Gallop Technology Group
Request an appointment
480-614-4227
Info@GallopTechGroup.com
  • Youtube
  • Facebook
  • Twitter
  • LinkedIn
  • Mail
  • Contact
    • Our Support Portal
    • New Client Intake Form
    • Technical Questionnaire
    • Join Our Family
  • Resources
    • Videos
    • Blog
  • Support
  • Solutions
    • Cybersecurity
    • Secured Cloud
    • Voice Over IP (VoIP)
    • Managed IT
    • Fractional CTO
    • IT Projects & Services
    • Legal Technology Solutions
  • Company
    • About Us
    • Team Bio
  • Home
  • Search
  • Menu Menu

Guide To Two-Factor Authentication

Offline Access for Windows Logon

Offline access for Duo Windows Logon helps you log on to Windows systems securely even when unable to contact Duo’s cloud service. You can activate one method for offline access, either Duo Mobile on iOS or Android or a U2F security key.

If your organization allows you to use this feature, you'll see the offline activation prompt after successful Duo two-factor authentication when you log in to, unlock the workstation, or approve a user elevation request while the system is online and able to contact Duo's service. Check with your organization's Duo administrators or Help Desk to verify availability of Offline Access on your workstation.

Activating Offline Access with Duo Mobile

Activating Offline Access with Duo Mobile

  1. Select Duo Mobile Passcode and click Activate Now to begin setting up offline access (or click Enroll later (May prevent offline login) to set it up another time).
  2. Scan the activation QR code using the Duo Mobile app installed on your iOS or Android device. Tap Add in the app and then tap Use QR code to begin adding the account by scanning the QR code shown by Duo for Windows.
  3. Enter a name for the new offline access account in Duo Mobile and tap Save to continue.
  4. Tap the new account you just added for your Windows computer in the Duo Mobile account list to generate a six digit passcode.
  5. Enter the passcode from Duo Mobile (without a space) into the offline activation screen on your computer and then click the Activate Offline Login button to finish setting up offline access.

Activating Offline Access with a Security Key

Duo's offline access works with these security keys:

  • Yubico brand keys supporting U2F/FIDO2
  • Google Titan
  • Feitian ePass FIDO
  • Thetis FIDO

HyperFIDO tokens are not supported for offline access activation, nor are simple OTP passcode tokens or Duo D-100 hardware tokens. If you're not sure whether your security will work, ask your organization's Duo administrator or your IT Help Desk.

To activate your security key for offline access:

  1. Select Security Key (Yubikey) and click Activate Now to begin setting up offline access (or click Enroll later (May prevent offline login) to set it up another time).
  2. Duo for Windows Logon attempts to contact your security key. If you don't have it plugged in, go ahead and insert it. You should see the security key begin flashing, and the Duo screen say Security key found - Tap to enroll. Touch your blinking security key to register it.
  3. Tap the security key again to verify.
  4. If successful, the Duo offline activation window says Security key verified - enrollment complete. Click the Activate Offline Login button to finish setting up offline access.

Authenticating with Offline Access

Once you’ve activated offline access for your account, when your computer isn’t able to contact Duo’s cloud service you’ll automatically be offered the option to login with an offline code or security key (depending on which type of device you activated earlier) after successfully submitting your Windows username and password during system logon or after entering your password in a UAC elevation prompt (if User Elevation is enabled).

If you activated Duo Mobile, tap the entry for your Windows computer in Duo Mobile to generate a passcode, enter it into the Duo prompt, and click Log In.

If you activated a security key, you should see it start blinking. Tap your security key to log in.

The offline two-factor authentication prompt shows you how many remaining offline logins you have left, or the last day you’ll be allowed to authenticate using offline access (depending on which option your organization's administrator chose when enabling offline access in the Duo Admin Panel).

Once you reach the offline access limit, the Duo prompt informs you that you must complete online authentication to Duo before you can log in again with an offline passcode. Offline access refreshes when you perform an online Duo authentication.

If Duo Authentication for Windows Logon was installed with the fail mode set to “fail closed”, then a user who does not activate offline access on that computer may not log in while disconnected from the internet. Make sure to complete offline activation the next time the computer has internet access.

Reactivating Offline Access

If you need to add the Windows Offline account to Duo Mobile on a different phone than you originally used for activation, you can do this from the online Duo MFA prompt.

IMPORTANT: Only one phone may be activated for offline access at a time. Activating offline access on another phone invalidates the previously activated phone.

If you restored the Duo Mobile accounts on your phone with Duo Restore, reactivating offline access won't reconnect the offline account that was restored. Instead, a second account for offline access will be created. Avoid confusion by deleting the restored offline access account before performing reactivation from the online Duo for Windows MFA prompt.

  1. With the Windows computer connected to the internet, log in with your username and password.
  2. Click the Replace/Reconnect an offline device link on the left side of the Duo prompt to begin. If your Duo for Windows Logon application is configured to automatically send a push request to your phone, you can cancel the authentication in progress and click the link on the left (don't approve the request on your phone).
  3. Next, you’ll need to complete Duo authentication. Click on an available method and approve the login request.
  4. Continue the activation process by scanning the QR code with Duo Mobile on the replacement phone and entering the verification code when prompted, just like the first time you activated an offline access device.

Pages

  • 2FA SETUP
  • 2FA-SETUP
  • About Us
  • Add a new user to BIG
  • Add a new user to your domain
  • Admin information
  • All-inclusive Support
  • Archive
  • AUGUST WHEELER
  • Backup and Disaster Recovery Services
  • Beits Livneh’s “Landing Page”
  • Billing Portal
  • Blog
  • Bold
  • chat
  • Chat is Unavailable
  • Check Ticket Status
  • Client Computer Quote
  • Client Quote Request Desktop
  • Client Quote Request Laptop
  • Client Registration
  • Coming soon
  • Configuring Office 365 Account on your Phone
  • Contact
  • Contact Support
  • Continued Education Classes
  • Cyber Security – Employee
  • Cyber Security – Manager
  • Cyber Training
  • Cybersecurity
  • DNS whitelist request form submission
  • Employment Schedule An Interview
  • Fast
  • Fractional CTO
  • GALLOP ALL INCLUSIVE SUPPORT DETAILS
  • GALLOP BACKUP AND DISASTER RECOVERY PACKAGE
  • GALLOP CYBER PLAN DETAILS
  • GALLOP SECURED CLOUD
  • GALLOP STARTER PACKAGE DETAILS
  • Guide To Two-Factor Authentication
  • Guide To Two-Factor Authentication
  • HOME
  • Home
  • Home backup 10/18/2022
  • Hosted Cloud Server
  • Hosted Exchange Account Management Fee
  • Hosted Exchange Registration Form
  • How to confirm your login password for Windows
  • How to connect to LTS cloud VPN
  • How to Log Off your Cloud Server Session
  • How to set up Sonicwall VPN on Windows 10
  • How to Update Older Version of Windows
  • HUB Page
  • Instructions on how to set up 2FA for the first time
  • Internal Quote Request
  • IT Projects & Services
  • Join Our Family
  • Legal Technology
  • Login Page
  • Managed IT
  • Microsoft Licensing Portal
  • New Client Intake Form
  • New Customer Questionnaire
  • New Email Account Request
  • NTS hosted exchange registration request
  • occ
  • Pay
  • Plan
  • Portal
  • Portal Page
  • Pre Employment Questionnaire Level 2 Engineer
  • Pre Employment Questionnaire – Engineer technical application
  • Pre Employment Questionnaire – Short Form
  • Privacy Policy
  • Proofpoint introduction
  • Quickbooks Maintenance Request
  • Remote Support
  • Remove user from your domain
  • Reporting & Statements Request
  • Request an appointment
  • Request to qualify a device for remote access
  • ROBERT VALVERDE
  • Search Results
  • Secured Cloud
  • SECURED CLOUD
  • Setting up an email account on an iPhone or iPad
  • Spam Filtering
  • Spirit Partner Technical Support
  • Spirited
  • Support
  • Team Bio
  • Terminate Computer
  • Terms of Service
  • Terms of Use
  • Test
  • test2
  • Thank you
  • Thoroughbred
  • Ticket lifecycle
  • User Information
  • Users Data Collection
  • Vendor data collection sheet
  • Videos
  • Voice Over IP (VoIP)
  • Welcome to Amit Donenfeld-Peled’s “Landing Page”
  • Welcome to August Wheeler’s “Landing Page”
  • Welcome to Eric Yared’s “Landing Page”
  • Welcome to John Michael Salbago’s “Landing Page”
  • Welcome to Michael Edwards’ “Landing Page”
  • Welcome to Michelle Wyrick’s “Landing Page”
  • Welcome to Robert Valverde’s “Landing Page”
  • Client Services
  • Client Services
  • Email portal
  • Submit A Ticket

Categories

  • Blog
  • Newsletter
  • Uncategorized

Archive

  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • November 2021
  • October 2021
  • August 2021

Contact Us Today For Exceptional Technical Support For Your Businesses!

Click Here for Your Free Assessment
480-614-4227 - GallopTechGroup.com
Scroll to top