Cisco Duo Security Multi-Factor Authentication servers are supported by all the actively supported clients like Connect Tunnel (CT) on Windows/Mac/Linux platforms, and Workplace.
SMA1000 AMC supports this authentication server for admin login and supports user enrollment as well.
Access methods like DeviceVPN, ActiveSync, and Outlook access do not support user-interaction and are forced to authenticate based on Duo's automatic authentication method. This means authentication happens via authentication methods like Push notification or phone call (if available for the user) without any interaction with user. User enrollment is not be supported for those access methods.
After you have integrated and configured SMA1000 with Cisco Duo Security MFA, when you log into clients like CT or Workplace you can:
For example, if you have selected Duo Push and click OK, approve notification is sent to your device.


The workflow depicts the Cisco Duo Security MFA server service for a user :