<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="text-align:left; direction:ltr;">
<div>We're using the admin API to change the Duo username at the same time we change local username. I like your idea, the problem we would have are the other integrations on things like desktops or VPNs, where it wouldn't be able to do the identity translation.</div>
<div><br>
</div>
<div>On Tue, 2021-04-13 at 15:00 -0700, IAM David Bantz wrote:</div>
<blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex">
<div dir="ltr">Is anyone sending a user identifier to Duo MFA different from that used for the password portion of authN?
<div dir="ltr">Is that feasible? Users have been trained to log in with a name-based identifier that of course is subject to change.</div>
<div dir="ltr">An alternative persistent identifier is available from the credential store (an ID #).</div>
<div dir="ltr"><br>
</div>
<div dir="ltr">The hope embodied in my question is that we could avoid the user experience of using their new username to log in,</div>
<div dir="ltr">then having Duo see that as a new user requiring new enrollment.</div>
<div dir="ltr"><br>
</div>
<div dir="ltr">David St. Pierre Bantz</div>
<div dir="ltr">U Alaska</div>
</div>
</blockquote>
</body>
</html>