<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo Offline Access in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880024#M526</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Here are some blog posts that talk about our approach to “temporary” offline MFA for Windows:&lt;/P&gt;
&lt;ASIDE class="onebox allowlistedgeneric" data-onebox-src="https://duo.com/blog/offline-multi-factor-authentication-for-windows-is-now-available"&gt;
  &lt;HEADER class="source"&gt;
      &lt;span class="lia-inline-image-display-wrapper" image-alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" style="width: 32px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190603i0796151EE974C08C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" /&gt;&lt;/span&gt;

      &lt;A href="https://duo.com/blog/offline-multi-factor-authentication-for-windows-is-now-available" target="_blank" rel="noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;

  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/354;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_2_224652e492722297f034d88698acf0055ddbf2db.jpeg" style="width: 690px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191073i9E1CD425B08F5933/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_2_224652e492722297f034d88698acf0055ddbf2db.jpeg" alt="2X_2_224652e492722297f034d88698acf0055ddbf2db.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/blog/offline-multi-factor-authentication-for-windows-is-now-available" target="_blank" rel="noopener"&gt;Offline Multi-Factor Authentication for Windows is Now Available&lt;/A&gt;&lt;/H3&gt;

  &lt;P&gt;We’re pleased to announce the general availability of our offline MFA for Windows laptops, desktops and servers. Duo’s offline MFA for Windows allows end users to perform 2FA even while they are temporarily disconnected from the internet.&lt;/P&gt;


  &lt;/ARTICLE&gt;

  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;

  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;
&lt;ASIDE class="onebox allowlistedgeneric" data-onebox-src="https://duo.com/blog/building-windows-offline"&gt;
  &lt;HEADER class="source"&gt;
      &lt;span class="lia-inline-image-display-wrapper" image-alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" style="width: 32px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190603i0796151EE974C08C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" /&gt;&lt;/span&gt;

      &lt;A href="https://duo.com/blog/building-windows-offline" target="_blank" rel="noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;

  &lt;ARTICLE class="onebox-body"&gt;
    &lt;IMG src="https://duo.com/blog/building-windows-offline" class="thumbnail" width="" height="" /&gt;

&lt;H3&gt;&lt;A href="https://duo.com/blog/building-windows-offline" target="_blank" rel="noopener"&gt;Building Windows Offline&lt;/A&gt;&lt;/H3&gt;

  &lt;P&gt;When our customers came to us with a desire to support offline multi-factor authentication for Windows, we started off by focusing on the fundamental technical problem to be solved. How can we trust enrollment and continued authentication from a...&lt;/P&gt;


  &lt;/ARTICLE&gt;

  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;

  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;Evidence that offline MFA not intended to be a permanent situation as evidenced by the &lt;A href="https://duo.com/docs/rdp#offline-access:~:text=Prevent%20offline%20login%20after"&gt;&lt;STRONG&gt;Prevent offline login after&lt;/STRONG&gt;&lt;/A&gt; setting for the RDP/Windows Logon Duo application. We do not permit that to be set to an infinite value, and instead enforce a max of 1000 logins or 365 days.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 06 Feb 2023 22:12:07 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2023-02-06T22:12:07Z</dc:date>
    <item>
      <title>Duo Offline Access</title>
      <link>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880020#M522</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Good afternoon,&lt;/P&gt;
&lt;P&gt;We are in the process of trialing duo at our ogranization, and have roughly 100 users who work from the field and they often do not have internet access.  These users will typically float between 5 and 10 laptops, depending on the user.   I am looking at duo offline access, and If I am understanding it properly, each user would need to set up an offline account  for each of these laptops in addition to their normal online account.&lt;/P&gt;
&lt;P&gt;I just want to ensure that I am understanding the information as it is presented, or if there is some other way to give them access short of allowing them to fail through when they do not have a connection to the internet.&lt;/P&gt;
&lt;P&gt;Thank you in advance for any insight you might share.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 30 Jan 2023 18:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880020#M522</guid>
      <dc:creator>fordh</dc:creator>
      <dc:date>2023-01-30T18:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Offline Access</title>
      <link>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880021#M523</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;You are correct, in the multiple laptop scenario you describe each individual user would need to enroll in Duo offline access on each individual laptop they might use prior to taking the laptop offline (or, as you mentioned, permitting fail open for any user of the laptop).&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 31 Jan 2023 20:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880021#M523</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2023-01-31T20:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Offline Access</title>
      <link>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880022#M524</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I believe there were some DUO documentations that states permanent offline access is not recommended.  I could not find that documentation any where somehow.  Would you have a reference to that documentation?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 06 Feb 2023 19:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880022#M524</guid>
      <dc:creator>amiguel</dc:creator>
      <dc:date>2023-02-06T19:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Offline Access</title>
      <link>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880023#M525</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;ASIDE class="quote group-Level_Up_Certified" data-username="amiguel" data-post="3" data-topic="14040"&gt;
&lt;DIV class="title"&gt;
&lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
&lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/letters/a_958977.png" style="display : inline;" /&gt; amiguel:&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;lieve there were some DUO documentations that states permanent offline access is not recommended. I could not find that documentation any where somehow. Would you have a reference to that documentation?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;
&lt;P&gt;And that is fine.  The locations without access to the interet arent the norm, but they are common.  I am trying to think worst case scenarios as we trial this product.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 06 Feb 2023 19:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880023#M525</guid>
      <dc:creator>fordh</dc:creator>
      <dc:date>2023-02-06T19:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Offline Access</title>
      <link>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880024#M526</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Here are some blog posts that talk about our approach to “temporary” offline MFA for Windows:&lt;/P&gt;
&lt;ASIDE class="onebox allowlistedgeneric" data-onebox-src="https://duo.com/blog/offline-multi-factor-authentication-for-windows-is-now-available"&gt;
  &lt;HEADER class="source"&gt;
      &lt;span class="lia-inline-image-display-wrapper" image-alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" style="width: 32px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190603i0796151EE974C08C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" /&gt;&lt;/span&gt;

      &lt;A href="https://duo.com/blog/offline-multi-factor-authentication-for-windows-is-now-available" target="_blank" rel="noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;

  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/354;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_2_224652e492722297f034d88698acf0055ddbf2db.jpeg" style="width: 690px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191073i9E1CD425B08F5933/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_2_224652e492722297f034d88698acf0055ddbf2db.jpeg" alt="2X_2_224652e492722297f034d88698acf0055ddbf2db.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/blog/offline-multi-factor-authentication-for-windows-is-now-available" target="_blank" rel="noopener"&gt;Offline Multi-Factor Authentication for Windows is Now Available&lt;/A&gt;&lt;/H3&gt;

  &lt;P&gt;We’re pleased to announce the general availability of our offline MFA for Windows laptops, desktops and servers. Duo’s offline MFA for Windows allows end users to perform 2FA even while they are temporarily disconnected from the internet.&lt;/P&gt;


  &lt;/ARTICLE&gt;

  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;

  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;
&lt;ASIDE class="onebox allowlistedgeneric" data-onebox-src="https://duo.com/blog/building-windows-offline"&gt;
  &lt;HEADER class="source"&gt;
      &lt;span class="lia-inline-image-display-wrapper" image-alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" style="width: 32px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190603i0796151EE974C08C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" alt="2X_5_519ce45665d8dce98a5273c38d3c937763bb406a.png" /&gt;&lt;/span&gt;

      &lt;A href="https://duo.com/blog/building-windows-offline" target="_blank" rel="noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;

  &lt;ARTICLE class="onebox-body"&gt;
    &lt;IMG src="https://duo.com/blog/building-windows-offline" class="thumbnail" width="" height="" /&gt;

&lt;H3&gt;&lt;A href="https://duo.com/blog/building-windows-offline" target="_blank" rel="noopener"&gt;Building Windows Offline&lt;/A&gt;&lt;/H3&gt;

  &lt;P&gt;When our customers came to us with a desire to support offline multi-factor authentication for Windows, we started off by focusing on the fundamental technical problem to be solved. How can we trust enrollment and continued authentication from a...&lt;/P&gt;


  &lt;/ARTICLE&gt;

  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;

  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;Evidence that offline MFA not intended to be a permanent situation as evidenced by the &lt;A href="https://duo.com/docs/rdp#offline-access:~:text=Prevent%20offline%20login%20after"&gt;&lt;STRONG&gt;Prevent offline login after&lt;/STRONG&gt;&lt;/A&gt; setting for the RDP/Windows Logon Duo application. We do not permit that to be set to an infinite value, and instead enforce a max of 1000 logins or 365 days.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 06 Feb 2023 22:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-offline-access/m-p/4880024#M526</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2023-02-06T22:12:07Z</dc:date>
    </item>
  </channel>
</rss>

