08-19-2024 11:51 AM
I just wanted to know if there were other organizations that are facing similar issues with the MFA requirement for CJI assessing devices. https://www.police1.com/cybersecurity/3-ways-to-meet-the-new-cjis-mfa-requirements
We have a department trying to implement this change with certain workstations. We are trying Duo authentication for Windows logon and facing a couple dilemmas given the connection type with some of these (some being internet connect, others not as such). We've looked at Duo tokens and Yubikeys which seem to work alright. It will create a challenge of users keeping up with it (if they don't utilize the Duo app). Will tokens only work on online devices? Is there any way to set up a proxy to bypass the use for this?
Just wanted to see if anyone was in a similar predicament or had suggestions before the Oct 1 deadline.
08-19-2024 06:14 PM
you can use a proxy for windows login.. you have to configure it.
08-20-2024 07:04 AM
08-20-2024 10:17 AM
The HTTP proxy support in Duo for Windows Logon is intended for the use case where you have Windows systems on a limited-access network that does not have direct outbound access to Duo's cloud service, but that limited-access network does have persistently available access to an HTTP proxy on an accessible, adjacent network and can therefore proxy out requests to Duo's cloud service via the upstream HTTP proxy.
This is not a solution for an individual Windows system that sometimes has no connectivity to the internet nor to any HTTP proxy on an accessible network.
For Windows systems that experience temporary periods without connectivity to Duo's service, we added support for offline logins: https://duo.com/docs/rdp#offline-access. The way this works is that users are able to enroll an offline 2FA factor (The Duo Mobile app or a U2F security key) for that specific Windows system, and can use that to log in when the system has no connectivity to Duo's cloud service.
The offline access feature isn't intended as a solution for persistently disconnected Windows systems as it does require a periodic refresh of offline policy.
Yubikey OTP (passcode-generating) hardware tokens only work for **ONLINE** Duo Windows logins, not for offline Duo Windows logins. But, you can get a Yubikey that does both OTP and U2F and be able to use it for both online and offline 2FA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide