Who this is for / when to use it
You got a new phone, a new number, or reset your phone, and now the Cornell Duo / Two-Step Login prompt won't work — the approval still goes to your old device.
Duo or Secure Connect? If your prompt shows a code plus an "Approve" button, that's Duo — you're in the right place. If it shows Beyond Identity or Windows Hello / fingerprint, that's Secure Connect — see it.cornell.edu/secure-connect. Note that even Secure Connect users still need Duo for some services (such as the CU VPN / Cisco AnyConnect), so you can still end up here.
Before you start
Two-Step Login is a Cornell-wide service, so the current step-by-step lives on the IT@Cornell site. Have your new phone and your NetID ready before you begin.
Fix it yourself (fastest)
Locked out completely?
If your only registered device is the old or lost one, you can't self-serve — and this is one thing JCB IT can't fix for you. Two-Step Login is a central Cornell service, and only the Cornell IT Service Desk can issue a temporary bypass code or reset your devices (after photo-ID identity verification). Contact them directly:
Common problems
For a Duo lockout / reset, go straight to the Cornell IT Service Desk — that's the only team that can reset Two-Step Login. For anything else (which article applies, VPN prompts, Duo vs. Secure Connect), JCB IT can help point you the right way.
Still need help? Contact the Cornell SC Johnson College of Business Helpdesk at itrequests@business.cornell.edu.
[authored via Jane by rtm25 on 2026-08-18 17:14 UTC]