<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuration with AD.. documentation confusing in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881184#M692</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;The moment you use bulk enrollment for a user, their account is locked out.  This means it is impossible to log in to pick up the email. New User policy appears to be ignored for bulk enrolled users.&lt;/P&gt;
&lt;P&gt;If it’s supposed to work as you describe unless I’m missing something it’s currently broken - there needs to be a way to send the email without enrolling the user.&lt;/P&gt;
&lt;P&gt;I’ll look at the device management portal although it looks quite involved.&lt;/P&gt;
&lt;P&gt;Tony&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 02 Mar 2017 18:56:37 GMT</pubDate>
    <dc:creator>tonymhoyle</dc:creator>
    <dc:date>2017-03-02T18:56:37Z</dc:date>
    <item>
      <title>Configuration with AD.. documentation confusing</title>
      <link>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881182#M690</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I set up a test domain over the weekend to see if duo would work for us, but I can’t get it to work in what I would consider a sensible way.&lt;/P&gt;
&lt;P&gt;If I add the RDP/Login to duo, it’s easy enough to set it up for only enrolled accounts to be asked for additional authentication, that’s fine.&lt;BR /&gt;
&lt;EM&gt;however&lt;/EM&gt; the moment I add a new account it locks that account from logging in.  This presents a problem, since you can’t send an enrollment email without adding the user - which prevents them logging in to receive the email.&lt;/P&gt;
&lt;P&gt;I need to set duo up so that someone who has been sent an email but not enrolled is allowed to enroll in their own time - enforcement is months away… it needs to be voluntary.&lt;/P&gt;
&lt;P&gt;The documentation  talks about self enrollment but I’ve been unable to work out how to set that up.  Is there a standard URL for that on the server?  Writing my own email that says ‘go here to enroll’ is acceptable.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Mar 2017 14:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881182#M690</guid>
      <dc:creator>tonymhoyle</dc:creator>
      <dc:date>2017-03-01T14:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration with AD.. documentation confusing</title>
      <link>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881183#M691</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;The Windows Logon doesn’t support self-enrollment (hence all the warnings in the documentation about making sure you’ve enrolled your users separately).&lt;/P&gt;
&lt;P&gt;You can have your users self-enroll in a few ways:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Use &lt;A href="https://duo.com/docs/enrolling_users#bulk-self-enrollment"&gt;bulk enrollment&lt;/A&gt; to end an enrollment email to users. the email contains a link they can use to add their authentication devices (easy).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Deploy Duo’s standalone &lt;A href="https://duo.com/docs/device-management"&gt;Device Management Portal&lt;/A&gt; so they can enroll themselves by visiting a URL you specify on a web server you’re hosting internally (more difficult).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;To make sure that users who haven’t enrolled in Duo yet aren’t challenged for two-factor when logging in to the application you can use Duo &lt;A href="https://duo.com/docs/policy"&gt;policies&lt;/A&gt; to &lt;A href="https://duo.com/docs/policy#create-and-apply-a-custom-application-policy"&gt;create and apply a group policy to your RDP application&lt;/A&gt; that sets the &lt;A href="https://duo.com/docs/policy#new-user-policy"&gt;New User Policy&lt;/A&gt; policy to “allow access” to unenrolled users.&lt;/P&gt;
&lt;P&gt;I hope this helps you stage out your Duo deployment! Thanks for trying Duo.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Mar 2017 15:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881183#M691</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2017-03-02T15:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration with AD.. documentation confusing</title>
      <link>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881184#M692</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;The moment you use bulk enrollment for a user, their account is locked out.  This means it is impossible to log in to pick up the email. New User policy appears to be ignored for bulk enrolled users.&lt;/P&gt;
&lt;P&gt;If it’s supposed to work as you describe unless I’m missing something it’s currently broken - there needs to be a way to send the email without enrolling the user.&lt;/P&gt;
&lt;P&gt;I’ll look at the device management portal although it looks quite involved.&lt;/P&gt;
&lt;P&gt;Tony&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Mar 2017 18:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/configuration-with-ad-documentation-confusing/m-p/4881184#M692</guid>
      <dc:creator>tonymhoyle</dc:creator>
      <dc:date>2017-03-02T18:56:37Z</dc:date>
    </item>
  </channel>
</rss>

