Managing your own second factor devices¶
Duo's self-service device management lets you enroll a new device, update your authentication methods, or remove an old device, without needing help desk support. The device list is shared between SSH and web — there's only one Duo account per person.
An LV member can reach self-management at https://lvk-duo-registration.ligo.org/, or from the status page's Add or change a device button — see MFA for web logins.
KAGRA identities cannot currently self-manage
If you sign in with a KAGRA identity, you cannot use this self-service system yet. Please open a help desk ticket for any device management request.
What you can do¶
- Add a new device (a new phone, or a security key) after authenticating with an existing second factor. If you originally enrolled with macOS Touch ID or Windows Hello, you can use self-management to add the Duo Mobile app as a second, SSH-compatible method — see the SSH vs. web comparison.
- Remove a device after authenticating with an existing second factor.
What this can't do¶
- Add a hardware token such as a YubiKey — see Hardware tokens instead.
- Recover a completely lost second factor. If you've lost access to your phone and have no other second factor, you'll need to open a help desk ticket to reset your account, or have an admin add a device for you.
Step-by-step¶
-
Sign in with your first factor: your LIGO.ORG username and password.
-
Choose Other options.
Using biometrics?
If your device offers a biometric prompt (Touch ID / Windows Hello), cancel out of that window first before you can reach Other options — see this example.
-
Click Manage devices.
-
Verify your identity with an existing second factor.
-
From your device list, choose Add a device (or Edit / I have a new phone on an existing one to update it).
-
Pick how you'd like to verify the new device. Touch ID and Duo Mobile are typically offered here; a hardware Security key option is also listed, but adding a YubiKey still requires the help desk step described on the hardware tokens page, rather than working directly through this picker.