Duo for Password Reset
Starting April 4, 2022, at 5 p.m., you’ll be able to use Duo to reset your forgotten password at onyen.unc.edu 24 hours a day, 7 days a week. Duo replaces the challenge and response questions, since many of the challenge questions have discoverable answers they are no longer considered secure. This change will simplify the password reset process for anyone with Duo and be a step toward proactively implementing incoming security recommendations from the National Institute of Standards and Technology (NIST). Changes to the Password Reset process are one part of a multi-faceted effort to strengthen authentication and identity security.
Who this affects
- Anyone with an Onyen who forgets their Onyen password and needs to reset their password to access University resources. This includes everyone from retirees to newly admitted students.
- If you remember your most recent Onyen password or can retrieve it from your device or Web browser, this won’t affect you, because you can change your password without a reset.
What’s changing at 5 p.m. on April 4?
Anyone who forgets their Onyen password and doesn’t have Duo set up will need to contact the ITS Service Desk for assistance resetting their Onyen password at 919-962-HELP between 7 a.m. – 7 p.m.
Anyone who forgets their Onyen password and does have Duo set up:
- Can reset their password using Duo to verify their identity 24 hours a day 7 days a week through onyen.unc.edu.
- Won’t use challenge-response questions as part of the Onyen password reset process.
- Can use their office phone to authenticate only if they have no other method set up for Duo authentication. If they have two methods set up, they will need to use the other (non-office phone) option.
What we’re suggesting you do
- Follow these steps to set up Duo if you haven’t already.
- Register more than one device in Duo so that if you break, lose, or trade in your primary device, you will still be able to authenticate with Duo. If you have both an office phone and a second device set up, you can’t use your office phone for password resets. Follow these steps to add a new device to your Duo account.
- Set up LastPass so that you can always have a place to retrieve your password from. All current UNC students, faculty, and staff have access to the Premium version of LastPass. Refer to Password Manager (LastPass) to sign up for LastPass and read about related best practices. Continue learning by checking out the LastPass FAQ.