08-15-2023 07:53 PM - edited 08-15-2023 07:59 PM
We use Duo Access Gateway with on-prim AD for authentication with Microsoft 365. We want to switch to using Azure AD Conditional Access with Duo MFA. I followed the instructions for setting up Conditional Access here: https://duo.com/docs/azure-ca
Sets followed
However, when I go to https://login.microsoftonline.com/ and attempt to sign in it redirects me to the Duo Access Gateway instead of using Microsoft login.
Running what-if confirms it picks up the expected Conditional Access Policy.
Does anyone have a suggestion on how to correct it?
Solved! Go to Solution.
08-16-2023 06:09 AM
As long as your Azure custom domain is federated a sign in with a federated user will redirect to the federated IdP.
You could test the conditional access policy with an Azure cloud-only user and then when you are ready to make the switch revert your federated domain back to "managed".
How do I defederate Office 365 from Duo SSO, Duo for AD FS, or Duo Access Gateway?
If you want to know the detailed effects of converting a federated domain back to managed please contact Microsoft support.
08-16-2023 06:09 AM
As long as your Azure custom domain is federated a sign in with a federated user will redirect to the federated IdP.
You could test the conditional access policy with an Azure cloud-only user and then when you are ready to make the switch revert your federated domain back to "managed".
How do I defederate Office 365 from Duo SSO, Duo for AD FS, or Duo Access Gateway?
If you want to know the detailed effects of converting a federated domain back to managed please contact Microsoft support.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide