<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User synchronization with Duo in Secure Access Discussions</title>
    <link>https://community.cisco.com/t5/secure-access-discussions/user-synchronization-with-duo/m-p/5551634#M185</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It sounds a like a potential configuration issue on the application within Duo, have you checked the informaation about limitations and best practices from Secure Access just to validate everything is properly configured&amp;nbsp;&lt;A href="https://securitydocs.cisco.com/docs/csa/olh/136532.dita" target="_blank" rel="noopener"&gt;https://securitydocs.cisco.com/docs/csa/olh/136532.dita&lt;/A&gt;&amp;nbsp;the things I would highlight to be reviewed are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Secure Access supports provisioning a maximum of 1000 groups from Duo. Any groups beyond this number that are in scope are not provisioned. Secure Access does not restrict the number of users that you can provision from Duo. For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://securitydocs.cisco.com/docs/csa/olh/118830.dita" target="_blank" rel="noopener"&gt;Limitations and Range Limits&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;To ensure that all users are provisioned, assign the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Everyone&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;group to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco Secure Access&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;app. You can push other additional groups for group-based Secure Access rule enforcement.&lt;/LI&gt;&lt;LI&gt;Duo does not support nested groups.&lt;/LI&gt;&lt;LI&gt;If you previously imported groups from the on-premises AD and push the same groups from Duo, the groups from Duo do not overwrite the groups imported from the on-premises AD. You must reassign any group-based Secure Access policy rules to the groups imported from Duo.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The appropiate attribute mapping is very important as well&amp;nbsp;&lt;A href="https://securitydocs.cisco.com/docs/csa/olh/136568.dita:" target="_blank" rel="noopener"&gt;https://securitydocs.cisco.com/docs/csa/olh/136568.dita:&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IvanGonzalez_0-1778254575981.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/281924iD7C8665DFD0A72CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IvanGonzalez_0-1778254575981.png" alt="IvanGonzalez_0-1778254575981.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also, to review if there are any errors on some of the groups getting synced, could check the "Recent Logs" section withing the "Provisioning" tab whithin the Secure Access Provisioning App in Duo Dashboard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 May 2026 15:38:49 GMT</pubDate>
    <dc:creator>Ivan Gonzalez</dc:creator>
    <dc:date>2026-05-08T15:38:49Z</dc:date>
    <item>
      <title>User synchronization with Duo</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/user-synchronization-with-duo/m-p/5551499#M184</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;We have currently integrated Duo with Secure Access for testing purposes. However, it seems that only some of the user information created in Duo is being synchronized, while the remaining users are not syncing properly. What could be causing this issue?&lt;/P&gt;&lt;P&gt;We have also integrated it with AD for testing, but the users imported from AD are also not being synchronized to Secure Access. Is there any specific reason for this?&lt;/P&gt;&lt;P&gt;Please help us.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 May 2026 05:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/user-synchronization-with-duo/m-p/5551499#M184</guid>
      <dc:creator>msbang</dc:creator>
      <dc:date>2026-05-08T05:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: User synchronization with Duo</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/user-synchronization-with-duo/m-p/5551634#M185</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It sounds a like a potential configuration issue on the application within Duo, have you checked the informaation about limitations and best practices from Secure Access just to validate everything is properly configured&amp;nbsp;&lt;A href="https://securitydocs.cisco.com/docs/csa/olh/136532.dita" target="_blank" rel="noopener"&gt;https://securitydocs.cisco.com/docs/csa/olh/136532.dita&lt;/A&gt;&amp;nbsp;the things I would highlight to be reviewed are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Secure Access supports provisioning a maximum of 1000 groups from Duo. Any groups beyond this number that are in scope are not provisioned. Secure Access does not restrict the number of users that you can provision from Duo. For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://securitydocs.cisco.com/docs/csa/olh/118830.dita" target="_blank" rel="noopener"&gt;Limitations and Range Limits&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;To ensure that all users are provisioned, assign the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Everyone&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;group to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco Secure Access&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;app. You can push other additional groups for group-based Secure Access rule enforcement.&lt;/LI&gt;&lt;LI&gt;Duo does not support nested groups.&lt;/LI&gt;&lt;LI&gt;If you previously imported groups from the on-premises AD and push the same groups from Duo, the groups from Duo do not overwrite the groups imported from the on-premises AD. You must reassign any group-based Secure Access policy rules to the groups imported from Duo.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The appropiate attribute mapping is very important as well&amp;nbsp;&lt;A href="https://securitydocs.cisco.com/docs/csa/olh/136568.dita:" target="_blank" rel="noopener"&gt;https://securitydocs.cisco.com/docs/csa/olh/136568.dita:&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IvanGonzalez_0-1778254575981.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/281924iD7C8665DFD0A72CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IvanGonzalez_0-1778254575981.png" alt="IvanGonzalez_0-1778254575981.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also, to review if there are any errors on some of the groups getting synced, could check the "Recent Logs" section withing the "Provisioning" tab whithin the Secure Access Provisioning App in Duo Dashboard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 15:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/user-synchronization-with-duo/m-p/5551634#M185</guid>
      <dc:creator>Ivan Gonzalez</dc:creator>
      <dc:date>2026-05-08T15:38:49Z</dc:date>
    </item>
  </channel>
</rss>

