cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
436
Views
3
Helpful
9
Replies

Can we do SAAS app like Cisco Cloud ES integrate LDAP using Cisco DUO

mshameed123
Level 1
Level 1

Hi 

We have Cisco Cloud email security (CES) solution and need to integrate with On Prem LDAP server. We have cisco DUO and want to integrate it with Cisco CES. i can see that DUO can be integrate with Open LDAP and can use as a Auth source for Cisco CES.

 

My query is can we validate the company recipient email addresses from Cisco CES to cisco DUO and DUO will query it with LDAP server ?

 

9 Replies 9

DuoKristina
Cisco Employee
Cisco Employee

I am not familiar with Cisco CES sign-in, but can tell you that you can set the username attribute for an LDAP authentication through Duo Authentication Proxy to whichever attribute the authenticating application submits as the username. See the description of the username_attribute config option here: https://duo.com/docs/ldap#active-directory

Duo, not DUO.

hello Kristina

thanks for your reply and link. So does Duo   validate the email address for Cisco CES, we want to achieve Directory harvest attack mitigation. In normal scenario when we do a direct integration with LDAP, Cisco CES will query to verify the email address and reject the Inbound mail which has a invalid address.  

We are introducing Duo in between CES and LDAP/Azure AD. this is because we want to allow users to SSO to the spam quarantine portal in CES since customer does not want to spend on Azure AD Domain services

Pulkit Mittal
Level 1
Level 1

I have done CES protection with Duo for many of my customers. Use Single Sign-On for Generic SAML Service Providers | Duo Security.

You will need to normalize username and create group attribute mapping.

If you find this useful, please mark it helpful and accept the solution.

Hi pulkit

thanks for your reply, using username attribute will validate the email address of the user ?

Usename normalisation as email and group attribute mapping will do the job.

Hi,

You would need to configure the list of AD attributes that contain the email addresses for your users. The default is to just search the mail AD attribute values for a match.

 

Hi pulkit

One of my customer has multi-tenant , multi domain environment with O365 and want to utilize the SAML auth option for the User to access SPAM quarantine mails.

 

is it possible to integrate Cisco Duo with multi tenant MS O365 ?

Yes, create another generic application in duo for spam quarantine.

Quick Links