You may remember that back in April, campus instituted 2-step authentication to do certain tasks within Workday. 2-Step authentication is now being expanded to include more sites and campus has been sending out e-mails to all staff about the upcoming requirement.
More information about 2-step is on my blog page from back in April here: https://blogs.cornell.edu/wsbnit/2017/03/31/two-step-login/ and on CIT’s web page here: https://it.cornell.edu/twostep/.
You can view a copy of the e-mails being sent from campus here: https://it.cornell.edu/verified/5132, https://it.cornell.edu/verified/5131 and at https://it.cornell.edu/verified/5202.
Starting August 1st, this 2-step authentication will be REQUIRED any time you see the CUWeblogin page (see screenshot of login page below).
We typically see this login page when we go to:
- Workday
- Kronos
- CCE Business Systems
- Box
- Lynda
- Cornell’s Dropbox
Why is Cornell Using 2-Step?
2-Step login makes it much more difficult for intruders to use your identity to access campus services. Even if your password has been stolen, the second step to the login process will prevent someone from logging in. This decreases your risk of account compromises and identity theft, along with the consequences of lost time, money, and privacy.
CCE’s Fact Sheet about 2-Step can be found here: http://staff.cce.cornell.edu/Information_Technology/Documents/2stephowto.pdf
What Devices Can I Register?
- Any phone number (landline or cell; work or home)
- Smartphone or tablet with Duo mobile app installed
- U2F token (works only with Chrome on a PC with a USB port)
- NOW AVAILABLE TO ALL REGULAR CCE STAFF: Duo hardware token
This is a mobile alternative for staff instead of using a personal device.
What do you need to do BEFORE August 1st?
- Go see your local IT contact about receiving your hardware token.
- Please note: If you choose not to use a hardware token you must still see your local IT contact to sign off that you do not wish to receive one at this time.
- Cattaraugus, Genesee, Monroe, Orleans and Wyoming: Your hardware tokens are now available in your office.
- Allegany, Erie, Niagara: Your hardware tokens will be available in your office next week.
- Chautauqua: Your hardware tokens will be available on August 1st.
- Ag Team Specialists: Your hardware tokens will be available at your upcoming Regional Ag Team Retreat next week. For those of you not going to the meeting, your token is available in your local CCE office (see availability for your office above).
- Please note: If you choose not to use a hardware token you must still see your local IT contact to sign off that you do not wish to receive one at this time.
- Register your devices at http://twostep.netid.cornell.edu
- Go to: http://twostep.netid.cornell.edu, log in with your NetID
- Click Manage Devices
- NOTE: if you have already enrolled devices, you will need to authenticate with a second device to get to this page
- Follow the instructions on this page to add phone numbers, smartphones/tablets, and U2F tokens
- CIT’s Step by Step Instructions: https://it.cornell.edu/sites/default/files/Two-Step%20Login/CIT%20Two-Step%20Login%20Enrollment%20Guide.pdf
- To register a Duo hardware token, click the “Enroll a Hardware Token” tab
How to video: https://www.youtube.com/watch?v=-TCOVYp2PRo&feature=youtu.be
(Please note: there is sound with this video how-to.)
For CIT’s full 40-minute 2-step authentication training video, go to: https://vod.video.cornell.edu/media/t/1_d32j1wyo
- Optional: Opt-in to require 2-step authentication now!
- If you would like to start requiring 2-step authentication now, instead of waiting for the August 1st deadline, go to https://it.cornell.edu/twostep/expand for more information.
- Optional: Test out your registered devices
- If you choose not to opt-in now, the easiest way to test out your 2-step authentication and your devices is to go into Workday since it requires 2-step authentication for certain tasks.
- One task that requires 2-step is to check your payment elections. To do this, go to http://workday.cornell.edu and log in with your NetID. Once in WorkDay, click on:
- Pay
- Then, Payment Elections
- The pop up notification you receive when in WorkDay when trying to access this page is:
- Once you click OK, you’ll be taken to the 2-step login page. You can then test out your registered devices by selecting the device from the drop-down menu and then selecting an option for that device (such as call me or enter a passcode).
- After you’ve authenticated and you see the notification below, you can simply hit the F5 button on your keyboard to refresh the webpage. You’ll now be able to access your WorkDay protected pages.
- You do NOT need to change anything within WorkDay to test the 2-step. Simply trying to access these pages will bring up the 2-step authentication page. Once you’ve tested, you can go ahead and close out of WorkDay.
What Will Logging Into the CUWebLogin Page Look Like After August 1st or if you choose to opt-in now?
- Here is a how-to video of the 2-step authentication in action as you will all see it starting August 1st: https://www.youtube.com/watch?v=BebNOILcBog&feature=youtu.be
(Please note: there is sound with this video how-to.)
**If you are not able to update or add new devices within the 2-step webpage, please contact CIT for assistance. https://it.cornell.edu/support