<p dir="ltr">Our self opt-in process simply adds the user to an AD group (via grouper web services) that is sync'd using Duo's DirSync and simultaneously creates the user via the Admin API to deal with propagation delay of DirSync. Then we send the user to a protected service (their Google email) and use Duo's in line self enrollment for the user to add devices. Later when DirSync runs, it pairs up to the user that was forced in via API and they are managed via DirSync going forward. Not overly complex so I'm not sure its worth sharing, but we could.</p>
<p dir="ltr">In a different vein, i'd be curious if you'd be willing to share how you selectively trigger 2FA via Duo on the shibb logon page?</p>
<p dir="ltr">Rob</p>
<div class="gmail_quote">On Apr 12, 2016 7:49 PM, "IAM David Bantz" <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Users who opt in to use of 2FA here receive a directory attribute indicating allowed authN context, in turn consumed by our IdP to trigger 2FA via Duo.  For initial use, I've just been pasting in a value in the directory, but it's time to deploy a self-service opt-in web form.  I know many of you must have deployed something of the sort. If you have and are willing to share, please do.<div><br>Thank you,</div><div>David Bantz</div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div>