cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4930
Views
1
Helpful
3
Replies

Protect Exchange ECP but not OWA

Dave Packham
Level 1
Level 1

Is there any way to enforce DUO for Exchange admins using ECP but not enforce them for OWA use? or how to only DUO auth the admins AD group when they try to login?

1 Accepted Solution

Accepted Solutions

DuoKristina
Cisco Employee
Cisco Employee

Hi dpackham!

Enforcing two-factor only for Exchange admin access to the ECP IIS site is not a supported use case for the Duo OWA application.

What is possible is to install Duo for OWA and apply a new user policy that lets unenrolled users log in without 2FA, and only enroll the Exchange admins in Duo.

Or, if you need to have all your users enrolled in Duo to protect access to other services, you could apply a group access policy that allows access without 2FA on the OWA application to a group of non-admin users.

Duo, not DUO.

View solution in original post

3 Replies 3

DuoKristina
Cisco Employee
Cisco Employee

Hi dpackham!

Enforcing two-factor only for Exchange admin access to the ECP IIS site is not a supported use case for the Duo OWA application.

What is possible is to install Duo for OWA and apply a new user policy that lets unenrolled users log in without 2FA, and only enroll the Exchange admins in Duo.

Or, if you need to have all your users enrolled in Duo to protect access to other services, you could apply a group access policy that allows access without 2FA on the OWA application to a group of non-admin users.

Duo, not DUO.

Thanks. we will go down the policy route

I forgot to mention that the Exchange admins whom you do require to use Duo MFA will also need to use 2FA on OWA mailbox access as well as ECP.

Duo, not DUO.
Quick Links