New Security Measure for Password Resets and Duo Assistance

New Security Measure for Password Resets and Duo Assistance

The Office of Information Technology (OIT) has started a new security process at the Help Desk. This measure aims to enhance the protection of our community members’ accounts and ensure the authenticity of requests for password resets and Duo assistance.

Video Confirmation of Identity

If you can’t reset your password or fix Duo issues on your own, the OIT Help Desk has a new way to help. They’ll send you a video link when you contact them. This video chat helps make sure it’s really you asking for help. This keeps your account safe and protects everyone at UCI from security risks.

Use Self-Service Whenever Possible

We encourage everyone to continue using the self-service tools whenever possible. However, if you require assistance and are asked to complete this video verification, please know that it is for your own security and the integrity of our systems.

Questions or Concerns?

For any questions or concerns regarding this new process, please contact the OIT Help Desk.

Thank you for your cooperation in maintaining the security of our digital environment at UCI. Your participation helps keep our entire community safe!

Duo Verified Push Coming to UCPath

Duo Verified Push Coming to UCPath

Beginning Monday, February 24, OIT is implementing Duo “Verified” Push for UCPath. A verified push is a more secure version of the standard Duo Push notification, where instead of simply approving a login attempt on your phone, you are required to enter a unique three-digit code displayed on the login screen to verify your identity, providing an extra layer of protection against potential phishing attacks or accidental approvals.

Faculty and staff will only see this special type of push if Duo suspects suspicious activity and determines an added layer of protection is necessary. Otherwise, Duo will log in using the normal push system the UCI community is used to.

Please continue to deny any push that is not sent as a direct result of attempting to log in to a protected system. If there is suspected suspicious login activity, contact the Help Desk at oit@uci.edu.

ZotDefend Update + Duo Fortification

ZotDefend Update + Duo Fortification

Our ZotDefend campaign, launched fall 2024, continues to protect UCI’s digital world. As a community, you’ve already committed to completing cybersecurity training, which offers a first line of defense against cyber risk. We thank you for your diligent completion of this important yearly compliance.

Now we’re shifting our focus to strengthening the security of our multi-factor authentication system, Duo. In the coming months, additional safeguards will be implemented into Duo to fortify the system to even greater levels of protection. 

  • If you see this, please update immediately with directions from this KB article.
  • If your device is unable to update due to outdated technology or other compliance issues, contact our Help Desk for more information. 

If you have questions regarding ZotDefend or updating your Duo application, please contact our Help Desk at oit@uci.edu.

ZotDefend: UCI App Restrictions

ZotDefend: UCI App Restrictions

UC Irvine continues to update, strengthen and elevate its information security processes to achieve new standards that all UC’s have committed to upholding. As part of the ZotDefend initiative, we must reach 100% compliance for completion of yearly Cybersecurity Awareness Training for all employees. Due to recent efforts, we are pleased to share that we have increased compliance from 86% to 96%. 

Beginning Monday, February 10, 2025, if you are overdue to complete Cybersecurity Awareness Training, you will be restricted from accessing UCI Single Sign-on applications until you have completed the training.

  • UCPath – University of California’s single payroll, benefits, human resources, and academic personnel solution for all UC campuses and medical centers
  • Commute Parking – UCI Transportation and parking services
  • Timesheets – UCI site for submitting employee timesheets
  • Campus Groups – UCI Campus Community site
  • FileNet – enterprise content management solution for securely storing UCI Campus and UCI Medical Center content

  • UCLC 
  • Canvas 
  • ServiceNow
  • VPN with SSO enabled
  • UCI SSO Temporary Access Extension
  • Point and Click (PNC)

Last fall we began to display reminders in your UCI Single Sign-on process when your training is coming due or overdue. Enforcement of this restriction emphasizes the importance of our commitment to ensuring our entire UCI workforce is educated about the most important cybersecurity issues we’re facing as a community.

If you require emergency access to a restricted application and are unable to complete the overdue training immediately, you will have the option to enable a one-time extension. This will grant you continued access for 7 days, after which you will be restricted again if the training is not completed.

To complete the training and ensure you are fully compliant, please log in to the UC Learning Center (UCLC) and search: “UC Cyber Security Awareness Fundamentals

More Information

For more about ZotDefend and to see FAQs, visit the project page. For more information regarding cybersecurity and how you can protect yourself from cyberattacks, visit the Information Security website.

For questions, contact OIT Security at security@uci.edu.

Changes Coming to Duo MFA on 10/19

Changes Coming to Duo MFA on 10/19

Login Changes Coming to Duo Multi-Factor Authentication

On October 19, 2023 the UCI Single Sign On (SSO) process is changing slightly. You will no longer need to select “send a push” after entering your UCInetID and password. It will automatically send a push to the last used device. The update should be seamless for most UCI faculty, staff and students, with no interruptions to services.

Below you will find the new four step process for logging in:

Step 1: Login to an SSO-enabled service (such as ZotPortal or Canvas) as you normally would with your UCInetID and password. 

Step 2: The page that states the Duo push has been sent to your phone will look a little different. 

Step 3: Open the Duo Mobile app and tap Approve. You will be automatically taken to the website you were trying to visit on your computer (ZotPortal, Canvas, etc). In the event that you don’t receive the push notification, you can select “Other options” where you can enter a 6-digit code to login (this code can be found in your Duo Mobile app).

Step 4: The page will reload asking you if this is your device. If you are using your own device, click on “Yes, this is my device” to have it remember your Duo authentication for the next 24 hours or if you are using a public computer select “No, other people use this device”, and you’re done!

Additional details can be found in this Knowledge Base article. If you need assistance with this process after the go-live on 10/19, please reach out to the Help Desk by emailing oit@uci.edu or via phone at 949-824-2222