The UW has in place requirements to use 2FA on every sign, referred to as "2FA on the web". For the majority of users, they are automatically opted in as documented on Opt-in. In cases with a clear hardships for an individual, this opted in status can be removed. It is important to note that this type of exception only removes the 2FA requirement on every sign in, but does not address applications that require 2FA on sign in (and as a result will still request 2FA). This is not an option for those who wish to not be opted in, instead a user must fall into one of the following categories or share with UW-IT an undue hardship. Please email help@uw.edu if you have questions or believe an opt-out exception is needed.
Accessibility concerns
The UW uses Duo as it's 2FA vendor, which offers many features to ensure 2FA is as accessible as possible. For many users facing an accessibility challenge, there may be offerings for 2FA that will allow for the added security while reducing the added friction on login. UW-IT is happy to assist in determining what 2FA method will work best for you, and Duo's accessibility team has documented their support at
https://duo.com/docs/accessibility. If an accessibility concern cannot be addressed by the current 2FA offerings, users may qualify for an opt-out exception.
Travel concerns
For those travelling outside of the united states 2FA may present a source of friction for logins. In most cases, preparing for your trip can be as simple as ensuring you have a device with you that has the Duo app installed successfully (as it can provide 2FA authentication even when you are out of cell service off wifi). More information can be found on the IT Connect page offering 2FA resources for
travel. For these cases, opt-out exceptions are not granted.
However, 2FA is not available in OFAC restricted regions as noted on
Duo and UW's 2FA resources for
travel. If your travel plans will take you to such a region and will need to log in to UW resources, please reach out to help@uw.edu before your travel for a potential out-out exception.
Test Users and Automation
2FA can present a barrier to "not real" UW NetIDs like those used in testing or automation. We strongly suggest wherever possible utilizing a shared UW NetID in place of a personal UW NetID as shared UW NetIDs are not required to do 2FA on a standard login. This also has the added benefit of allowing your test cases and automation "live longer" as they can be used by another personal UW NetID in case you pass the responsibility on to someone else.
However, some systems require 2FA from all logins including a shared UW NetID. Other times a test account must be a personal UW NetID and needs to appear as a real user (including the need to do 2FA). In those cases, bypassing 2FA requirements or enabling bypass options can be reviewed and if applicable offered. Please reach out ot help@uw.edu to start a conversation if you need this exception.
In some cases specific devices can have external factors that make 2FA a block for use of the device. Users of the device should not face hardship outside of the specific device, and the device is critical to UW business. If this is the case, a network based exception may be appropriate.
Network based exceptions allows for specific network traffic to bypass the 2FA step for any user on that device, while still requiring that those users do 2FA generally on all logins. This is especially beneficial in highly controlled environments such as clean rooms or sensitive laboratories.
Because of the nature of a network based exception removing the 2FA requirement for any and all users who access this device, network based exceptions are only issued in extremely specific circumstances. In order to meet the policy requirements for this exception, a use case needs to be shared with UW-IT via help@uw.edu that captures:
- A strong, documented business justification that has already explored other alternative solutions
- A secure, well understood environment in which the device is to be located and accessed
- A secure, well managed device that is regularly maintained and audited
- Agreement to a high standard of notification and involvement with UW-IT to issue and maintain this exception