360Score.me Sign-in Security with Duo Universal Prompt
In a time where online security is of the utmost importance, 360Score.me recognizes the sensitivity of peer review data and how crucial it is to protect that data. This article will walk your organization through activating DUO 2FA within 360Score.me.
Important Notice: 360Score.me Duo Universal Web SDK Updated 2/2/2026 to Duo_universal_csharp 1.3.0
Per Duo’s guidance, February 2, 2026 is considered a soft deadline. The underlying certificate changes are not expected to be strictly enforced until the March 31, 2026 hard cutover, which allows for additional testing and validation.
After upgrading the 360Score.me Duo Web SDK version during the scheduled maintenance window, it is critical to regenerate your Duo Web SDK credentials to maintain secure and uninterrupted authentication.
- Log in to the Duo Admin Panel
Go to https://admin.duosecurity.com and authenticate with your administrator credentials. - Access the Application Configuration
Navigate to Applications → Protect an Application
Locate the existing 360Score.me Duo Access application (Web SDK / OIDC). - Regenerate Credentials
Within the application settings:- Find the Client ID and Client Secret fields
- Click the option to regenerate or reset these credentials
- Confirm any prompts
- Verify API Hostname
Confirm the API Hostname remains correct or update it if necessary based on Duo's latest configuration. - Update 360Score.me Configuration
Login to 360Score.me as an Admin User:
360Score.me → Company Profile → Expand your Company Name → Setup MFA - Replace the old Client ID, Client Secret, and API Hostname in your 360Score.me admin configuration with the newly generated values. Save to deploy the updated configuration. - Test Authentication Flow
Log out and log back into 360Score.me.
Confirm the Duo Universal Prompt appears and authentication completes successfully.
Part 1: End User Guide — Logging In with Duo 2FA
What Duo 2FA Is
Duo Two Factor Authentication adds an extra layer of security to your 360Score.me account.
After entering your email and password, you’ll verify your identity using a second method such as a Duo Push, passcode, or security key.
How to Log In
- Enter Your Credentials
On the 360Score.me login page:- Enter your email address
- Enter your password
- Select Remember Me if desired
- Click Login
- If needed, select Forgot Password? to reset your credentials
- Complete Duo Authentication
After submitting your credentials, the Duo Universal Prompt will appear.
You may authenticate using:- Duo Push (recommended)
- Passcode from the Duo Mobile app
- Phone call
- SMS code
- Security key or biometric method (if enabled)
Part 2: Administrator Guide — Configuring Duo Universal Prompt for 360Score.me
This section explains how to configure Duo Universal Prompt using Duo’s Web SDK (OIDC) and how to create the application named 360Score.me Duo Access.
Step 1: Log In to the Duo Admin Panel
Go to the Duo Admin Panel
Navigate to Applications → Add an Application
Step 2: Create the Application
Search for Web SDK or OIDC Web SDK (depending on your Duo edition)
Click Protect to create a new applicationSet the Application Name to: 360Score.me Duo Access
Under Details, you will see 3 items – Integration Key, Secret Key and API Hostname. Please make note of these as you will
need these 3 items later in the process to activate DUO within 360Score.me.
Step 3: Enable Duo Universal Prompt
Inside the application settings:
- Locate the Universal Prompt section
- Set Enable Universal Prompt to ON
- Set User access to Enable for all users
- Under Settings > Username normalization --> Select "Simple
- Save your changes
Step 4: Configure OIDC Settings
360Score.me uses Duo’s OIDC-based Web SDK. You will need the following values from Duo:
- Client ID
- Client Secret
- API Hostname
- Copy the Client ID
- Copy the Client Secret
- Copy the API Hostname
- Save the application
Step 5: Configure Duo Web SDK in 360Score.me
Login to 360Score.me as an Admin User:
360Score.me→ Company Profile → Expand your Company Name → Setup MFA- Insert the Client ID
- Insert the Client Secret
- Insert the API Hostname
- Confirm that the 360Score.me Duo Access application is selected
- Click Apply Duo 2FA Settings to deploy your changes
- Activate Duo 2FA for Employees via Setup MFA – Employee Link
Once configured, 360Score.me will automatically redirect users to the Duo Universal Prompt during login.
Step 6: Test the Integration
- Log out of 360Score.me
- Log back in using a test account
- Confirm that the Duo Universal Prompt appears
- Complete authentication
- Verify that you are redirected back to 360Score.me successfully
TroubleshootingCommon Duo Errors
- “Client ID or Secret invalid”
Re-copy values from Duo and confirm no whitespace or formatting issues. - Universal Prompt not appearing
Check that the Universal Prompt toggle is enabled in Duo.
