I'm setting up Duo Security on my work PC and want to be prepared for situations where my phone is lost, damaged, or unavailable. Is there an option I should enable during setup that lets me get around the MFA or passkey push? I manage a small business and currently may be the only administrator, so I'm also looking for practical recovery options that won't weaken security.
3 Answers
Use a second authentication method instead of relying only on your phone. A hardware token such as a YubiKey, a Duo-compatible fob, or a passkey on a trusted tablet can provide access if your phone is unavailable. Keep the backup device somewhere secure and test it before you actually need it.
For administrator accounts, keep at least one spare hardware security key in a secure location, such as a locked desk drawer or a safe. A separate break-glass admin account configured for hardware-key authentication is also a good emergency measure. Treat bypass codes as a last resort, not as the normal recovery method.
A permanent MFA bypass generally defeats the point of using Duo. The safer approach is to have a documented recovery process: register a replacement device or have an administrator reset your Duo enrollment and issue a new registration link. If you’re the only administrator, create a second emergency admin account and make sure the recovery credentials are stored securely.

I’m currently the only admin for the business, so setting up a second emergency account sounds like an important first step.