SMA1000 allows users enroll with Cisco Duo Security Multi-Factor Authentication.
This procedure is only for the users who are not added to Cisco Duo Security MFA server on admin portal or for users who are added at the server but no devices attached. For the users who already have a device (phone or token), irrespective of whether they are in-possession or lost, will not see the enrollment option. In case if a phone is lost, the user must reach the admin to remove the lost device and so that the user can see the enroll option during next login.
To configure new user enrollment with Cisco Duo Security MFA, do the following
In the AMC, navigate to System Configuration > Authentication Servers > Cisco Duo Security MFA.
Duo MFA authentication fails if appliance clock is incorrect. Synchronize with NTP server to avoid Duo MFA authentication failures.
Under the User Enrollment section, choose the following enrollment methods for the users:
| Enrollment method | Description |
|---|---|
| Display a link to the Duo Security portal |
This option is enabled by default. |
| Show QR code during first login |
|
| Do not prompt users to enroll during the login process | Users who are not enrolled with Cisco Security Duo MFA server will not be able to log in to SMA. |
Select additional authentication methods for users to enroll the devices. See Additional Authentication Methods