2Factor Authentication Replace image with a 3C image 2Factor Authentication 2Factor Authentication Communications Plan 1. Focus group of cross-campus users 2. UC Creative for design work 3. Outreach presentations to various groups 4. Postcard mailing to staff in summer, to faculty in fall 5. Bulk Email 6. Posters around campus 7. Techb@r training events 8. Internal/technical documentation 9. ITS Support Desk training 10. ITS website, social media, newsletters 11. Brochure on safe computing that includes 2FA 12. Knowledge Base articles links from 2FA 2Factor Authentication 2 FOCUS GROUP Quiz on password strength/usage Yeah, you can still stumble around...and no one can say you don't have singleminded focus, but when you don't use your brain, you end up having to eat them. The good news is, you really can't go anywhere but up. Just changing your password will move you into the land of the living---"Aaarr!Rrrrrr!" should work just fine! Two-Step Authentication 2Factor Authentication Focus Group – Quiz Score You are the softest little furball out there with the pinkest toe pads and a purr so sweet it causes toothaches. The electricity spent streaming videos of you chasing your tail and discovering wet food could fuel a small country. The problem is, when everyone knows you, everyone really wants to know you! You may not even recognize the big electronic target on your forehead what with all the sweet grooming sessions and adorable naps with the dog. Spend a moment or two considering where your information is distributed and make sure that the only thing you distribute is your own floofy brand of twee. You are the greatest of the Greek heroes; the subject of epic poetry, demigod, and played by Brad Pitt. Obviously, there's a lot going right for you. Buuut . . . there is that tricky heel issue. Don't let the fact that you created a password strong enough for the ages prevent you from doing the right thing and changing it regularly. 2Factor Authentication 4 2Factor Authentication Rollout 1. 2. 3. 4. 5. 6. Test scripts – internal testing Pilot program – early adopters Soft rollout this summer Summer announcements – staff rollout Fall announcements – faculty rollout Adjustments and enhancements 2Factor Authentication 5 2Factor Authentication Postcard 2Factor Authentication 6 2Factor Authentication Poster 2Factor Authentication 7 2Factor Authentication Sample Outreach PowerPoint Here are some slides from an earlier introduction.... 2Factor Authentication 8 2Factor Authentication https://www.duosecurity.com/why-two-factor 2Factor Authentication 2Factor Authentication 2Factor Authentication enhances the security of your account by using a device (such as your phone) to verify your identity. This prevents anyone but you from accessing your account, even if they know your password. We are using “Duo Security” software for our authentication. The “duo” factors are: 1. Your CNetID (no changes to this use) 2. A verification sent to your device (smartphone, landline, tablet, other alternatives) 10 2Factor Authentication Why Do I Need This? Passwords are becoming increasingly easy to compromise. They can be stolen, guessed, and hacked — you might not even know who else has your password and is accessing your account. Two-factor authentication adds a second layer of security to your account to make sure that your account stays safe, even if someone else knows your password. And you'll be alerted right away (on your phone) if someone does know your password and tries to log in with it. 11 2Factor Authentication Will 2FA affect all the applications that I can access? 2FA is only for University of Chicago sites that use Shibboleth authentication. There are two ways you can interact with 2FA. 1. You can opt-in so that you will need to authenticate using 2FA on all University sites with Shibboleth. 2. You can register a device so that you will be ready in case any University sites elect to require 2FA. 12 2Factor Support ITS Support will be available by the usual methods .… 2Factor Authentication 13 2Factor Authentication Initial Screen 14 2Factor Authentication Opt In 15 2Factor Authentication Online Support link from 2FA What are commonly visited UC sites using Shibboleth? # 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 Description ESS - Employee Self-Serve Remote access to Library databases (proxy) My Chicago University portal UChicago Google Applications Service (including gMail) cAlert - emergency notification system Vendor Management Database for procurement Institutional Review Board Management System Grants Management System Inter-Library Loan CNetID site for Trusted Agent management JSTOR academic publisher UChicago's Service-Now Issue Management System Personalized use of Library catalog Instructor's course management Detailed information about classes Career Advancement service 2Factor Authentication Site ess.uchicago.edu/ess login.proxy.uchicago.edu/ezproxy my.uchicago.edu google.com calert.uchicago.edu non-po.uchicago.edu aurairb.uchicago.edu auragrants-prod.uchicago.edu requests.lib.uchicago.edu cnet.uchicago.edu www.jstor.org uchicago.service-now.com libcat.uchicago.edu facultyaccess.uchicago.edu classes.uchicago.edu careeradvancement.uchicago.edu 16 2Factor Authentication When you select the recommended Duo Push, this is what Duo looks like on your phone … 2Factor Authentication 17 2Factor Authentication Then you will proceed to the site you originally requested. 2Factor Authentication 18 2Factor Authentication Yikes! I’m NOT signing in!! • Click “Deny” • Click to report it as fraudulent, or oops – my mistake & re-try. • Fraudulent? Email will be sent to our Duo Administrator & tracked on the 2FA log 2Factor Authentication 19 2Factor Alternatives Alternative to a smartphone: 1. Register your office and home phones – as many phones as you may use. You will receive an automated voice message with a passcode to use. 2. Register your Tablet. You will receive the Approve/Deny prompt. 3. Tokens – departments will be able to order from the Identity & Privileges Office in Regenstein for a nominal fee. 2Factor Authentication 20 2Factor Alternatives How do I use the token? • Just press a button on the token to view a passcode • Key in that passcode on the login prompt 2Factor Authentication 21 2Factor Summary • 2Factor Authentication helps secure University data • The University has been the target of phishing schemes. •Various device options are available • Register smartphones, landlines, tablets, or tokens •Support • Contact itservices@uchicago.edu or visit the TECHB@R 2Factor Authentication 22 2Factor Authentication Questions? 2Factor Authentication 23