

The 2FA Authentication Required screen is displayed.  A drop-down list shows the devices you have enrolled for 2FA, using the nicknames you chose when you enrolled them.

  1. Press and release the button on your Duo Token to display a passcode.
  2. Enter the passcode in the Passcode box on the 2FA Authentication Required screen and click Log In.

The website you're logging in to appears.

  1. If the code you entered simply disappeared without logging you in: