<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple user IDs on one authentication system in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/multiple-user-ids-on-one-authentication-system/m-p/4881362#M705</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;One of the first systems we integrated with Duo is our Palo Alto GlobalProtect VPN.  When we began enrolling individuals in the system, one of the first things we discovered was that users could get around the Duo prompt by using their email address as a username, instead of their sAMAccountName.  We’re an O365 and SkypeforBiz customer and are required to have the email address setup as a SIPAddress.&lt;/P&gt;
&lt;P&gt;Is there any way to either&lt;BR /&gt;
a) setup multiple usernames in Duo that can authenticate through an application?&lt;BR /&gt;
-or-&lt;BR /&gt;
b) disallow users from using a secondary user ID other than their sAMAccountName?  We’re not seeing anything like this in our GlobalProtect instance.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 11 Jul 2017 19:56:51 GMT</pubDate>
    <dc:creator>Plundstedt</dc:creator>
    <dc:date>2017-07-11T19:56:51Z</dc:date>
    <item>
      <title>Multiple user IDs on one authentication system</title>
      <link>https://community.cisco.com/t5/managing-users/multiple-user-ids-on-one-authentication-system/m-p/4881362#M705</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;One of the first systems we integrated with Duo is our Palo Alto GlobalProtect VPN.  When we began enrolling individuals in the system, one of the first things we discovered was that users could get around the Duo prompt by using their email address as a username, instead of their sAMAccountName.  We’re an O365 and SkypeforBiz customer and are required to have the email address setup as a SIPAddress.&lt;/P&gt;
&lt;P&gt;Is there any way to either&lt;BR /&gt;
a) setup multiple usernames in Duo that can authenticate through an application?&lt;BR /&gt;
-or-&lt;BR /&gt;
b) disallow users from using a secondary user ID other than their sAMAccountName?  We’re not seeing anything like this in our GlobalProtect instance.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Jul 2017 19:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/multiple-user-ids-on-one-authentication-system/m-p/4881362#M705</guid>
      <dc:creator>Plundstedt</dc:creator>
      <dc:date>2017-07-11T19:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple user IDs on one authentication system</title>
      <link>https://community.cisco.com/t5/managing-users/multiple-user-ids-on-one-authentication-system/m-p/4881363#M706</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi Plundstet,&lt;/P&gt;
&lt;P&gt;I spoke with our support team and here are responses to your questions:&lt;/P&gt;
&lt;P&gt;a) Yes, by enabling &lt;A href="https://duo.com/docs/creating_applications#username-normalization"&gt;Username Normalization&lt;/A&gt;. Please ensure that Username normalization for your Palo Alto application is set to “Simple.”&lt;/P&gt;
&lt;P&gt;b) Yes. If your &lt;A href="https://duo.com/docs/policy#new-user-policy"&gt;New User Policy&lt;/A&gt; is set to Allow Access, set it to Deny Access. If I am understanding you correctly, you have more than one “style” of username that your users are trying to use to log in. If you are alright with enforcing sAMAccountName as the only accepted username, setting this policy to Deny Access would block users from completing authentication with their email.&lt;/P&gt;
&lt;P&gt;We are actively exploring more complex username aliasing features that would accommodate formats beyond email address and sAMAccountName in the future, but I don’t have a timeline to share for that feature at this time.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Jul 2017 20:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/multiple-user-ids-on-one-authentication-system/m-p/4881363#M706</guid>
      <dc:creator>mkorovesisduo</dc:creator>
      <dc:date>2017-07-11T20:44:49Z</dc:date>
    </item>
  </channel>
</rss>

