Hello Everyone,
we are using Cisco ISE 3.2 for Device Admin. We use local users and Duo for MFA.
We followed this guide:
https://community.cisco.com/t5/security-knowledge-base/duo-mfa-integration-with-ise-for-tacacs-device-administration/ta-p/3882063
our problem is that user's password change at next login works only if we bypass DUO MFA, otherwise if the authentication goes via duo proxy it will always fail and the user can't change their username.
any idea of what can we do to make it work?