A knowledge base article about How to Use CalNet 2-Step provided by the UC Berkeley IT Service Hub - Knowledge Portal
Using a Duo Push to 2-Step on your Smartphone or Tablet
A "push" is a notification sent to your device
- Login to your CalNet account using your CalNet ID and passphrase.
- This is your first-step verification
- A screen will appear notifying you that a Duo Push has been sent to your registered device. If Duo Push is not the default choice, click on Other Options and select Duo Push from the list of your registered devices.
- Open the Duo Mobile app to view the notification.
- Approve the login request to complete your login, and you're done!
Using a Verified Duo Push to 2-Step
Occasionally, you may see something called a Verified Duo Push screen–where you'll be asked to enter an additional security code in the Duo Mobile App–instead of tapping the green checkmark.
- Login to your CalNet account using your CalNet ID and passphrase.
- This is your first-step verification
- A four-digit code will appear on the login screen
- Open the Duo Mobile App on your mobile device and enter the 4-digit verification code from the login screen
- Click Verify. Once the verification is complete, an “Approved” message will display, and you will be logged in
This step-up authentication occurs for high-risk logins. Examples of high-risk scenarios include:
- Accessing from a new device or IP address
- Traveling to a new location
- Unusual activity, such as multiple failed access attempts
Getting Passcodes from Duo Mobile
You can use a passcode from the Duo App to complete the 2-Step even without a WiFi or cellular connection! Note: Passcodes are single-use; you must enter a new one each time you verify. Duo deactivates any old, unused passcodes once you request new ones.
- View Passcode. On your phone, go to Duo Mobile. Tap the "CalNet - UC Berkeley" entry to view a passcode.
- Log in to your CalNet account with your usual credentials. This is your first-step verification.
- When prompted to 2-Step, select Duo Mobile Passcode (you may need to select Other options if it does not appear by default)
- View the passcode and enter it into the 2-Step prompt.
Getting Passcodes from CalNet Account Manager
-
Log in to mycalnet.berkeley.edu using your CalNet ID and passphrase. Select “Manage 2-Step Verification” on the left-hand menu.
-
Complete a 2-Step authentication (this is required to manage your 2-Step account even if you already completed a 2-Step to log in to mycalnet.berkeley.edu).
-
Click on “Renew(or Generate) Bypass Codes.” This will void any existing set of codes and generate a new set of 10 codes. Each passcode can only be used one time.
- Be sure to print the codes out and keep them under your control. We recommend putting half in your wallet and half in a safe location you can access when you need a bypass code, such as when you are traveling.
Logging in with a Passcode
To use bypass codes to authenticate, follow these steps:
- Log in to your CalNet account with your usual credentials (ex: https://bpr.calnet.berkeley.edu/account-manager/login/auth).
- Once the Duo screen is prompted, showing your default device choice, select "Other Options" located at the bottom.
- If you are automatically logged in and the 2-Step prompt is bypassed, try either clearing cache/cookies or using an incognito browser.
- Then, select "Bypass code" located toward the bottom of the list of verification devices.
- Enter your code and click Verify. You're done! For information on receiving bypass codes, please keep reading!