Overview
Two-step authentication uses two forms of authentication to verify your identity. First, you enter your SUNet ID and password. Then you need a physical device such as your mobile phone, tablet, or landline phone to complete the login. This approach protects your Stanford account from fraudulent access.
There are seven physical devices that you can use to provide the second factor of two-step authentication. Each device has one or more authentication methods available.
Device Type | Authentication Options | Supported Platforms |
---|---|---|
Smartphone |
|
|
Tablet |
|
|
Mobile Phone |
|
|
Landline |
|
|
YubiKey |
|
|
Security Key |
|
|
Note: If you currently use Google Authenticator for your second factor you can continue to do so. However, you are no longer able to set up Google Authenticator on your smartphone or tablet. The Duo Mobile app is the preferred replacement.
Getting started
To get started, select the device you want to set up:
One device must be designated as your default device, and your default device must have a preferred way to authenticate. Stanford Login prompts you to authenticate using your default device and preferred method but you have the option of authenticating using a different device (if you have other devices set up) or method.
You are strongly encouraged to set up a backup device in case your primary device is lost or unavailable.
What to expect with two-step authentication
Once you enable two-step authentication, you may see an extra page after you sign into a Stanford resource via Login. If you are using a browser that you previously used to authenticate, you will be presented with the last-used authentication method. To choose a different authentication method from what is provided initially in the prompt, you can select Other options to choose one of the other options that may be available to you. How frequently you are asked to authenticate on your default device varies, depending upon:
- the website you're accessing (for added security, some sites always require a two-step authentication)
- your individual browser settings (whether or not you clear cookies)
- whether or not you use more than one computer and web browser (two-step authentication is requested at least every 90 days for each computer and each browser you use to access protected websites)
- if you are prompted with a screen that asks if you want to trust the browser. You’ll have the option to select “Yes, trust browser.” This takes the place of the “Remember Me” screen. If you click “Yes, trust browser” the browser will automatically remember you, and you will not be prompted to authenticate for that application or service for the next 90 days.
How you authenticate depends upon the device and method you chose for two-step authentication:
- If you chose Duo Mobile push notifications: a push notification is sent to the device, and you can review the request and tap Approve to authenticate. Internet or cellular access is required.
- If you chose SMS text message: you receive a text message on your device containing a passcode. Enter the passcode on the two-step authentication screen to authenticate.
- If you chose Phone Call: you receive an automated phone call that requires you to press or tap any key on your phone to authenticate.
- If you chose Security Key: press the Security Key sensor when prompted to authenticate.
Information for international travelers
We recommend that anyone who travels internationally and needs to log in to Stanford websites use the Security Key. You can use Security key to generate your authentication code without an Internet or cellular connection.