06-21-2023 03:34 AM
As recommended, I’ve just turned on Verified Duo Push:
But as I turned it on, I spotted the caveat that it needs Universal Prompt activated:
AFAIK, RD Web is waiting on Duo and RD Gateway has no information about universal prompt. Does this mean that RD Gateway pushes are never going to support Verified (PIN) Duo Pushes?
Solved! Go to Solution.
06-21-2023 01:35 PM
The issue with RD Gateway is that by Microsoft’s design there is no UI presented to the end user at all after the RDP client cred submission (which is why that integration today only supports automatic Duo methods like push or phone call). This also means no obvious way to present a UI with the verified push code.
We are doing some research into what’s possible so feel free to contact your Duo account exec or Duo Care manager if you have one to get added to the feature request for verified Duo Push and RD Gateway. If you don’t have one of those contacts, you can reach out to Duo Support.
Another option is to deploy Duo Network Gateway (DNG) to protect external-to-internal RDP connections. DNG does show the full Universal Prompt via the DuoConnect client today.
06-21-2023 01:35 PM
The issue with RD Gateway is that by Microsoft’s design there is no UI presented to the end user at all after the RDP client cred submission (which is why that integration today only supports automatic Duo methods like push or phone call). This also means no obvious way to present a UI with the verified push code.
We are doing some research into what’s possible so feel free to contact your Duo account exec or Duo Care manager if you have one to get added to the feature request for verified Duo Push and RD Gateway. If you don’t have one of those contacts, you can reach out to Duo Support.
Another option is to deploy Duo Network Gateway (DNG) to protect external-to-internal RDP connections. DNG does show the full Universal Prompt via the DuoConnect client today.
06-22-2023 02:10 AM
Doh of course, I actually knew that! Engage brain That’s why I have to stress during training that there is no hint/prompt on screen that RDS/RDP is waiting for you to accept the push. It’s not too bad if you’re using Windows Phone Link to get phone notifications on your PC as that does work.
Anyone know if there is anything on the Microsoft roadmap for allowing customisation of the RDP logon process?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide