Question
How does Yes, this is my device work in Duo?
Cause
Due to increased security measures by Duo, there are now Yes, this is my device and No, other people use this device browser cookies that need to be considered.
Scenarios
There are four possible scenarios with the Yes, this is my device feature. Any of these can be reset with a deletion of your browser cache:
Scenario 1: Establish trust?
This is what users see initially. It’s what they see if they delete all their browser cookies. It’s what they’ll see if they switch to another web browser they previously were not using for authentications.
Your experience:
- Attempting to log on to a protected service will redirect you to the single sign-on screen. Provide your Duck ID and password.
- You'll be redirected to Duo.
- The Duo screen will appear asking for a second factor and you provide the second-factor response.
- Another Duo screen will appear asking if this is a trusted device. Upon selecting a response, you will be redirected to the protected service.
- If you click Yes, this is my device, then a seven-day trusted cookie is created. Proceed to Scenario 2 for next steps.
- If you click No, other people use this device then a 14-day not trusted cookie is created. Proceed to Scenario 4 for next steps.
Scenario 2: The computer or device is trusted
This is what you see when you have an active Yes, this is my device cookie in place on the browser being used. This will be experienced until the seven-day trusted cookie expires.
Your experience:
- Attempting to log on to a protected service will redirect you to the single sign-on screen. Provide your Duck ID and password.
- You'll be redirected to Duo.
- The Duo screen appears on the Duo server for a brief second to validate the trusted cookie. You will be redirected to the protected service.
To see what happens after seven days has passed, proceed to Scenario 3.
Scenario 3: Renew trust?
This is what users will experience after their seven-day cookie has expired. By default, the checkbox for Yes, this is my device is already checked, but they can uncheck it.
Your experience:
- Attempting to log on to a protected service will redirect you to the single sign-on screen. Provide your Duck ID and password.
- You'll be redirected to Duo.
- The Duo screen will appear asking for a second factor showing the checked Remember Me checkbox, and you provide the second-factor response.
- If you uncheck the Remember Me checkbox, proceed to Scenario 4.
- Another Duo screen will appear asking if this is a trusted device.
- If you click Yes, this is my device, then a seven-day trusted cookie is created. Proceed to Scenario 2 for next steps.
- If you click No, other people use this device then a 14-day not trusted cookie is created. Proceed to Scenario 4 for next steps.
Scenario 4: The computer or device is not trusted
This is what you would experience if you either:
- Deselected the Yes, this is my device checkbox in Scenario 3, or
- If you selected No, other people use this device in Scenario 1.
This will be your experience for 14 days after taking the action to not trust the device. You can go back to Scenario 1 if you delete your browser’s cookies.
Your experience:
- Attempting to log on to a protected service will redirect you to the single sign-on screen. Provide your Duck ID and password.
- You'll be redirected to Duo.
- The Duo screen will appear asking for a second factor without the Remember Me checkbox and you provide the second-factor response.
- Upon verification, you will be redirected to the protected service.