01-09-2025 09:13 AM
Hi,
I know the answer but our client wants confirmation from Cisco. Situation is client PC with RDP/Windows Login client using MFA to login to PC. Then the client runs Edge browser to login to Office.com - This is successful with no MFA.
I've told them this is expected behaviour as it's doing pass-thru auth via Edge.
Confirmed with the same situation using Chrome or FF and it prompts for MFA everytime.
They still are requesting either documentation stating this or a response here from Cisco validating this is the case.
Thanks in advance,
01-09-2025 01:42 PM
Did you enable Duo Passport for your customer to achieve the pass through MFA from Duo for Windows Logon to a Duo web app? If so, you should b able to refer them to the Passport documentation.https://duo.com/docs/passport
If you didn't enable Duo Passport, then what you describe doesn't sound entirely expected. What type of Duo config is being used to protect M365? Is it federated with Duo SSO or another identity provider like Okta or AD FS that supplies Duo MFA, or is it cconfigured with Duo's EAM method or Azure custom control in Entra conditional access?
01-09-2025 01:46 PM
Thanks for jumping on Kristina,
No Passport. The PC's have the Windows Desktop (RDP) login app on them and MFA is setup on MS ADFS.
01-13-2025 06:03 AM
Hm, I think you might want to look to Microsoft documentation for support of Edge pass-through behavior that causes it to skip primary and MFA (I guess through an access token)? Maybe in here: https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-identity.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide