Using a Personal Device for Multi-Factor Authentication (MFA)

Overview

The university requires multi-factor authentication (MFA) to access sensitive University systems and data. This includes information classified as High Risk (Red) or Moderate Risk (Amber), such as student records, HR files, financial information, and other regulated data.

Employees may choose one of the following authentication methods:

Using a personal device is optional. If you choose this option, you must meet the security requirements outlined below.

Your Responsibilities When Using a Personal Device

If you use a personal device for MFA, you are responsible for maintaining its security and keeping it up to date.

Your device must:

  • Have at least a four-digit PIN or passcode enabled
  • Automatically lock after a period of inactivity
  • Have encryption enabled to protect data stored on the device
  • Be supported by the manufacturer and capable of receiving updates

Security updates must be installed within 15 days of release. If the device has not been used for some time, it must be fully updated before it is used again for authentication.

You are accountable for all activity performed using your university credentials.

If your device is lost, stolen, or misplaced, you must immediately:

Checking your compliance

Select the title of each accordion panel in order to see its contents.

Additional questions and resources

  • For questions, contact the Information Security Office at isrc@uoregon.edu.
  • For additional information regarding the university’s authentication standard please review, Information Security office: Authentication Standard
  • To report a lost device or security concern, contact:
    • infosec@uoregon.edu, or
    • Cyber Security Operations Center: 541-346-5837