<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSO with AD - Sending sAMAccountName instead of Email in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5282708#M1476</link>
    <description>&lt;P&gt;MHurley,&lt;/P&gt;&lt;P&gt;Did you find a solution for this?&amp;nbsp; We are looking for a solution like yours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Bret&lt;/P&gt;</description>
    <pubDate>Fri, 18 Apr 2025 12:00:41 GMT</pubDate>
    <dc:creator>macocharlie</dc:creator>
    <dc:date>2025-04-18T12:00:41Z</dc:date>
    <item>
      <title>SSO with AD - Sending sAMAccountName instead of Email</title>
      <link>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5259951#M1465</link>
      <description>&lt;P&gt;I am configuring DUO using the auth proxy to on-prem AD.&amp;nbsp; &amp;nbsp; &amp;nbsp; Internal users have their email addresses in the AD mail attribute, and things work great.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the internal users are added to DUO using directory sync, two main things work:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;They receive an enrollment email with steps on downloading the app and enrolling their phone&lt;/LI&gt;
&lt;LI&gt;When they log into VPN (utilizing SAML integration to DUO), they enter their email address and AD password&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Things break down a bit when dealing with third-party users, which we want to use MFA when coming in over VPN.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The vendors have AD accounts but we do not give them email boxes.&amp;nbsp; &amp;nbsp;The AD accounts have their third-party email addresses in the mail attribute.&lt;/P&gt;
&lt;P&gt;They receive the enrollment email when they are added to DUO using directory sync, which is exactly what we want.&lt;/P&gt;
&lt;P&gt;I understand they will need to log into the DUO prompt using a corporate email address (because of domain validation), so asking them to put the corporate domain is acceptable&amp;nbsp; (Ex:&amp;nbsp; &amp;nbsp;AD Username - hvac-user, DUO prompt - &lt;A href="mailto:hvac-user@mycorp.com" target="_blank" rel="noopener"&gt;hvac-user@mycorp.com&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;We can create an alias on their duo account to match:&amp;nbsp; &lt;A href="mailto:hvac-user@mycorp.com" target="_blank" rel="noopener"&gt;hvac-user@mycorp.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The issue I am running into now is that authentication is failing.&amp;nbsp; &amp;nbsp; When I look at the auth proxy logs, DUO is sending the full email address of the user, which doesn't exist in AD.&amp;nbsp; &amp;nbsp;It results in a "user not found" error.&lt;/P&gt;
&lt;P&gt;If we can strip the "@mycorp.com" from the authentication attempt it would be able to match the sAMAccountName.&lt;/P&gt;
&lt;P&gt;Is there a way to make these authentication attempts send the sAMAccountName to AD, rather than the full email address typed in?&lt;/P&gt;
&lt;P&gt;If not, has anyone else found a flow that works for vendors and allows them to send the enrollment email to their "real" email?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 01:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5259951#M1465</guid>
      <dc:creator>mhurley131</dc:creator>
      <dc:date>2025-02-13T01:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with AD - Sending sAMAccountName instead of Email</title>
      <link>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5275374#M1475</link>
      <description>&lt;P&gt;So, this was an option we set up in our environment:&lt;/P&gt;&lt;P&gt;We registered a new DNS under our DNS provider. For example, if our main domain is mycorp.com, we registered a subdomain like a.mycorp.com. We then added this subdomain in Duo under Permitted Email Domains and completed the verification process.&lt;/P&gt;&lt;P&gt;Next, for the vendor accounts, we updated their email addresses in Active Directory to use the new subdomain for example, abc@a.mycorp.com. We tested this configuration, and it worked as expected.&lt;/P&gt;&lt;P&gt;Now, all vendor accounts in AD have their email addresses set to use @a.mycorp.com.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5275374#M1475</guid>
      <dc:creator>temz147</dc:creator>
      <dc:date>2025-03-26T14:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with AD - Sending sAMAccountName instead of Email</title>
      <link>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5282708#M1476</link>
      <description>&lt;P&gt;MHurley,&lt;/P&gt;&lt;P&gt;Did you find a solution for this?&amp;nbsp; We are looking for a solution like yours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Bret&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 12:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/sso-with-ad-sending-samaccountname-instead-of-email/m-p/5282708#M1476</guid>
      <dc:creator>macocharlie</dc:creator>
      <dc:date>2025-04-18T12:00:41Z</dc:date>
    </item>
  </channel>
</rss>

