Information Technology Services IT Security Office
Note: Two-factor authentication (2FA) is mandatory for Mason employees
to access the Cisco AnyConnect VPN


Enrolling in 2FA

Before you use 2FA when you log into the Cisco AnyConnect VPN client, you must first create your 2FA account and enroll at least one device through the Duo Enrollment process. To complete your enrollment, do following:

square Verify and update your phone numbers on file in Patriot Web. You will need to receive a phone call at one phone numbers listed in Patriot Web during the enrollment process. Please make sure the phone number of your device is listed.
square Download and Install the Duo Mobile app by Duo Security on your smartphone from your device's App Store. The app is required to confirm your identity when connecting to Cisco AnyConnect VPN.
Note: When configuring the app, Enabling Notifications improves your ability to authenticate using Duo Mobile.
square Enroll your initial device. See the Enrollment Guide for more instructions.
square Optional: Enroll a backup device. See Management Options for more instructions.
Note: ITS recommends having a backup device incase your initial is unavailable for any reason.

Using 2FA with Cisco AnyConnect VPN

After completing enrollment, verify that you can connect to the VPN using the Cisco AnyConnect VPN Client.

square Download and Install the Cisco AnyConnect client if you do not already have it on your computer. Installation instructions are found on the VPN Information page.
square Determine your VPN Group for when you login to Cisco AnyConnect VPN. When you connect to Cisco AnyConnect VPN you need to specify a VPN Group. Each VPN Group is setup for specific access.
square Login to the Cisco AnyConnect VPN Client. For instructions see Using 2FA with VPN.

You may now use the Cisco AnyConnect VPN with the improved security and reliability of 2FA. Each time you connect to the VPN, you will be required to use 2FA to complete the login process.