Home → CRL IT Knowledge Base → CRL Account Management → First-Time Sign-In & Two-Factor Setup
1.1. First-Time Sign-In & Two-Factor Setup
Last updated: Fri Jul 2026 01:29 PM (EDT)
First-Time Sign-In & Two-Factor Setup
This guide walks you through signing in to your CRL account for the first time, setting up two-factor authentication (2FA), and registering the recovery options that let you reset your own password later. Work through the steps in order — it takes about 10–15 minutes.
Before you begin: keep your cell phone within reach (and a QR-code scanner app, if your camera doesn’t scan codes on its own). If IT issued you a THALES hardware token instead of using your phone for 2FA, have the token with you.
Step 1 — Sign in
Open Microsoft Edge.
Browse to https://portal.office365.us/. This is CRL’s GCC High sign-in portal. Don’t use office.com — CRL accounts live in the GCC High cloud and won’t authenticate there.
Click Sign in.
Enter your CRL email address and click Next.
Enter your password and continue. If you don’t have an initial password yet, ask the IT department or your team lead.
Step 2 — Approve your sign-in (2FA)
Two-factor authentication confirms it’s really you signing in. Use Option A to set up the DUO app on your phone, or Option B if IT issued you a THALES hardware token.
Option A — DUO mobile app
Begin DUO enrollment.
Choose Mobile Phone as your contact method and click Continue.
Type your phone number, tick the confirmation box, and click Continue.
Select your phone type.
Install DUO Mobile from the App Store (iPhone) or Play Store (Android).
In the DUO app, tap Add, then Use QR Code, and scan the code on your screen with your phone’s camera.
A green check mark confirms the scan worked.
Leave Ask me to choose an authentication method selected and click Continue.
Enrollment is complete.
Test it: click Send Me a Push. DUO displays a Request ID (for example, 9ZQV).
The push notification on your phone shows the matching Request ID.
Tap Approve to finish.
Detailed DUO setup guides: Android | iPhone / iOS
Option B — THALES hardware token
Click Enter a Passcode, type the code shown on your token, and click Log In.
Your token is now verified.
That completes 2FA. To also register your phone, click Add another Device and follow Option A — otherwise, skip ahead to Step 3.
Step 3 — Accept the CRL Terms of Use
Read the CRL Technologies Terms of Use and accept them to continue.
Step 4 — Register your account recovery methods
This step is separate from 2FA. DUO (or your token) approves your day-to-day sign-ins; the recovery methods below are what let you reset your own password if you’re ever locked out. You’ll see the Keep Your Account Secure prompts:
Register two recovery methods — a phone and an email.
Authentication phone — enter the number you want to use, then choose Text Me or Call Me.
Don’t choose Text Me for a landline — it can’t receive text messages. Use Call Me instead.
Authentication email — enter a personal, non-CRL email address you can open right away. Microsoft emails you a link to confirm it.
Never use your CRL email address here. If you’re locked out of your CRL account, you won’t be able to open it to verify the request — which defeats the purpose of a recovery method.
Click Next.
Step 5 — Finish signing in
Click Next to acknowledge, then sign in again.
Complete the 2FA prompt: click Send Me a Push and approve it on your phone, or click Enter a Passcode if you’re using a token.
When asked whether you’d like to stay signed in, click Yes.
Sign in one final time. You’ll then land on the Microsoft 365 home page.
Your Office applications — Outlook, Word, Excel, PowerPoint, and more — are listed down the left side of the page.
Next steps
For a quick-start guide on using CRL-H, see the CRL-H Quick Start Guide.
© CRL Technologies, Inc. — Internal IT Knowledge Base. For CRL staff use only.