cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
601
Views
0
Helpful
2
Replies

How to use DUO to allow for remote users to change their network password?

StavrosK1
Level 1
Level 1

We have some contractors that work remotely and they currently use DUO Mobile - Push for a 2nd factor authentication. We are to require the contractors to change their password after X days have passed.

These contractors only work remotely and never come into the office. How can we allow these remote the ability to change their passwords with DUO?

2 Replies 2

StavrosK1
Level 1
Level 1

I want to say that setting up a new security group for these users and to enable DUO Single Sign on while only allowing specific security groups to use Signle - Sign on may do the trick.

What doe you guys think?

There are a few different options that would allow a password reset. Would not not want other users besides these contractors to be able to change their passwords remotely?

One is, as you found, to set up Duo SSO with Active Directory and proactive password change, and then restrict access to Duo Central to just permitted groups.

Another option could be available through a VPN configuration. If the VPN allows chained primary and secondary authentication then you could point primary auth to AD and just secondary auth to Duo via RADIUS. When a user’s password expires they could reset it through the VPN directly against AD. An example of that config is here: Duo RADIUS Two-Factor Authentication with Password Reset for Cisco ASA SSL VPNs | Duo Security

Duo, not DUO.
Quick Links