2Factor Authentication

advertisement
2Factor Authentication
Replace image
with a 3C image
2Factor Authentication
2Factor Authentication
Communications Plan
1. Focus group of cross-campus users
2. UC Creative for design work
3. Outreach presentations to various groups
4. Postcard mailing to staff in summer, to faculty in fall
5. Bulk Email
6. Posters around campus
7. Techb@r training events
8. Internal/technical documentation
9. ITS Support Desk training
10. ITS website, social media, newsletters
11. Brochure on safe computing that includes 2FA
12. Knowledge Base articles links from 2FA
2Factor Authentication
2
FOCUS GROUP
Quiz on password strength/usage
Yeah, you can still stumble around...and no
one can say you don't have singleminded
focus, but when you don't use your brain, you
end up having to eat them.
The good news is, you really can't go
anywhere but up. Just changing your
password will move you into the land of the
living---"Aaarr!Rrrrrr!" should work just fine!
Two-Step Authentication
2Factor Authentication
Focus Group – Quiz Score
You are the softest little furball out there with the pinkest toe pads and a purr so sweet it causes
toothaches. The electricity spent streaming videos of you chasing your tail and discovering wet food
could fuel a small country. The problem is, when everyone knows you, everyone really wants to
know you! You may not even recognize the big electronic target on your forehead what with all the
sweet grooming sessions and adorable naps with the dog.
Spend a moment or two considering where your information is distributed and make sure that the
only thing you distribute is your own floofy brand of twee.
You are the greatest of the Greek heroes; the subject of epic poetry, demigod, and played by
Brad Pitt. Obviously, there's a lot going right for you.
Buuut . . . there is that tricky heel issue. Don't let the fact that you created a password strong
enough for the ages prevent you from doing the right thing and changing it regularly.
2Factor Authentication
4
2Factor Authentication
Rollout
1.
2.
3.
4.
5.
6.
Test scripts – internal testing
Pilot program – early adopters
Soft rollout this summer
Summer announcements – staff rollout
Fall announcements – faculty rollout
Adjustments and enhancements
2Factor Authentication
5
2Factor Authentication
Postcard
2Factor Authentication
6
2Factor Authentication
Poster
2Factor Authentication
7
2Factor Authentication
Sample Outreach PowerPoint
Here are some slides from an earlier introduction....
2Factor Authentication
8
2Factor Authentication
https://www.duosecurity.com/why-two-factor
2Factor Authentication
2Factor Authentication
2Factor Authentication enhances the security
of your account by using a device (such as your
phone) to verify your identity. This prevents
anyone but you from accessing your account,
even if they know your password.
We are using “Duo Security” software for our
authentication.
The “duo” factors are:
1. Your CNetID (no changes to this use)
2. A verification sent to your device
(smartphone, landline, tablet, other
alternatives)
10
2Factor Authentication
Why Do I Need This?
Passwords are becoming increasingly easy to
compromise. They can be stolen, guessed, and
hacked — you might not even know who else
has your password and is accessing your
account.
Two-factor authentication adds a second layer
of security to your account to make sure that
your account stays safe, even if someone else
knows your password. And you'll be alerted
right away (on your phone) if someone does
know your password and tries to log in with it.
11
2Factor Authentication
Will 2FA affect all the applications that I can access?
2FA is only for University of Chicago sites that use
Shibboleth authentication. There are two ways you can
interact with 2FA.
1. You can opt-in so that you will need to authenticate
using 2FA on all University sites with Shibboleth.
2.
You can register a device so that you will be ready in
case any University sites elect to require 2FA.
12
2Factor Support
ITS Support will be available by the usual methods .…
2Factor Authentication
13
2Factor Authentication
Initial Screen
14
2Factor Authentication
Opt In
15
2Factor Authentication
Online Support link from 2FA
What are commonly visited UC sites using Shibboleth?
#
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
Description
ESS - Employee Self-Serve
Remote access to Library databases (proxy)
My Chicago University portal
UChicago Google Applications Service (including gMail)
cAlert - emergency notification system
Vendor Management Database for procurement
Institutional Review Board Management System
Grants Management System
Inter-Library Loan
CNetID site for Trusted Agent management
JSTOR academic publisher
UChicago's Service-Now Issue Management System
Personalized use of Library catalog
Instructor's course management
Detailed information about classes
Career Advancement service
2Factor Authentication
Site
ess.uchicago.edu/ess
login.proxy.uchicago.edu/ezproxy
my.uchicago.edu
google.com
calert.uchicago.edu
non-po.uchicago.edu
aurairb.uchicago.edu
auragrants-prod.uchicago.edu
requests.lib.uchicago.edu
cnet.uchicago.edu
www.jstor.org
uchicago.service-now.com
libcat.uchicago.edu
facultyaccess.uchicago.edu
classes.uchicago.edu
careeradvancement.uchicago.edu
16
2Factor Authentication
When you select the
recommended Duo Push,
this is what Duo looks like
on your phone …
2Factor Authentication
17
2Factor Authentication
Then you will proceed to the site
you originally requested.
2Factor Authentication
18
2Factor Authentication
Yikes! I’m NOT signing in!!
• Click “Deny”
• Click to report it as fraudulent, or
oops – my mistake & re-try.
• Fraudulent? Email will be sent to
our Duo Administrator & tracked
on the 2FA log
2Factor Authentication
19
2Factor Alternatives
Alternative to a smartphone:
1. Register your office and home phones – as
many phones as you may use. You will
receive an automated voice message with
a passcode to use.
2. Register your Tablet. You will receive the
Approve/Deny prompt.
3. Tokens – departments will be able to
order from the Identity & Privileges Office
in Regenstein for a nominal fee.
2Factor Authentication
20
2Factor Alternatives
How do I use the token?
• Just press a button on the token to view a
passcode
• Key in that passcode on the login prompt
2Factor Authentication
21
2Factor Summary
• 2Factor Authentication helps secure University data
• The University has been the target of phishing schemes.
•Various device options are available
• Register smartphones, landlines, tablets, or tokens
•Support
• Contact itservices@uchicago.edu or visit the TECHB@R
2Factor Authentication
22
2Factor Authentication
Questions?
2Factor Authentication
23
Download