I was able to get this type of configuration working by putting ISE in the path between the ASA and the Duo Proxy. ISE is configured to forward RADIUS requests to the Duo Proxy in the Auth policy. The Duo Proxy then process the AD lookup and the user...