09-03-2020 12:44 PM
Hey there, folks! We’re doing a little research for an upcoming course series on trust-based access.
0 voters
I’m really looking forward to seeing the results of this one. Want to share more? Let’s talk! Tell us your thoughts in the comments
09-03-2020 03:32 PM
I use the Device Insight tab as an investigation point into the health of devices connecting to our applications. Based on that, I reach out to our Desktop Admin team and they use AutoMox to step up patching for browsers or OS (and automate it moving forward) or make sure our JAMF/GPO deployments are pushing out the Duo Device Certificates. We use the Duo Device Health app to enforce stricter settings for everyone in IT/Cyber Security. CrowdStrike, firewall, encryption, and a high patch level is strictly enforced.
09-10-2020 07:00 AM
@Jason_Waits That sounds like an amazing strategy, thank you for sharing! I’m curious - Do you face any resistance among your end-users when enforcing these? That’s a challenge we hear from a lot of admins. If so, how did you encourage adoption?
09-11-2020 08:32 AM
The only thing we expect of normal end users is to use Duo Push and/or Yubikeys for a single MFA per day. We don’t get much push back there and the tech users appreciate how much faster Duo is than generic TOTP app codes. We only apply the stringent controls with Duo Device Health app to IT and Cyber Security members using, so we haven’t really gotten any push back there either since strict hygiene requirements go with the territory. If we rolled out DHA to a larger audience, I imagine we would get a bit more push back since we’re potentially adding more friction to users lives.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide