<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: USING MULTIPLE DOMAIN in Deployment Strategy</title>
    <link>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5118458#M211</link>
    <description>&lt;P&gt;If this is about a Duo customer please instruct them to contact &lt;A href="https://duo.com/support" target="_self"&gt;Duo Support&lt;/A&gt;. I'm not in support; don't @ me.&lt;/P&gt;
&lt;P&gt;However, it is correct that they will receive the error you mentioned if there are duplicate usernames coming from the two domains. Is this SSO + AD authentication? It is noted in the documentation that email addresses must be unique across all domains and forests:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://duo.com/docs/sso#active-directory:~:text=When%20a%20user,all%20the%20directories" target="_self"&gt;If Duo Single Sign-On gets results for multiple users matching the email address, it will show an error to the user. All email addresses that users log-in with should be unique across all the directories.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;They should check the users that can't log in to make sure their email is not duplicated between forests. Again, if you don't know how to proceed advise the customer to contact Duo Support.&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2024 12:07:41 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2024-05-28T12:07:41Z</dc:date>
    <item>
      <title>USING MULTIPLE DOMAIN</title>
      <link>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5117884#M210</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;The issue you are facing with the Duo Authentication Proxy and the two domains (abc.com and xyz.com) seems to be related to the user directory configuration. Based&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;on the information provided:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL class="list-decimal marker:font-mono marker:text-sm pl-11"&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;Customer had only one domain (abc.com) configured on Duo and the Authentication Proxy was also configured for only that domain.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;Some users from the xyz.com domain were trying to log in, but they were getting an error saying their organization was not allowed to log in. This is because the Duo Authentication Proxy was only configured for the abc.com domain.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN class=""&gt;To resolve this issue:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL class="list-decimal marker:font-mono marker:text-sm pl-11"&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;We advised the customer to add a new Authentication Proxy server in Duo with the xyz.com domain. This was the right approach, as it would allow users from both domains to authenticate through Duo.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;However, Customer mentioned that even after this configuration, some users from the xyz.com domain are still not able to log in, and the Duo dashboard is indicating that there are multiple, duplicate user accounts with invalid credentials.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/878627"&gt;@DuoKristina&lt;/a&gt;&amp;nbsp;Need your expertise.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 27 May 2024 19:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5117884#M210</guid>
      <dc:creator>mumbai.support</dc:creator>
      <dc:date>2024-05-27T19:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: USING MULTIPLE DOMAIN</title>
      <link>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5118458#M211</link>
      <description>&lt;P&gt;If this is about a Duo customer please instruct them to contact &lt;A href="https://duo.com/support" target="_self"&gt;Duo Support&lt;/A&gt;. I'm not in support; don't @ me.&lt;/P&gt;
&lt;P&gt;However, it is correct that they will receive the error you mentioned if there are duplicate usernames coming from the two domains. Is this SSO + AD authentication? It is noted in the documentation that email addresses must be unique across all domains and forests:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://duo.com/docs/sso#active-directory:~:text=When%20a%20user,all%20the%20directories" target="_self"&gt;If Duo Single Sign-On gets results for multiple users matching the email address, it will show an error to the user. All email addresses that users log-in with should be unique across all the directories.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;They should check the users that can't log in to make sure their email is not duplicated between forests. Again, if you don't know how to proceed advise the customer to contact Duo Support.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 12:07:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5118458#M211</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2024-05-28T12:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: USING MULTIPLE DOMAIN</title>
      <link>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5118570#M212</link>
      <description>&lt;P&gt;I'm told that TAC can create a case in CSOne and bond the case to the Duo Support queue.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 13:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/using-multiple-domain/m-p/5118570#M212</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2024-05-28T13:47:50Z</dc:date>
    </item>
  </channel>
</rss>

