cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2299
Views
1
Helpful
3
Replies

Windows Login - Duo only for admin accounts

TravisJ
Level 1
Level 1

Is it possible to roll out protection for all endpoints but only prompt for Duo when users login with an admin account? (domain admin, IT support desk, etc…)?

3 Replies 3

Amy2
Level 5
Level 5

Hi @TravisJ,
I think you can accomplish what you’re after using Duo Group Policy, depending on which edition of Duo you are using today. You’ll need to be on at least Duo MFA edition to make use of Policy Enforcement. Please refer to our documentation for Duo Authentication for Windows Logon (RDP) Active Directory Group Policy here.

You can set up a Group Policy for the roles you would like to prompt for Duo 2FA while bypassing all other users. Read how to do that in the help article here: https://help.duo.com/s/article/3888

Our Policy & Control documentation and Duo Policy Guide may also be useful for you to check out.

TravisJ
Level 1
Level 1

Thank you! That’s exactly what I needed.

sslayton
Level 1
Level 1

What we want to happen:
We want to allow all users to RDP into the system and not have DUO pop up unless they are in one of the configured OU Groups we defined. We do want all users with Admin rights from the defined groups to have to use DUO in order to get in.

Issue we are having:
everything works as planned but with one caveat. If an user has local admin rights on a server but they are not in one of the configured OU groups, they gain access without using DUO. Is there any way for DUO to check servers for local admin accounts and force them to use DUO to gain access even if they are not in a defined group?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Quick Links