ALTA Standard Operating Procedure Duo Mobile Multi-Factor Authentication (MFA) Setup for Employee Staff
- Purpose
This Standard Operating Procedure (SOP) provides IT personnel with a consistent, step-by-step process for enrolling ALTA employee staff in Duo Mobile for multi-factor authentication (MFA). Following this procedure ensures every account is secured correctly, reduces help desk rework, and provides a repeatable experience regardless of which technician performs the setup. 2. Scope
This procedure applies to all IT support personnel responsible for provisioning or resetting Duo Mobile MFA for ALTA employees, including: New hire onboarding and initial device enrollment Re-enrollment after a lost, replaced, or wiped phone Adding a secondary/backup authentication device Troubleshooting push notification or code generation issues Applies To All IT Support Personnel Review Cycle Annually Audience ALTA Employee Staff (New Hires & Existing Users)
- Prerequisites
3.1 IT Personnel Requirements Active administrator access to the Duo Admin Panel Active Directory permissions sufficient to modify group membership (specifically the "Duo MFA" security group) Access to the ALTA identity provider / directory (e.g., Active Directory) to confirm the employee's account status Verified employee identity per ALTA's identity-verification policy before making any MFA changes
3.2 Employee/End-User Requirements A smartphone (iOS or Android) with an active data or Wi-Fi connection Employee's ALTA email address and network/domain credentials Ability to download apps from the Apple App Store or Google Play Store (or a companymanaged app store, if applicable)
- Procedure
5.1 Step 1 — Verify Employee Identity Confirm the employee's full name, and employee ID. Confirm the employee's ALTA network account is active and not disabled or locked. IT Support Verifies employee identity, creates/updates the Duo user profile, sends enrollment link, and confirms successful activation. ALTA Employee Installs the Duo Mobile app, completes enrollment on their personal or company device, and tests login. IT Security (Duo Admin) Maintains Duo policies, monitors enrollment compliance, and handles escalations for locked or compromised accounts. Role Responsibility
5.2 Step 2 — Add User to Duo MFA Group in Active Directory & Create Duo Profile Open Active Directory Users and Computers (ADUC) on the domain controller. Locate the employee's user account using their username or full name. Open the account's Properties, go to the Member Of tab, and click Add. Enter the group name "Duo MFA" (or the exact ALTA security group name used to trigger Duo enrollment/sync), click Check Names to validate, then click OK to add the employee to the group. Click Apply/OK to save the group membership change. Log in to the Duo Admin Panel at admin-xxxxxxx.duosecurity.com using your administrator’s credentials. Navigate to Users. Search for the employee by username or email to confirm the Duo profile was created automatically via AD sync. Confirm the employee's Duo profile shows membership in the Duo MFA group under the Groups section of their profile.
5.3 Step 3 — Send the Enrollment Link On the employee's Duo profile page, locate the Device section. Click Send Enrollment Email or generate a temporary enrollment link if the employee does not yet have a working ALTA mailbox. Instruct the employee to check their ALTA email inbox (and spam/junk folder) for the message titled "Welcome to Duo Security." Note: Enrollment links typically expire after a set number of days per ALTA security policy. If a link expires, generate a new one rather than reusing the old link.
5.4 Step 4 — Employee Installs the Duo Mobile App Have the employees open the App Store (iOS) or Google Play Store (Android) on their smartphone. Search for "Duo Mobile" (published by Cisco Systems, Inc.) and install the app. Once installed, the employee open the app and grant notification permissions when prompted (required for push authentication).
5.5 Step 5 — Complete Enrollment Have the employee open the enrollment email/link on the same device they will use for MFA, or on a computer if scanning a QR code with their phone. Click "Start setup" in the enrollment wizard. Select the device type (e.g., "Mobile phone") and enter the phone number, confirming it is correct. Choose the platform (iPhone/Android) when prompted. In the Duo Mobile app, tap the "+" icon to add a new account, then scan the QR code displayed in the enrollment wizard. Confirm the account appears in the Duo Mobile app as "ALTA" (or the configured organization name). Click Continue to Login in the enrollment wizard to finish setup.
5.6 Step 6 — Test Authentication Direct the employee to log in to an ALTA application that requires Duo MFA (e.g., VPN, email, or SSO portal). Confirm the employee receives a push notification in Duo Mobile and can approve it successfully. As a backup, verify the employee can also generate and enter a passcode from the Duo Mobile app in case push notifications are unavailable. Document the successful enrollment in the IT ticketing system and close the request.
-
Re-Enrollment After Lost or Replaced Device Verify employee identity per Section 5.1 before making changes is mandatory and cannot be skipped for lost-device cases. In the Duo Admin Panel, locate the employee's profile and remove the old/lost device under the Devices section. Follow Section 5.3 through 5.6 to re-enroll the employee's new device. Advise the employee to report the lost device to IT Security if it may have contained cached ALTA credentials.
-
Troubleshooting Common Issues Employees do not receive push notification Confirm the phone has an active internet/data connection. Check that notifications are enabled for Duo Mobile in phone settings. Issue Resolution
-
Security Considerations Never enroll or reset MFA for an employee without completing identity verification (Section 5.1). Do not accept enrollment requests submitted only by email without a verification step, as email accounts can be compromised. Remove Duo devices promptly for terminated employees as part of the offboarding checklist. Report any suspected MFA fraud or social-engineering attempt to IT Security immediately.
-
Revision History Have the employee use the backup passcode option instead. QR code will not scan Ensure camera permissions are granted to Duo Mobile. Increase screen brightness on the enrollment screen and retry. Use the manual key entry option shown below the QR code. Enrollment link expired Generate a new enrollment email/link from the Duo Admin Panel. Confirm the employee's email address on file is correct. Employee has a new phone number Update the phone number under Devices in the Duo Admin Panel. Re-send the enrollment link if the device also needs to be re-registered. Account locked after failed attempts Verify employee identity per Section 5.1. Unlock the account in the Duo Admin Panel under the user profile. Escalate to IT Security if repeated lockouts suggest a compromise attempt. 1.0 July 3, 2026 IT Security Team Initial release