cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4096
Views
4
Helpful
16
Replies

Microsoft Mandatory MFA - Using DUO

bjames
Level 5
Level 5

So I keep getting the notice from Microsoft they will mandate MFA for Azure, etc. by Oct, 15th. We are currently using Duo for MFA to 365/Azure/etc. It seems like Microsoft is pointing to their Authenticator app for MFA, Is there a way we can insure it accepts Duo after their push to MFA?

Their documentation does really show a way to use a third party app, has Duo already tackled this issue?

 

Thanks in Advance

16 Replies 16

DuoKristina
Cisco Employee
Cisco Employee

For those confounded by current product limitations on either side or feeling pressured by the deadline: I found postponing the MFA enforcement to March to be pretty painless. I did it in three tenants, so signing in three times was the hardest part.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication#request-more-time-to-prepare-for-enforcement

We understand that some customers may need more time to prepare for this MFA requirement. Microsoft is allowing customers with complex environments or technical barriers to postpone the enforcement for their tenants until March 15, 2025.

Between August 15, 2024 and October 15, 2024, Global Administrators can go to the Azure portal to postpone the start date of enforcement for their tenant to March 15, 2025. Global Administrators must have elevated access before postponing the start date of MFA enforcement on this page.

Global Administrators must perform this action for every tenant for which they would like to postpone the start date of enforcement.

By postponing the start date of enforcement, you take extra risk because accounts that access Microsoft services like the Azure portal are highly valuable targets for threat actors. We recommend all tenants set up MFA now to secure cloud resources. 

Duo, not DUO.

mleather
Level 1
Level 1

We setup DUO EAM and yet our Microsoft Secure Score is still indicating the all of our users with admin roles are not registered for MFA, as per the requirement, however they are and it does prompt for Duo via EAM when they sign in. What am I missing here?

Quick Links