# Setting Up Duo MFA (IT Staff and Select Roles)

## Overview

**Duo MFA is used only by IT staff and a small number of select roles** — primarily for systems that integrate with Duo, such as NetSuite. If you are a general PBR staff member, please use **Microsoft Authenticator** instead — see [Setting Up Microsoft Authenticator](https://bookstack.pbr.org.au/books/multi-factor-authentication-mfa/page/setting-up-microsoft-authenticator-standard-mfa).

If you are unsure which MFA method applies to your role, contact IT Helpdesk.

---

## Setup Steps

1. Contact IT Helpdesk at <helpdesk@pbr.org.au> to request a Duo enrolment email if you have not already received one
2. Download the **Duo Mobile** app on your phone from the App Store (iPhone) or Google Play (Android)
3. Open the enrolment email on a computer or tablet and click the enrolment link
4. Follow the on-screen prompts to link your phone to your Duo account
5. When prompted, scan the QR code with the Duo Mobile app
6. Complete the setup — you will receive a test push notification to confirm it is working

---

## Using Duo

When signing into a Duo-protected system (such as NetSuite), you will be prompted to approve a push notification on the Duo Mobile app, or enter a one-time passcode generated by the app.

---

## Troubleshooting

<table id="bkmrk-issuesolution-no-pus"><tr><th>Issue</th><th>Solution</th></tr><tr><td>No push notification</td><td>Open Duo Mobile and check for a pending request, or use the passcode option instead</td></tr><tr><td>Lost or replaced phone</td><td>Contact IT Helpdesk at <helpdesk@pbr.org.au> to reset your Duo enrolment</td></tr><tr><td>Cannot log into NetSuite via Duo SSO</td><td>See [Cannot log into Duo Single Sign-On](https://bookstack.pbr.org.au/books/netsuite/page/cannot-log-into-duo-single-sign-on)</td></tr></table>