Duo Enrollment: Post-SMS & Phone Disable

 

Users reliant on SMS or phone 2FA lose self-enrollment once those options are disabled; an admin must then enroll them manually by using a bypass code or an admin‑initiated activation link.

What changes once SMS & phone calls are disabled?

When SMS and phone call authentication are turned off, users who used these methods:

  • Cannot authenticate using those methods to reach the Duo enrollment prompt.

  • Cannot add Duo Mobile or Hardware Security Key themselves because they cannot complete the required authentication step.

Admins must provide a temporary access method (bypass code or admin‑initiated activation link) so the user can enroll Duo Mobile or Hardware Security Key.

 

How to enroll users in Duo Mobile after SMS and phone calls are Disabled

 

Option 1 — Use a Duo Bypass Code (Recommended) 

This is the most reliable method for users who cannot authenticate via SMS or Phone. 

Admin Steps:

  1. Locate User: Log into the Duo Admin Panel, go to Users, and select the specific user.

  2. Generate Code: Scroll to the "Bypass Codes" section and click Generate Bypass Code.

  3. Secure Delivery: Send the code to the user securely (e.g., via Password Pusher).

User Steps:

  1. Install App: Download Duo Mobile from the App Store or Google Play.

    • Requirement: iOS 16.0+ or Android 12.0+.

  2. Login: Access your Duo-protected application. When prompted for 2FA, select Enter a Passcode.

  3. Authenticate: Enter the bypass code provided by the Admin.

  4. Register Device: Once logged in, go to My Settings & Devices > Add a device and choose Mobile phone.

  5. Sync: Scan the QR code displayed on the screen with your Duo Mobile app camera to complete enrollment.

  1.  

Option 2 — Resend a Duo Mobile Activation Link 

Use this method if the user already has a smartphone listed in the Duo Admin Panel, but the app is not activated, or the "Duo Push" option isn't working.

Admin Steps:

  1. Search User: In the Duo Admin Panel, go to Users and select the affected user.

  2. Verify Device: Scroll to the Phones table.

    • Note: If the "Platform" column says Unknown, click Edit and change it to the correct OS (e.g., Android or iOS) before proceeding.

  3. Send Link: Under the device settings, click Send Duo Mobile Activation Link.

  4. Choose Method: Select Send Link via SMS (this will work even if 2FA-via-SMS is disabled, as it is a setup link, not a login code).

User Steps:

  1. Open Message: Open the SMS text message from Duo on your phone.

  2. Activate: Tap the link within the message. It will automatically open the Duo Mobile app and link your account.

  3. Confirm: Once the app shows your organization’s account, you are ready to receive Pushes for future logins.

Option 3 — Admin Manually Adds the User’s Smartphone 

Use this method if the user is entirely new to Duo or has never had a phone number associated with their account.

Admin Steps:

  1. Access User Profile: In the Duo Admin Panel, go to Users and select or search for the user.

  2. Add Device: Click the Add Phone button.

  3. Enter Details: * Input the user's mobile phone number.

    • Select Mobile as the type.

    • Click Add Phone to save the record.

  4. Finalize: You must now complete the process by using either Option 1 (providing a bypass code) or Option 2 (sending an activation link) so the user can link their app to this new record.

User Steps:

  1. Coordinate: Stay in contact with your Admin to receive either your one-time bypass code or your SMS activation link.

  2. Follow Setup: Refer to the "User Steps" in Option 1 or Option 2 above to finish linking your device to the Duo Mobile app.

Enroll Hardware Security Key After SMS and Phone Calls are Disabled

Users reliant on SMS or phone 2FA lose self-enrollment once those options are disabled; an admin must then enroll them manually by using a bypass code or an admin‑initiated activation link.

What changes once SMS & phone calls are disabled?

When SMS and phone call authentication are turned off, users who used these methods:

  • Cannot authenticate using those methods to reach the Duo enrollment prompt.

  • Cannot add Duo Mobile or Hardware Security Key themselves because they cannot complete the required authentication step.

Admins must provide a temporary access method (bypass code or admin‑initiated activation link) so the user can enroll Duo Mobile or Hardware Security Key.

The two valid admin‑provided methods are:

  1. Bypass code (most reliable)

  2. Admin‑initiated WebAuthn enrollment link

Option 1 — Enroll Hardware Security Key using a Duo Bypass Code (Recommended) 

Use this method if the user needs to register a physical security key (like a YubiKey) and cannot use SMS or Phone calls to authenticate.

Admin Steps:

  1. Locate User: In the Duo Admin Panel, navigate to Users and select or search for the user.

  2. Generate Code: Click the Generate Bypass Code button.

  3. Secure Delivery: Provide the code to the user securely. You may use Password Pusher to ensure the code expires after it is read.

User Steps:

  1. Start Login: Log into any Duo-protected application.

  2. Enter Bypass: When the Duo prompt appears, select Other options (or Enter a Passcode) and type in the bypass code provided by your admin.

  3. Access Settings: Once logged in, click on Settings or Add a new device within the Duo prompt.

  4. Select Key: Choose Security Key (YubiKey, etc.) from the list of device types.

  5. Register Key: * Insert your Security Key into your computer’s USB port.

    • When prompted by your browser, tap the gold sensor/button on your Security Key.

  6. Complete: The Duo prompt will confirm that the registration is successful. You can now use this key for future logins.

Option 2 — Admin‑initiated enrollment link

Admin Steps:

  1. Select User: In the Duo Admin Panel, go to Users and select the specific user.

  2. Initiate Link: Scroll to the Security Keys section and click Add or Send enrollment link.

  3. Delivery: Duo will automatically email a unique, time-sensitive enrollment link to the user’s email address on file.

User Steps:

  1. Open Email: Access your email and click the enrollment link sent by Duo. This will open the Duo setup portal in your web browser.

  2. Prepare Hardware: When prompted, insert your Security Key (YubiKey) into the USB port.

  3. Register: Follow the on-screen prompts and tap the gold sensor/button on the key when the browser asks for permission.

  4. Confirm: Once the screen says "Enrollment Successful," your hardware key is linked and ready for use.

Note: This method is highly efficient because it bypasses the need for the user to authenticate with a code or phone call during the setup process.

 

Additional Resources

For more support and self-help articles and resources, visit our ITS Ticketing Service Catalog at help.maricopa.edu or you can call the District Information Technology Service support line directly at 480-731-8632