08-24-2024 02:15 PM
we are setting up duo ad sync to an on premise domain
duo proxy client installed
duo ad sync configured
duo ad sync says connected
we are now sitting here unable to continue becuase duo is waiting for the initial sync
(per the documentation)
"Duo's directory sync for users runs automatically twice a day, at 12 hour intervals chosen at random when you create your sync."
The Sync now button does not appear because we can't fully configure the duo sync and select "Groups" until duo gets our group list from the initial sync
also, due to this the SYNC NOW button does not appear
this is undesirable behavior because we would like to complete the duo sync setup in a few minutes and not wait a random time up to 12 hours.
Perhaps in future versions of the release an instant initial sync can be allowed?
Solved! Go to Solution.
08-24-2024 04:27 PM
the sync now should always work... something is wrong in your setup
make sure that director sync show as connected ?
are you using on prem AD or Azure ?
Please show screenshots..
08-24-2024 04:32 PM
Once everything is configured correctly initially, it does an immediate sync, and the sync now button becomes available.
You don't need to wait for 12 hours or any specific time for initial sync to be become available.
So you are probably missing a configuration step.
Once you initially add the ad sync part, you need to add the relevant [cloud] config to the auth proxy config file, and then you may need to restart the auth proxy service. (And verify it starts up.)
If everything's set up correctly at that point, the group selection in the duo portal becomes instantly available.
I've done this a number of times, last time was in July, and you can absolutely finish configuring everything in one session, no need to wait.
In my experience, if there's an issue it's usually one of these 3:
08-24-2024 04:27 PM
the sync now should always work... something is wrong in your setup
make sure that director sync show as connected ?
are you using on prem AD or Azure ?
Please show screenshots..
08-24-2024 04:44 PM
thanks i spent time setting up a new domain in azure and signed up for a duo trial
it all works instantly there with the same settings i have used before
thanks - this one on prem domain must be corrupt even though we were installing the duo proxy on the local dc as i normally do
08-24-2024 04:32 PM
Once everything is configured correctly initially, it does an immediate sync, and the sync now button becomes available.
You don't need to wait for 12 hours or any specific time for initial sync to be become available.
So you are probably missing a configuration step.
Once you initially add the ad sync part, you need to add the relevant [cloud] config to the auth proxy config file, and then you may need to restart the auth proxy service. (And verify it starts up.)
If everything's set up correctly at that point, the group selection in the duo portal becomes instantly available.
I've done this a number of times, last time was in July, and you can absolutely finish configuring everything in one session, no need to wait.
In my experience, if there's an issue it's usually one of these 3:
08-24-2024 04:42 PM - edited 08-24-2024 04:43 PM
"So you are probably missing a configuration step."
definitely not - i just built a new domain on azure and setup a duo trial account and it worked instantly like you described.
i didn't know there are things on AD can that can break it...
must be a corrupt domain etc
i'll just tell the customer to use something else thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide