01-09-2025 10:06 AM - edited 01-10-2025 06:22 AM
We have an application setup for our Microsoft Entra ID (External Authentication Methods)
It appears that all regular users get pointed to the universal prompt for DUO when signing in.
The administrators in Entra get a microsoft landing page that looks like DUO.
The prompt comes from login.microsoftonline.com instead of api-xxxxxx.duosecrity.com.
I also notice when an admin logs into Entra ID or an application that SSO is pointed to Entra, there is not a log of that in DUO.
If I go to my user in the log, I see VPN application and nothing from the Entra ID application.
Almost as if it's not hitting DUO at all.
I am assuming this is from the new MFA requirements that microsoft put out for administrators.
I am thinking my set up may be wrong somewhere?
Additional note: we only have 50% of our users enrolled in DUO, so the Conditional Access policy is based on a group "EnrolledDUO", so not sure if it's a setting I missed with setting exemptions?
Anyone have insight? DUO Support said its on the microsoft side and cant really help with that.
I also reviewed these articles and didn't see anything that I missed.
https://help.duo.com/s/article/8915?language=en_US
https://duo.com/docs/microsoft-eam
https://duo.com/docs/azure-ca
01-09-2025 01:03 PM - edited 01-09-2025 01:03 PM
>Almost as if it's not hitting DUO at all.
That is exactly what's happening.
That screenshot is Microsoft's own MFA asking for a code from the MS Authenticator app. The MFA request captured in the image is not coming from Duo, therefore you do not see that activity in Duo logging.
Have you reviewed the information in https://help.duo.com/s/article/7591? My guess is the Entra security defaults are requiring that your admins use Microsoft MFA.
01-09-2025 01:35 PM
we found that are a couple of other places where MS authenticator could be used even if under CA it is disabled... i dont have a azure account handy.. but check under MFA at user level and you should be able to reset it... That is not in the DUO document..
01-10-2025 06:19 AM
Thank you both for replying.
I have checked the per user authentication and it is disabled.
I also checked under "Authentication Methods" for devices registered, and there were none.
Additionally, I got to a point where I could click "login in other ways" on the Microsoft page. This allowed to me to login to DUO.
Under that I see the link to https://aka.ms/mfasetup. I removed two tokens that were stored in there. After I removed those, I no longer go to the first prompt where it asks me for "login in other ways"
However, It still doesn't go straight to DUO either.
Once I click to approve it with Cisco DUO, it brings me to the typical DUO universal prompt and the URL changes.
Any more ideas?
It it is working and connecting, just adding an extra step.
01-10-2025 06:49 AM
After re-reading this article and scrolling down to the "Test your Setup" section, it appears this extra step is expected?
Can anyone confirm this?
https://duo.com/docs/microsoft-eam
01-10-2025 12:26 PM
Yes, for now the experience offered by Microsoft for external authentication methods requires that extra step. We have been told they plan to improve this in the future.
01-10-2025 06:45 PM
DuoKristina, you are a cisco employee and i think part of Duo (not DUO) team , it would great if you can take it up with the Duo doc team to update the documentation to cover these scenarios.
01-13-2025 05:47 AM
What exactly do you mean?
It's been a moving target with MS too.
01-13-2025 05:03 PM
what i meant is that your document is missing a few cases where it doesnt switch to DUO... even if you disable MS completely in CA, there may user level or like this post, where it didnt come up right away.. it would be good to document these.
01-10-2025 01:27 PM
It is expected when you have existing users who already MFA set up.. i have seen different behaviors with different users... some had user level auth enabled.. and the other one you mentioned... It would be good for the document to include those nuances.... we also spent a bit of extra time to figure this out.
**Please rate helpful if this was useful**
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide