Configure Duo as a factor for MFA in ETP

Before you begin

Retrieve the required information from Duo. See Retrieve information from Duo.

You can add Duo multi-factor authentication (MFA) to any ETP identity provider (IdP).

How to

  1. In the navigation menu, select Identity > Identity Providers.
    Note: If you are trying the new Enterprise Center interface, in the navigation menu, select Identity & Users > Identity Providers.
  2. Locate the IdP that you want to configure with Duo or add a new identity provider. To add an identity provider, see Add an identity provider.
  3. In the Settings tab, click Advanced User Authentication.
  4. To enable a global MFA policy, select IdP MFA Policy.
  5. In the MFA Factors area, select Duo. The Duo configuration parameters appear.
  6. Enter the Integration key, Secret key, and API hostname values that you retrieved from Duo.
  7. Select a Duo User ID attribute. Choose one of these attributes:
    • Email
    • SAM account name
    • User Principal Name
    • Domain/SAM account name
  8. Select any other MFA factor that you want to enable.
  9. Click Save.

Next steps

Deploy the IdP. See Deploy configuration changes.