alternate userids in IdP's MFA?
Michael Brogan
mbrogan at uw.edu
Wed Apr 14 03:20:34 UTC 2021
You could also use the Duo alias feature to support more than one userID for a Duo account. We have use cases at the UW that rely on this functionality. We also have a second set of use cases that interact with a local API rather than Duo directly and that API has its own mapping of netids to Duo accounts. Either way, the netid for password authentication can be different from the Duo account used for MFA.
--Michael
From: users <users-bounces at shibboleth.net> On Behalf Of Richard Frovarp via users
Sent: Tuesday, April 13, 2021 3:06 PM
To: users at shibboleth.net
Cc: Richard Frovarp <richard.frovarp at ndsu.edu>
Subject: Re: alternate userids in IdP's MFA?
We're using the admin API to change the Duo username at the same time we change local username. I like your idea, the problem we would have are the other integrations on things like desktops or VPNs, where it wouldn't be able to do the identity translation.
On Tue, 2021-04-13 at 15:00 -0700, IAM David Bantz wrote:
Is anyone sending a user identifier to Duo MFA different from that used for the password portion of authN?
Is that feasible? Users have been trained to log in with a name-based identifier that of course is subject to change.
An alternative persistent identifier is available from the credential store (an ID #).
The hope embodied in my question is that we could avoid the user experience of using their new username to log in,
then having Duo see that as a new user requiring new enrollment.
David St. Pierre Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210414/7a49ae1e/attachment.htm>
More information about the users
mailing list