12-18-2024 08:11 AM
We have implemented DUO MFA for a year or two.
It works well except we have one issue.
When a user is remote and their account expires it does not allow them to log in.
We used to use RSA token but we authenticated first and then logged in with Windows account info.
With DUO we authenticate the MFA after the log in.
Users will get access denied and we will have to reset them and not force a password change until they are back on prem.
What would we need to implement in order to allow users to change their expired password remotely?
Thanks,
Will
12-19-2024 06:05 AM - edited 12-19-2024 06:05 AM
It's impossible to answer your question unless you specify how you have deployed Duo. Are you using it with some VPN and RADIUS/LDAP, are you talking about an SSO integration, have you installed Duo for Windows Logon, or ... ?
12-19-2024 06:40 AM
12-19-2024 02:14 PM
Where are they trying to change the password? At a Windows system that has Duo for Windows Logon installed, or when they are remoting in via UAG? If you have UAG configured to also use Duo authentication, how did you set that up?
12-23-2024 06:39 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide