Duo Verified Push - Resource Guide

Summary

Previously, users simply approved or denied a login request by pressing a button in the Duo Mobile app. With Duo Verified Push, you will now be asked to enter a 3-digit verification code displayed on the sign-in screen into the Duo Mobile app before approving the request.

Body

Resource Guide - Using Duo Verified Push Multi-Factor Authentication (MFA)

What is Duo Verified Push?

The University of Richmond uses Duo Multi-Factor Authentication (MFA) to help protect university accounts and data. All faculty, staff, and students are required to use Duo MFA when accessing certain university technology services.

Previously, users simply approved or denied a login request by pressing a button in the Duo Mobile app. With Duo Verified Push, you will now be asked to enter a 3-digit verification code displayed on the sign-in screen into the Duo Mobile app before approving the request.

This added verification helps confirm that you are the person initiating the login.
Duo Verified Push will be required when accessing select University of Richmond services, including but not limited to UR email, Box, Workday, and Virtual Private Networking (VPN). 
 

Why is this changing?

Cybercriminals increasingly use a technique known as Push Fatigue (or push bombing) by repeatedly sending authentication requests in the hope that someone accidentally approves one.

Duo Verified Push helps prevent these attacks by requiring you to enter a unique 3-digit code that is presented by the application for each authentication attempt. Because only the person attempting to sign in can see this code, it provides an additional layer of protection while adding only a few seconds to the login process.

For more information about MFA push fatigue attacks, see: https://sl.richmond.edu/JM

Details / Instructions

How does Duo Verified Push work?

Step 1: Sign in
Log in to your University of Richmond account or university service as you normally would. When prompted for Duo MFA, the application will present you with a 3-digit verification code. 

The application provides you a 3-digit code, do NOT use a random code.

Uploaded Image (Thumbnail)


Step 2: Open the Duo Mobile app
Open the Duo Mobile app. A field will be displayed requesting a 3-digit verification code.

Uploaded Image (Thumbnail)

Step 3: Enter the 3-digit verification code presented by the application you are currently accessing.

Do NOT enter a code in Verified Push unless you get it directly from the application.

Step 4: Complete authentication by pressing “Verify”
After entering the correct code, approve the authentication request in Duo by pressing the “Verify” button. You will then be signed in to the requested service.


What if I didn't initiate the login?

If you receive a Duo Verified Push request but are not trying to sign in:
•    Do not enter a verification code.
•    Deny the authentication request.
•    Report the unexpected login attempt to infosec@richmond.edu


Frequently Asked Questions

  1. Will I need to do this every time I log in?
    • Only for services that require Duo Verified Push. Some university services may continue to use the standard Duo MFA process or will not require Duo MFA.
  2. What if I enter the wrong code?
    • Simply return to the login screen, verify the displayed code, and enter it again.
  3. What if I don't have my phone?
    • If you are unable to access the Duo Mobile app, use another registered authentication method (if available) or contact the Help Desk for assistance.
  4. Is Duo Mobile available for my device?
    • Duo Mobile is available from the official app stores for:
      • Apple iOS devices
      • Android devices
  5. I use my Apple Watch to approve Duo requests. How will this be impacted?
    • Apple Watch can still be used. You will need to send the verification code using the Watch interface by hitting the "Enter Code" button and then typing the code into the reply field. 

Need Help?

If you experience issues with Duo Verified Push or have questions about Multi-Factor Authentication, contact:
University Help Desk
(804) 287-6400
helpdesk@richmond.edu
SpiderTechNet

Details

Details

Article ID: 163554
Created
Tue 7/14/26 9:18 AM
Modified
Wed 7/22/26 10:06 AM