ECP on an idp configured for MFA
Phil Pishioneri
pgp at pSu.edu
Thu Feb 21 15:08:05 EST 2019
On 2019/2/19 8:59 PM, Paul B. Henson wrote:
> While I have both a token and a phone on my duol account, I have it configured to auto push to my phone. So it worked okay for me; but a lot of our users have only been issued a hardware token and don't necessarily set up their own phone. How does the Duo ECP support work if somebody needs to enter a passcode as part of the authentication? The documentation isn't very clear other than seeming to indicate it is possible?
If you can configure ECP to use LDAP BIND for authentication (with a
separate LDAP server if you're already doing that), I suppose you could
point the IdP to a Duo LDAP proxy, which would allow specifying a
password of the form
password + "," + duo-passcode
See <https://duo.com/docs/ldap#test-your-setup>, but then there's
problem of explaining that technique. (And then you'd not do MFA for ECP.)
-Phil
More information about the users
mailing list