If the username you specify doesn’t already exist in Duo, but matches the value of the source directory attribute you configured as the username attribute for the sync, it will create the user.
- Create new user
kav in AD and make the user a member of the group configured in the Duo AD sync.
- Run an individual sync from the Admin Panel or with the Admin API for username
- Sync finds
kav in the source AD directory and imports that new user into Duo. The API response indicates the user was added and includes the new user’s Duo values.
From the AD Sync info linked from the description of the sync user API endpoint:
When initiated, the individual user sync verifies that each specified user is a member of a group currently synced with Duo and then imports information for that user into Duo. If a specified user doesn’t already exist in Duo, the sync creates them using the information imported from the source directory.
If you don’t know the new username though, you can’t specify it during an individual sync. If that’s your use case, you might be interested in a delta sync (to only import changes, as opposed to a full sync). Please contact your Duo Account Executive or Customer Success Manager (if you have one) or Duo Support (if you don’t) to add your support for the delta sync feature request, or for the feature request for management of full sync via Admin API (if that interests you as well).