There is nothing you can do in Duo itself to resolve this. The solution is to make sure whatever attribute you're using to find a user i.e. samaccountname or email is unique across forests so that when Duo SSO or the Duo Authentication Proxy performs the ldapsearch for the user using the attribute value which identifies the user it only receives one result.
Duo, not DUO.