What Happens When Moving Workstations from AD to Entra with Duo?

0
9
Asked By TechNinja77 On

I'm curious about the login process when transitioning workstations from Active Directory (AD) to Entra with Duo federated Microsoft 365 Tenant. If I start this move, will logging in fail because it can't authenticate via Duo? Is there a workaround that allows users to log in without being prompted for Duo authentication? Also, would setting up Duo Conditional Access policies and defederating be the best approach to handle this situation? Thanks for your insights!

3 Answers

Answered By GadgetGuru26 On

This is quite the situation! With Duo, an interactive web login is required for Duo SSO. If you federate your 365 domain to Duo, users will generally struggle to log into Entra-joined devices. The good news is if you enable WS-Trust, Duo will remove the 2FA requirement, allowing SSO on those devices through the standard login flow. Just a heads up though, for this to work currently, users have to log in with their full email as their username due to a bug—this will be fixed in the next major update! Also, consider making a group policy to bypass certain requirements during device enrollment if you're using device trust.

Answered By CloudMaster42 On

While I'm not an expert on Duo specifically, I can share my experience with similar setups like Secret Double Octopus. For Entra ID to work properly, the tenant needs to be federated via WS-FED instead of SAML. This ensures a smoother redirection for logins, especially during the initial configuration. I suggest giving it a try with Duo—you might find that it operates similarly! If you're interested, I can share a blog post detailing this process with SDO.

Answered By LoginLover99 On

From my experience, if the Duo client is not installed on the workstation, users won’t get prompted for Duo at login, even with Duo federation for Microsoft 365. But if the client is present, it will prompt based on your configuration for passwordless access or push notifications.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.