<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New User Enrollment with bypass codes in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367509#M1540</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1854823"&gt;@doGlooPA&lt;/a&gt;&amp;nbsp;Please read through&amp;nbsp;&lt;A href="https://help.duo.com/s/article/4518?language=en_US" target="_blank" rel="noopener"&gt;https://help.duo.com/s/article/4518?language=en_US&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;"Note: Bypass codes are intended for temporary access. A user with only a bypass code configured and no other 2FA device is not considered to be enrolled with Duo. This user falls into the unenrolled category."&lt;/P&gt;
&lt;P&gt;Duo for Windows Logon is a client implementation of our AuthAPI. The post to the /preauth endpoint with the username is receiving an "enroll" response (ETA you can see this in the Duo Windows Logon log output in C:\ProgramData\DuoSecurity). That is why the user receives the message they do. This is distinct behavior from the web-based Duo Universal Prompt (Duo Web SDK) seen when accessing apps in a browser.&lt;/P&gt;
&lt;P&gt;If the users had any other factor attached then they would be considered "enrolled" and would be able to use the bypass code to log in.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a really clunky but achievable way to do this: attach a dummy hardware token to the new user, and then they can log in to Windows with the bypass code. However, since attaching the dummy hardtoken makes the user "enrolled", and emailed enrollment links won't work (they'll get a an error saying they're already enrolled). At this point though, they would need to enter self-service device management in Duo Central or inline during auth to a non-sso web application (using the bypass code to get in, so they would be blocked here if it's a one-time use bypass code). The really clunky part os that while they can add and remove almost any authentication method from the self-service device portal, they can't add or remove a hardware token. So, that dummy token would hang around attached to the user until you (or an Admin API process) removes it.&lt;/P&gt;
&lt;P&gt;Ideally you would have collected a user's mobile phone number as part of their onboarding process and put it in AD so that the sync to Duo can add the phone with that number to the new user. They way they could use it to log into Windows and anything else they might need after that.&lt;/P&gt;
&lt;P&gt;ETA there is an existing feature request to treat users with a bypass code as enrolled that would address this, as the AuthAPI would no longer return an "enroll" response for a user with only a bypass code. You may contact your Duo/Cisco account or customer success team (or Duo Support if you have neither) to upvote this or provide additional context.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Feb 2026 15:53:33 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2026-02-04T15:53:33Z</dc:date>
    <item>
      <title>New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367188#M1525</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our environment we use Active Directory to import users into Duo. We use the login MFA application to provide MFA to our Windows devices. When new employees start, our plan was to create a one time bypass code for their account so they can get into Windows and get to their email where their enrollment codes should be so they can enroll their phone in Duo.&amp;nbsp;&lt;BR /&gt;We just started this process but pretty sure it worked a few times previously. Currently though, it is not working. When a new user enters their password they are given a prompt in Windows to "Enroll an authentication device to proceed." They are not given an option to use the bypass code to bypass MFA. I am guessing that a bypass code is not considered a device so with no device setup, it stops there. I swear this worked a few times in testing but maybe there were other circumstances involved with the accounts.&amp;nbsp;&lt;BR /&gt;Any thoughts or ideas on how to get new users enrolled in our environment? My only other thought is to try to get a phone added to their accounts before hand but that is difficult with new hires.&amp;nbsp;&lt;BR /&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 18:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367188#M1525</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T18:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367201#M1526</link>
      <description>&lt;P&gt;Is there any chance this enrollment is for offline use?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367201#M1526</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2026-02-03T19:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367209#M1527</link>
      <description>&lt;P&gt;No. Online enrollment. They would be prompted to create an offline token after using MFA the first time as we do allow offline logins.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367209#M1527</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T19:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367212#M1528</link>
      <description>&lt;P&gt;This is all they get when logging on the first time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DuoEnrollment.jpg" style="width: 756px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/258970iBFB7CC955EA18A0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="DuoEnrollment.jpg" alt="DuoEnrollment.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367212#M1528</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T19:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367215#M1529</link>
      <description>&lt;P&gt;Have you got bypass codes enabled under allowed authentication methods?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PhilipDAth_0-1770146644224.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/258971iC17F0D626ECB5498/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PhilipDAth_0-1770146644224.png" alt="PhilipDAth_0-1770146644224.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367215#M1529</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2026-02-03T19:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367216#M1530</link>
      <description>&lt;P&gt;Have you considered using the option ("Activate") to TXT the user the enrollment procedure to get their mobile enrolled?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367216#M1530</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2026-02-03T19:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367218#M1531</link>
      <description>&lt;P&gt;Yes, Duo Push, Mobile passcode, Hardware tokens and bypass code.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DuoBypass.jpg" style="width: 598px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/258972iA467A7CC824298E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="DuoBypass.jpg" alt="DuoBypass.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:31:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367218#M1531</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T19:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367220#M1532</link>
      <description>&lt;P&gt;Bypass codes do work fine for those who are already enrolled. Just not for someone who is brand new.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367220#M1532</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T19:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367222#M1533</link>
      <description>&lt;P&gt;I am not sure what that option is you are referring to. We generally do not import mobile phone data into Duo for new users so if we were do to that, I could manually setup their phones and text them enrollment. Just trying to automate so I don't need to do that for every new user.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367222#M1533</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T19:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367224#M1534</link>
      <description>&lt;P&gt;Following&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367224#M1534</guid>
      <dc:creator>chickpeafilae</dc:creator>
      <dc:date>2026-02-03T19:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367227#M1535</link>
      <description>&lt;P&gt;You won't be able to complete the enrollment process for Duo Mobile via the Windows Login process.&lt;/P&gt;
&lt;P&gt;What about generating a QR enrollment code, printing that out, and giving that to new users to scan in Duo Mobile prior to their first login?&lt;BR /&gt;What about TXTing the user the enrollment URL, to complete activation of their phone prior to logging in?&lt;/P&gt;
&lt;P&gt;You are going to need to do something to complete the activation of their MFA device prior to them logging in.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367227#M1535</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2026-02-03T19:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367229#M1536</link>
      <description>&lt;P&gt;What about having them web browse to your Duo Central portal on their mobile device, and try to complete enrollment via that process?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 19:51:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367229#M1536</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2026-02-03T19:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367232#M1537</link>
      <description>&lt;P&gt;That was kind of what I was afraid of. That gets pretty hard for large business to manage. It makes the most sense to allow a bypass code to actually work as a bypass code. We will have to look into the other options. Printing or sending a QR Code is a great idea. I will try that. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 20:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367232#M1537</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T20:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367234#M1538</link>
      <description>&lt;P&gt;These are personal phones mostly and I am pretty sure we limit Duo Central access to trusted endpoints only.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 20:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367234#M1538</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-03T20:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367509#M1540</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1854823"&gt;@doGlooPA&lt;/a&gt;&amp;nbsp;Please read through&amp;nbsp;&lt;A href="https://help.duo.com/s/article/4518?language=en_US" target="_blank" rel="noopener"&gt;https://help.duo.com/s/article/4518?language=en_US&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;"Note: Bypass codes are intended for temporary access. A user with only a bypass code configured and no other 2FA device is not considered to be enrolled with Duo. This user falls into the unenrolled category."&lt;/P&gt;
&lt;P&gt;Duo for Windows Logon is a client implementation of our AuthAPI. The post to the /preauth endpoint with the username is receiving an "enroll" response (ETA you can see this in the Duo Windows Logon log output in C:\ProgramData\DuoSecurity). That is why the user receives the message they do. This is distinct behavior from the web-based Duo Universal Prompt (Duo Web SDK) seen when accessing apps in a browser.&lt;/P&gt;
&lt;P&gt;If the users had any other factor attached then they would be considered "enrolled" and would be able to use the bypass code to log in.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a really clunky but achievable way to do this: attach a dummy hardware token to the new user, and then they can log in to Windows with the bypass code. However, since attaching the dummy hardtoken makes the user "enrolled", and emailed enrollment links won't work (they'll get a an error saying they're already enrolled). At this point though, they would need to enter self-service device management in Duo Central or inline during auth to a non-sso web application (using the bypass code to get in, so they would be blocked here if it's a one-time use bypass code). The really clunky part os that while they can add and remove almost any authentication method from the self-service device portal, they can't add or remove a hardware token. So, that dummy token would hang around attached to the user until you (or an Admin API process) removes it.&lt;/P&gt;
&lt;P&gt;Ideally you would have collected a user's mobile phone number as part of their onboarding process and put it in AD so that the sync to Duo can add the phone with that number to the new user. They way they could use it to log into Windows and anything else they might need after that.&lt;/P&gt;
&lt;P&gt;ETA there is an existing feature request to treat users with a bypass code as enrolled that would address this, as the AuthAPI would no longer return an "enroll" response for a user with only a bypass code. You may contact your Duo/Cisco account or customer success team (or Duo Support if you have neither) to upvote this or provide additional context.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 15:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367509#M1540</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2026-02-04T15:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367521#M1541</link>
      <description>&lt;P&gt;Thanks Kristina. I will reach out and upvote that. It seems the bypass code method would work best if allowed. Allowing new users to enroll using their devices means we need to allow mobile browsers. We specifically blocked those to prevent people from using their personal phones to connect to our Duo Central site and launch SAML apps on their phones. My guess is we will now need to create a new policy surrounding SAML apps for extra security.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 16:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367521#M1541</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-04T16:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367643#M1542</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Allowing new users to enroll using their devices means we need to allow mobile browsers&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;You don't have to do this to get what you want I think.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Have phone # in AD.&lt;/LI&gt;
&lt;LI&gt;Import new user with phone from sync. Don't send an enrollment email.&lt;/LI&gt;
&lt;LI&gt;Create bypass code for new user and communicate it to them somehow (with their AD creds?). You give them maybe 24 hours to reuse the code. You tell the user to use the bypass code to log in if you have not allowed SMS or phone call authentication methods.&lt;/LI&gt;
&lt;LI&gt;User logs in to Windows that day with AD creds and bypass code.&lt;/LI&gt;
&lt;LI&gt;Also that day user launches browser on that Windows system, which I have assumed is trusted, to log into Duo Central and get to self-service management. They use either the bypass code (or use SMS/phone if you allow it) to get into device management.&lt;/LI&gt;
&lt;LI&gt;User activates their phone for push or enrolls whatever other methods you allow (passkeys?).&lt;/LI&gt;
&lt;LI&gt;The bypass code expires but user doesn't need it anymore because they have one or more usable auth methods.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;There are multiple possible permutations of this that wouldn't require you letting them use the phones themselves to access Duo Central or any SAML apps.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 20:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367643#M1542</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2026-02-04T20:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367645#M1543</link>
      <description>&lt;P&gt;That is what we have tried but we have the Duo Logon MFA app already installed on all PC's so you need to have MFA to get passed that. Or a bypass code, but for new users, a bypass code with no device enrolled, is not allowed. So we are back to changing bypass codes to allow that. Which I did upvote with support. For now though, we will have to give new employees an enrollment code and link to the enrollment page and they will need to enroll via their cell phone before being able to logon to any PC's. Not convenient but it works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 20:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367645#M1543</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-04T20:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: New User Enrollment with bypass codes</title>
      <link>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367656#M1544</link>
      <description>&lt;P&gt;We did just create a new application level policy that blocks mobile devices for all the apps we don't want them to access in Duo Central with their phones. It was easier than I thought and seems to work well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 21:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/new-user-enrollment-with-bypass-codes/m-p/5367656#M1544</guid>
      <dc:creator>doGlooPA</dc:creator>
      <dc:date>2026-02-04T21:13:15Z</dc:date>
    </item>
  </channel>
</rss>

