Skip to main content

New BuckeyePass Security Check for Unusual Sign-In Activity

A person holding a tablet with a screen showing a digital lock labeled 'privacy'

Ohio State is updating BuckeyePass multi-factor authentication (MFA) service to provide additional protection when unusual sign-in activity is detected. The change is scheduled for Wednesday, Sept. 23 and is designed to help reduce the risk of unauthorized access to your university account and data.

Most people will continue to use Duo as they do today and will not notice any difference during routine sign-ins. However, if Duo detects unusual or potentially risky sign-in activity, you may be asked to complete an additional verification step before signing in. The additional step, known as Verified Push, will require you to enter a code displayed on your sign-in screen into the Duo Mobile app to confirm that the login attempt is yours.

Examples of activity that may trigger the additional verification include:

  • Signing in from a location, network, or device that differs from your normal sign-in activity. 
  • Receiving multiple Duo push notifications that you do not approve or respond to, which could indicate that someone else is attempting to access your account.
     

What if I do not have Duo Mobile?

BuckeyePass, powered by Duo Mobile is required to use Verified Push.  If you do not currently use Duo Mobile, follow the instructions to add it to your account. 

As an alternative, you can use a passkey on supported Windows, Apple, or Android devices.  Passkeys provide a secure and convenient sign-in experience using features such as Windows Hello, Android Biometrics, Touch or Face ID.

If Duo Mobile or passkeys are not an option, YubiKey are available for purchase through Tech Hub or online.  
 

Need Help?

The IT Service Desk is available to support you 24/7.Request IT support onlineor call the Service Desk at 614-688-4357 (HELP).