<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo Cisco Anyconnect Secondary Password in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878069#M313</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Is this an ASA? Did you follow these directions: &lt;A href="https://duo.com/docs/ciscoasa-ldap" class="inline-onebox"&gt;Cisco ASA SSL VPN for Browser and AnyConnect | Duo Security&lt;/A&gt;?&lt;/P&gt;
&lt;P&gt;It sounds like there is a misconfiguration or other issue with the &lt;A href="https://duo.com/docs/ciscoasa-ldap#modify-the-sign-in-page"&gt;customized Duo login page&lt;/A&gt; , because when configured correctly the ASA browser SSL VPN login page does not show a text input field for the second password, but instead loads the interactive Duo 2FA prompt where a new user could complete inline self-enrollment.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 26 May 2021 21:30:52 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2021-05-26T21:30:52Z</dc:date>
    <item>
      <title>Duo Cisco Anyconnect Secondary Password</title>
      <link>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878066#M310</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi&lt;BR /&gt;
I am trying to remove the secondary password option on my Cisco AnyConnect SSL VPN web portal - so new users can sign in using their AD username and password, and proceed to register their device once signed on.&lt;/P&gt;
&lt;P&gt;new users do not have the secondary password to login, if that makes sense.&lt;/P&gt;
&lt;P&gt;The duo is synced with AD security group.&lt;/P&gt;
&lt;P&gt;Is there an option/setting for me to change?&lt;/P&gt;
&lt;P&gt;thanks&lt;BR /&gt;
Aisling&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 May 2021 11:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878066#M310</guid>
      <dc:creator>aisling.natola</dc:creator>
      <dc:date>2021-05-26T11:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Cisco Anyconnect Secondary Password</title>
      <link>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878067#M311</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi Aisling,&lt;BR /&gt;
I see that you have an open support case about this as well, and it looks like you may have gotten the answer there already, but I am going to share it here as well for the wider community’s benefit &lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/cdn_emojis/twitter/smiley.png" style="display : inline;" /&gt;&lt;/P&gt;
&lt;P&gt;Users can self-enroll via the Duo Authentication Prompt if they are able to log in to the ASA VPN using a browser. You can &lt;A href="https://duo.com/docs/self-service-portal#enabling-the-self-service-portal"&gt;enable the Self-service portal through the Duo Admin Panel&lt;/A&gt; and users can enroll the device when you set a &lt;A href="https://duo.com/docs/policy#new-user-policy"&gt;new user policy&lt;/A&gt; to require enrollment.&lt;/P&gt;
&lt;P&gt;If only AnyConnect client access is permitted, users cannot self-enroll and must be enrolled using &lt;A href="https://duo.com/docs/enrolling-users#automatic-enrollment"&gt;automatic&lt;/A&gt; or &lt;A href="https://duo.com/docs/enrolling-users#manual-enrollment"&gt;manual enrollment&lt;/A&gt;.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 May 2021 14:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878067#M311</guid>
      <dc:creator>Amy2</dc:creator>
      <dc:date>2021-05-26T14:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Cisco Anyconnect Secondary Password</title>
      <link>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878068#M312</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi Amy,&lt;/P&gt;
&lt;P&gt;Thanks for getting back to me.&lt;/P&gt;
&lt;P&gt;My issue here is – new users do not have secondary password sign so cannot log onto the AnyConnect VPN via browser because the portal page is asking for two passwords.&lt;/P&gt;
&lt;P&gt;New users cannot have a secondary password yet as they have to log onto this portal with username and password from AD – and then register their device and set up 2fA. My question is how do you disable the secondary password field on the login page so users only are prompt for login creds - AD username and password, and begin to register their phone when logged into the web portal?&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;
Aisling&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 May 2021 14:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878068#M312</guid>
      <dc:creator>aisling.natola</dc:creator>
      <dc:date>2021-05-26T14:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Cisco Anyconnect Secondary Password</title>
      <link>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878069#M313</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Is this an ASA? Did you follow these directions: &lt;A href="https://duo.com/docs/ciscoasa-ldap" class="inline-onebox"&gt;Cisco ASA SSL VPN for Browser and AnyConnect | Duo Security&lt;/A&gt;?&lt;/P&gt;
&lt;P&gt;It sounds like there is a misconfiguration or other issue with the &lt;A href="https://duo.com/docs/ciscoasa-ldap#modify-the-sign-in-page"&gt;customized Duo login page&lt;/A&gt; , because when configured correctly the ASA browser SSL VPN login page does not show a text input field for the second password, but instead loads the interactive Duo 2FA prompt where a new user could complete inline self-enrollment.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 May 2021 21:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-cisco-anyconnect-secondary-password/m-p/4878069#M313</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2021-05-26T21:30:52Z</dc:date>
    </item>
  </channel>
</rss>

