DUO is not an idp as such, it is typically integrated with Azure etc. This is unlike OKTA which is, and as such offers the ability to provision users from it. There are sound security reasons why you don't want your MFA to also be your idp, however I appreciate that this makes things more complicated. As such, for labs/demos I tend to use Okta or Azure for simplicity.
James