<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DUO policy vs User Bypass in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/duo-policy-vs-user-bypass/m-p/4904210#M1271</link>
    <description>&lt;P&gt;I have the 'Deny Access to Unenrolled Users' policy active for all users/groups.&lt;/P&gt;&lt;P&gt;I have one user that needs ad-hoc special access without authenticating through DUO (3rd party contractor - not able to install/use an app). I have created a user account for him and added his phone number. He now appears as an inactive user NOT not enrolled.&lt;/P&gt;&lt;P&gt;Is this enough for him to be considered enrolled and for the 'Bypass' option to work under the user - status, so he won't need to authenticate with DUO when logging in?&lt;/P&gt;</description>
    <pubDate>Sun, 13 Aug 2023 14:25:33 GMT</pubDate>
    <dc:creator>alceryes</dc:creator>
    <dc:date>2023-08-13T14:25:33Z</dc:date>
    <item>
      <title>DUO policy vs User Bypass</title>
      <link>https://community.cisco.com/t5/managing-users/duo-policy-vs-user-bypass/m-p/4904210#M1271</link>
      <description>&lt;P&gt;I have the 'Deny Access to Unenrolled Users' policy active for all users/groups.&lt;/P&gt;&lt;P&gt;I have one user that needs ad-hoc special access without authenticating through DUO (3rd party contractor - not able to install/use an app). I have created a user account for him and added his phone number. He now appears as an inactive user NOT not enrolled.&lt;/P&gt;&lt;P&gt;Is this enough for him to be considered enrolled and for the 'Bypass' option to work under the user - status, so he won't need to authenticate with DUO when logging in?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 14:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-policy-vs-user-bypass/m-p/4904210#M1271</guid>
      <dc:creator>alceryes</dc:creator>
      <dc:date>2023-08-13T14:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: DUO policy vs User Bypass</title>
      <link>https://community.cisco.com/t5/managing-users/duo-policy-vs-user-bypass/m-p/4905459#M1272</link>
      <description>&lt;P&gt;That should be sufficient. You don't mention which Duo application you're using. Some of them treat partially-enrolled users in a slightly different but typically if a user exists in Duo for you to be able to set bypass status on that user it's enough to bypass with that new user policy setting configured.&lt;/P&gt;
&lt;P&gt;You could also explore alternative authentication methods to have the contractor actually use MFA when logging in that don't rely on the Duo Mobile app, like a hardware token or SMS/Phone call, and restrict use of those methods to ONLY that one contractor by using &lt;A href="https://duo.com/docs/policy#apply-a-custom-group-policy" target="_self"&gt;group policy&lt;/A&gt; (apply the policy to a Duo group containing just that contractor for that Duo application).&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 16:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-policy-vs-user-bypass/m-p/4905459#M1272</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2023-08-15T16:29:58Z</dc:date>
    </item>
  </channel>
</rss>

