Duo to satisfy MFA requirement

0KAY 20 Reputation points
2024-08-20T12:11:57.42+00:00

We currently use Duo for MFA and Microsoft does not recognize it as a form of MFA. Does this mean that when enforcement of MS MFA takes place in October that our users will have to perform MFA twice, once through Duo and then through Authenticator as well? This would be less than ideal, however we need to know this ahead of time to plan properly.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,834 questions
0 comments No comments
{count} votes

Accepted answer
  1. Raja Pothuraju 10,760 Reputation points Microsoft Vendor
    2024-08-20T17:45:11.24+00:00

    Hello @0KAY,

    Thank you for posting your query on Microsoft Q&A.

    From your description, I understand that you’re referring to the recent announcement about MFA enforcement, particularly the mandatory multifactor authentication for Azure and other administration portals starting on October 15, 2024. You’re asking whether this enforcement will support third-party MFA providers like DUO.

    If you’re using a third-party MFA provider (DUO) for second-factor authentication and have configured it through the Conditional Access Custom Controls preview, it will not satisfy the new MFA requirements. To continue using your external solution with Microsoft Entra ID, you should migrate to the External Authentication Methods (EAM) preview.

    If your DUO MFA is already configured through the External Authentication Methods preview, it will support the upcoming MFA enforcement requirements.

    You’ll need to verify how your DUO configuration is set up in your tenant—whether it’s configured through Custom Controls (Preview) or External Authentication Methods (Preview).

    Please refer to the screenshot below for guidance on verifying the configuration.

    If your DUO MFA is set up through Custom Controls (Preview), you can find it under Entra ID > Security > Conditional Access > Custom Controls (Preview).

    User's image If your DUO MFA is set up through External Authentication Methods (EAM) Preview, it will be visible under Entra ID > Security > Authentication Methods > Policies > External (Preview).User's image

    Please verify your setup. If it’s not configured under the External Authentication Methods blade, refer to the following document for instructions on setting up your MFA, and contact DUO support for the required details.

    Additional Resources:

    For more information, please refer to the following articles.

    Planning for mandatory multifactor authentication for Azure and other administration portals

    Manage an external authentication method in Microsoft Entra ID (Preview)

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Raja Pothuraju.

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.