Body
Multi-factor authentication (MFA) through Duo is a critical layer of security protecting Dartmouth accounts and the data they contain. ITC is unable to exempt individual accounts from Duo MFA requirements. This article explains why bypasses are not permitted and outlines the recommended alternatives for common access scenarios.
Why Duo MFA Bypasses Are Not Permitted
Duo MFA is a required security control for all Dartmouth accounts. Bypassing MFA removes a critical layer of protection and significantly increases the risk of unauthorized access, even when the intent is simply to make mailbox access more convenient. ITC cannot make exceptions to this requirement, regardless of the use case.
Recommended Alternatives
Depending on your situation, one of the following approaches is likely to meet your needs while keeping your account secure.
Option 1: Use Only as Shared Mailbox
If multiple people need access to the same mailbox, the preferred solution is to provide delegate access to the shared mailbox. Mailboxes with delegated rights do not require a separate login or Duo authentication -- team members can access them directly through their own authenticated accounts. This is the recommended approach in most cases where a full user account is being used solely as a mailbox.
Option 2: Assign a Authentication Device to a Duo Account
Ideally each account belongs to one individual to help ensure a secure account.
Please keep the following in mind if this option is pursued:
- Each individual authenticating should have their own registered device.
- The account owner remains responsible for all activity on the account.
- Converting to a delegate mailbox should still be considered as the longer-term solution.
For instructions on adding a device to Duo, see: Add a Duo Device.
External Resources
See Related Articles to the right for more information.