cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
354
Views
0
Helpful
0
Replies

ISE - Tacacs+ "password change at next login" - Local User w/ Duo MFA

andrea-florio
Level 1
Level 1

Hello Everyone,

we are using Cisco ISE 3.2 for Device Admin. We use local users and Duo for MFA.

We followed this guide:

https://community.cisco.com/t5/security-knowledge-base/duo-mfa-integration-with-ise-for-tacacs-device-administration/ta-p/3882063

 

our problem is that user's password change at next login works only if we bypass DUO MFA, otherwise if the authentication goes via duo proxy it will always fail and the user can't change their username.

any idea of what can we do to make it work? 

0 Replies 0