Skip to content
Current/ Help Center

Duo sign-in: approve with Duo, email code as backup

7 min read · Updated Sep 26, 2026

If your company already uses Duo, your workspace can use it for the second step when people sign in to Current with a password. After the password, they see Approve with Duo Push and Enter a Duo passcode, and Use an email code instead is always there. Current talks to your own Duo account through a Duo Auth API application you create, so Duo's own rules about who may use it apply.

Who is offered Duo

Duo replaces the emailed code, and only for the people who would get that code today. Everyone else keeps the method they already have:

  • +Staff who sign in with a password and have no authenticator app or passkey are offered Duo, as long as their email domain is on the Applies to list (or the list is empty).
  • +Anyone with an authenticator app or a passkey keeps using it. A workspace that requires an app or passkey doesn't offer Duo at all.
  • +People who sign in through single sign-on never see a second step from Current, so they never see Duo either.
  • +Partner Viewers are never offered Duo. They keep the emailed code.
  • +Super admins are never offered Duo, in any workspace. They keep the method they already have.

Linking your Duo account the first time

Current asks Duo about a name made from the person's email address, so the first time someone approves with Duo, Current also emails them a code. They approve in Duo Mobile (or type a Duo passcode), the screen says one more step is needed, and they enter the emailed code. That links their Duo account to their Current account, and from the next sign-in Duo alone is enough. The extra code proves the Duo account really belongs to the person who owns the mailbox, so a Duo user with the wrong name can't be used to sign in as someone else.

  • +Each person links once, and only from the same browser session that just approved in Duo, within ten minutes.
  • +Saving new Duo keys or a new API hostname, changing the Duo username setting, or removing Duo sign-in un-links everyone. Each person links again with one emailed code at their next Duo sign-in.
  • +A Reset second factor on Users & roles, a password reset, or a Duo request the person reported as fraud un-links that one person, so they link Duo again with an emailed code at their next Duo sign-in.
  • +The Duo row in the Sign-in panel shows how many people have linked their Duo account with the keys saved now.
  • +If linking doesn't go through, the sign-in still finishes with the emailed code, and the person is simply asked to link again next time.

Set it up

  1. 1
    Create an Auth API application in Duo
    In the Duo Admin Panel, go to Applications, find Auth API (it carries the 2FA label) and click Add. Duo shows its integration key, secret key and API hostname. Current needs all three, and keys from any other kind of Duo application are refused.
  2. 2
    Let your people use the application
    Duo doesn't let existing users into a new application until you grant access. Give the application to the groups or users who sign in to Current, the same way you would for any Duo-protected app.
  3. 3
    Paste the details into Current
    In Current, open Workspace, then Users & roles, then the Sign-in panel, and click Set up Duo on the Duo row. Paste the API hostname (it looks like api-1a2b3c4d.duosecurity.com), the integration key and the secret key, choose the Duo username setting, and click Save. Only a Tenant Admin can do this, and only from a session that already passed its own second step.
  4. 4
    Test, then turn it on
    Click Test connection. When Duo accepts the keys, click Check my Duo account to see whether Duo knows you and can send you a push. Then switch on Turn on Duo sign-in. The switch stays off until a test passes with the keys you saved, and saving new keys turns Duo sign-in off again until the next passing test.

The Duo username setting

Current tells Duo who is signing in by name. Pick whichever matches the usernames in your Duo account. Full email address sends the person's sign-in address, in lower case. The part before the @ sends only that part (alex for alex@acme.com), and it needs exactly one domain on the Applies to list, so two people on different domains can never share one Duo account. Check my Duo account shows the exact name Current sends for you.

The emailed code stays available

Duo is a second option, not a lock. Use an email code instead is on every Duo screen, and when Duo can't be used Current sends the code on its own and says why in one line above the code box: Duo doesn't have an account for that username, Duo isn't answering, or Duo let the sign-in through without asking. Wrong passcodes and declined pushes count against the same limit as wrong email codes: five, then fifteen minutes before anyone can try again.

Note
Why a Duo user in Bypass status gets an email code
When Duo lets someone through without asking them anything (a user in Bypass status, a policy set to skip two-factor, or a new-user policy that admits people Duo doesn't know), nobody proved anything, so Current doesn't count it as a second step and emails a code instead. Duo bypass codes are different: they are passcodes a Duo admin gave that person, and Current accepts them in Enter a Duo passcode.

Pushes, passcodes and fraud reports

  • +Current never sends a push on its own. The person clicks Approve with Duo Push, and one request goes to the first phone Duo has for them.
  • +If your Duo policy asks for Verified Duo Push, the sign-in screen shows a number to type into Duo Mobile before approving.
  • +One request can be open at a time, a new one needs 30 seconds after the last, and after four in fifteen minutes the screen offers the emailed code instead. A request started in another browser has to finish or time out before a new one can be sent.
  • +A passcode is 6 to 12 digits: one from Duo Mobile, a hardware token, or a bypass code from your Duo admin.
  • +If someone taps to report a request as fraud, their sign-in is paused for 15 minutes, every Tenant Admin in the workspace gets a notification, and the report is written to the audit log. Someone may know that person's password, so ask them to change it.

Trusted devices and the audit log

A browser that passed Duo is trusted exactly like one that passed the emailed code: for the workspace's trusted device window (30, 14 or 7 days), and Reset second factor on Users & roles clears it. Duo's own Remembered Devices setting has no effect on Current. Every approval, fraud report and settings change is written to the audit log, and settings changes also notify every Tenant Admin.

When something goes wrong

What you seeWhat it means
Test connection says Duo doesn't recognise the integration keyThe integration key is mistyped, or it belongs to an application that was deleted. Copy it again from the Auth API application page.
The secret key doesn't match this integration keyPaste the secret key again. It must come from the same application as the integration key.
These keys belong to a different kind of Duo applicationThe keys come from something other than an Auth API application. Add an Auth API application (the one with the 2FA label) and use its keys.
Duo says our clock and theirs disagreeDuo refused the request's timestamp. Try again in a minute.
The Duo row says Needs attentionDuo refused the saved keys when someone tried to sign in, so people are getting emailed codes. Open Manage, run Test connection, and replace the keys if it fails.
Someone is told Duo doesn't have an account for themThe name Current sends doesn't match a Duo user. Check the Duo username setting, or add that person in Duo and give them the application.
Someone approves with Duo and is still asked for an emailed codeTheir Duo account isn't linked yet, or new keys un-linked everyone. Entering the emailed code links it, and Duo alone is enough from then on.

To stop using Duo, switch Turn on Duo sign-in off, or click Remove Duo sign-in to delete the saved keys. People get the emailed code at their next sign-in either way. See "Two-factor authentication: the email sign-in code" for the rest of how the second step works.

Was this helpful?