<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PreAuth not returning U2F Tokens in APIs</title>
    <link>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879052#M227</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;You’re correct, we do not return U2F tokens in a &lt;CODE&gt;preauth&lt;/CODE&gt; call.&lt;/P&gt;
&lt;P&gt;Please note that we only recommend using the AuthAPI &lt;CODE&gt;check&lt;/CODE&gt; and &lt;CODE&gt;ping&lt;/CODE&gt; calls in a Duo Web integration, per our instructions here: &lt;A href="https://duo.com/docs/duoweb#using-auth-api-with-duo-web"&gt;Duo Web Two-Factor Authentication for Your Web Application | Duo Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I’m also confused by the logic you describe… wouldn’t you want an unenrolled user to hit the frame to enroll?&lt;/P&gt;
&lt;P&gt;Regardless, this isn’t a recommend use of the AuthAPI &lt;CODE&gt;preauth&lt;/CODE&gt; endpoint.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 13 Nov 2018 20:41:25 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2018-11-13T20:41:25Z</dc:date>
    <item>
      <title>PreAuth not returning U2F Tokens</title>
      <link>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879051#M226</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hello: We came across this during one of our rollouts.  The PreAuth API does not seem to return U2F tokens for users.  Since we use the PreAuth check as a method of routing users to the IFrame, this means that a user with only U2F Tokens would not be seen as “enrolled”.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Nov 2018 16:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879051#M226</guid>
      <dc:creator>tdergens</dc:creator>
      <dc:date>2018-11-13T16:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: PreAuth not returning U2F Tokens</title>
      <link>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879052#M227</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;You’re correct, we do not return U2F tokens in a &lt;CODE&gt;preauth&lt;/CODE&gt; call.&lt;/P&gt;
&lt;P&gt;Please note that we only recommend using the AuthAPI &lt;CODE&gt;check&lt;/CODE&gt; and &lt;CODE&gt;ping&lt;/CODE&gt; calls in a Duo Web integration, per our instructions here: &lt;A href="https://duo.com/docs/duoweb#using-auth-api-with-duo-web"&gt;Duo Web Two-Factor Authentication for Your Web Application | Duo Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I’m also confused by the logic you describe… wouldn’t you want an unenrolled user to hit the frame to enroll?&lt;/P&gt;
&lt;P&gt;Regardless, this isn’t a recommend use of the AuthAPI &lt;CODE&gt;preauth&lt;/CODE&gt; endpoint.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Nov 2018 20:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879052#M227</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2018-11-13T20:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: PreAuth not returning U2F Tokens</title>
      <link>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879053#M228</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Check and Ping are not user specific and make the assumption that we send all users to the Duo IFrame. We currently have a mix of enrolled users and users pending their enrollment dates. PreAuth allows us to pull back the list of devices and their enrollment status (which we have found to be unreliable since we are not leveraging the bulk enrollment. Ex: Users created through the API, but with no devices report as “auth” and not “enroll”. For us, this translates to any users known to Duo will be presented with the enrollment iframe). PreAuth has been a work around.  We are currently re-coding our “PreAuth” check to pull the user instead where all tokens are listed, however this will be much heavy call.  My Contact Information is associated with my account if you want further information.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Nov 2018 20:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/preauth-not-returning-u2f-tokens/m-p/4879053#M228</guid>
      <dc:creator>tdergens</dc:creator>
      <dc:date>2018-11-13T20:59:11Z</dc:date>
    </item>
  </channel>
</rss>

