How to Use CalNet 2-Step

A knowledge base article about How to Use CalNet 2-Step provided by the UC Berkeley IT Service Hub - Knowledge Portal

Using a Duo Push to 2-Step on your Smartphone or Tablet 

A "push" is a notification sent to your device

Using a Verified Duo Push to 2-Step

Occasionally, you may see something called a Verified Duo Push screen–where you'll be asked to enter an additional security code in the Duo Mobile App–instead of tapping the green checkmark. 

This step-up authentication occurs for high-risk logins. Examples of high-risk scenarios include:

Getting Passcodes from Duo Mobile

You can use a passcode from the Duo App to complete the 2-Step even without a WiFi or cellular connection! Note: Passcodes are single-use; you must enter a new one each time you verify. Duo deactivates any old, unused passcodes once you request new ones. 

Getting Passcodes from CalNet Account Manager

  1. Log in to mycalnet.berkeley.edu using your CalNet ID and passphrase. Select “Manage 2-Step Verification” on the left-hand menu.

  2. Complete a 2-Step authentication (this is required to manage your 2-Step account even if you already completed a 2-Step to log in to mycalnet.berkeley.edu).

  3. Click on “Renew(or Generate) Bypass Codes.” This will void any existing set of codes and generate a new set of 10 codes. Each passcode can only be used one time. 

  4. Be sure to print the codes out and keep them under your control. We recommend putting half in your wallet and half in a safe location you can access when you need a bypass code, such as when you are traveling.

Logging in with a Passcode

To use bypass codes to authenticate, follow these steps:

  1. Log in to your CalNet account with your usual credentials (ex: https://bpr.calnet.berkeley.edu/account-manager/login/auth).
  2. Once the Duo screen is prompted, showing your default device choice, select "Other Options" located at the bottom. 
  3. If you are automatically logged in and the 2-Step prompt is bypassed, try either clearing cache/cookies or using an incognito browser.
  4. Then, select "Bypass code" located toward the bottom of the list of verification devices.
  5. Enter your code and click Verify. You're done! For information on receiving bypass codes, please keep reading!