<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo Auth Proxy + AD sync + LDAP filters in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879498#M502</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I am not 100% sure on this but I think you are confusing the sections in the proxy configuration. The AD sync or LDAP sync section is under the Cloud Section and does not provide any LDAP filter methods.&lt;/P&gt;
&lt;ASIDE class="onebox whitelistedgeneric"&gt;
  &lt;HEADER class="source"&gt;
      &lt;IMG src="https://duo.com/favicon.ico" class="site-icon" width="32" height="32" /&gt;
      &lt;A href="https://duo.com/docs/authproxy-reference#cloud-section" target="_blank" rel="nofollow noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;
  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/362;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191267i2802AA91D1A88FF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/docs/authproxy-reference#cloud-section" target="_blank" rel="nofollow noopener"&gt;Duo Authentication Proxy Reference&lt;/A&gt;&lt;/H3&gt;

&lt;P&gt;Duo’s trusted access solution enables organizations to secure access to all work applications, for all users, from anywhere, with any device they choose.&lt;/P&gt;


  &lt;/ARTICLE&gt;
  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;
  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;&lt;EM&gt;The  &lt;CODE&gt;[cloud]&lt;/CODE&gt;  section is a special configuration used only when importing users to Duo via OpenLDAP or Active Directory synchronization. See &lt;A href="https://duo.com/docs/adsync" rel="nofollow noopener"&gt;our AD Sync documentation&lt;/A&gt; or &lt;A href="https://duo.com/docs/ldapsync" rel="nofollow noopener"&gt;OpenLDAP sync documentation&lt;/A&gt; to learn more. Only one  &lt;CODE&gt;[cloud]&lt;/CODE&gt;  may be present in the configuration file.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I am guessing you are looking at the ad_client section which is used for client integrations when an application leverages Active Directory for authentication.&lt;/P&gt;
&lt;ASIDE class="onebox whitelistedgeneric"&gt;
  &lt;HEADER class="source"&gt;
      &lt;IMG src="https://duo.com/favicon.ico" class="site-icon" width="32" height="32" /&gt;
      &lt;A href="https://duo.com/docs/authproxy-reference#ad_client" target="_blank" rel="nofollow noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;
  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/362;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191267i2802AA91D1A88FF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/docs/authproxy-reference#ad_client" target="_blank" rel="nofollow noopener"&gt;Duo Authentication Proxy Reference&lt;/A&gt;&lt;/H3&gt;

&lt;P&gt;Duo’s trusted access solution enables organizations to secure access to all work applications, for all users, from anywhere, with any device they choose.&lt;/P&gt;


  &lt;/ARTICLE&gt;
  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;
  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;I would recommend you create new Active Directory groups with correct user objects in the groups for sync.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 22 Apr 2019 16:39:20 GMT</pubDate>
    <dc:creator>Toto_Tamberine</dc:creator>
    <dc:date>2019-04-22T16:39:20Z</dc:date>
    <item>
      <title>Duo Auth Proxy + AD sync + LDAP filters</title>
      <link>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879497#M501</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;We have logically separate offices in our Active Directory such as Office1 and Office2. For phasing in Duo we would like to enable enrollments based on Active Directory sync using “Office1 Users” security group and “Office2 Users” security group. These AD groups currently contain various AD user objects including real users, shared calendars, generic user objects, etc but I only want to sync users that have an employeeID AND mail AD attribute.&lt;/P&gt;
&lt;P&gt;I’m using this in the Duo Auth Proxy config file to filter only users that have those attributes:&lt;/P&gt;
&lt;P&gt;search_dn=DC=mycompany,DC=com&lt;BR /&gt;
ldap_filter=(&amp;amp;(ObjectCategory=person)(objectClass=user)(mail=asterix)(employeeID=asterix))&lt;/P&gt;
&lt;P&gt;Note: asterix=wildcard… that symbol won’t show in this post&lt;/P&gt;
&lt;P&gt;However, when I add “Office1 Users” to the Duo portal settings under Users-&amp;gt;Directory Sync-&amp;gt;Active Directory-&amp;gt; Choose Groups… ALL users in “Office1 Users” get synced including those without mail or emplyeeID.&lt;/P&gt;
&lt;P&gt;Am I setting the filter wrong on the auth proxy config? is the wildcard grabbing accounts that have empty values as well?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Apr 2019 14:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879497#M501</guid>
      <dc:creator>BusterDoney</dc:creator>
      <dc:date>2019-04-22T14:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Auth Proxy + AD sync + LDAP filters</title>
      <link>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879498#M502</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I am not 100% sure on this but I think you are confusing the sections in the proxy configuration. The AD sync or LDAP sync section is under the Cloud Section and does not provide any LDAP filter methods.&lt;/P&gt;
&lt;ASIDE class="onebox whitelistedgeneric"&gt;
  &lt;HEADER class="source"&gt;
      &lt;IMG src="https://duo.com/favicon.ico" class="site-icon" width="32" height="32" /&gt;
      &lt;A href="https://duo.com/docs/authproxy-reference#cloud-section" target="_blank" rel="nofollow noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;
  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/362;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191267i2802AA91D1A88FF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/docs/authproxy-reference#cloud-section" target="_blank" rel="nofollow noopener"&gt;Duo Authentication Proxy Reference&lt;/A&gt;&lt;/H3&gt;

&lt;P&gt;Duo’s trusted access solution enables organizations to secure access to all work applications, for all users, from anywhere, with any device they choose.&lt;/P&gt;


  &lt;/ARTICLE&gt;
  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;
  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;&lt;EM&gt;The  &lt;CODE&gt;[cloud]&lt;/CODE&gt;  section is a special configuration used only when importing users to Duo via OpenLDAP or Active Directory synchronization. See &lt;A href="https://duo.com/docs/adsync" rel="nofollow noopener"&gt;our AD Sync documentation&lt;/A&gt; or &lt;A href="https://duo.com/docs/ldapsync" rel="nofollow noopener"&gt;OpenLDAP sync documentation&lt;/A&gt; to learn more. Only one  &lt;CODE&gt;[cloud]&lt;/CODE&gt;  may be present in the configuration file.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I am guessing you are looking at the ad_client section which is used for client integrations when an application leverages Active Directory for authentication.&lt;/P&gt;
&lt;ASIDE class="onebox whitelistedgeneric"&gt;
  &lt;HEADER class="source"&gt;
      &lt;IMG src="https://duo.com/favicon.ico" class="site-icon" width="32" height="32" /&gt;
      &lt;A href="https://duo.com/docs/authproxy-reference#ad_client" target="_blank" rel="nofollow noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;
  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/362;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191267i2802AA91D1A88FF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/docs/authproxy-reference#ad_client" target="_blank" rel="nofollow noopener"&gt;Duo Authentication Proxy Reference&lt;/A&gt;&lt;/H3&gt;

&lt;P&gt;Duo’s trusted access solution enables organizations to secure access to all work applications, for all users, from anywhere, with any device they choose.&lt;/P&gt;


  &lt;/ARTICLE&gt;
  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;
  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;I would recommend you create new Active Directory groups with correct user objects in the groups for sync.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Apr 2019 16:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879498#M502</guid>
      <dc:creator>Toto_Tamberine</dc:creator>
      <dc:date>2019-04-22T16:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Auth Proxy + AD sync + LDAP filters</title>
      <link>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879499#M503</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Thanks for pointing that out; I had made the assumption that the Cloud section was using the ad_client section settings. Unfortunately in the portal I can only configure the Base DN and nothing more in regards to the Directory Sync… I was really hoping to use the existing groups and avoid having to create a new user group per office since we have over 120 offices.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Apr 2019 18:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-auth-proxy-ad-sync-ldap-filters/m-p/4879499#M503</guid>
      <dc:creator>BusterDoney</dc:creator>
      <dc:date>2019-04-22T18:30:54Z</dc:date>
    </item>
  </channel>
</rss>

