Secure Mobile Access 12.5 Administration Guide

Table of Contents

Enrolling users for Cisco Duo Security MFA Server

SMA1000 allows users to enroll their devices with Cisco Duo Security Multi-Factor Authentication during login.

Users who are not added to Cisco Duo Security MFA server on admin portal or for users who are added at the server but without any devices attached, can be allowed to enroll their devices for MFA during login. For the users who already have a device (phone or token), irrespective of whether they are in-possession or lost, will not see the enrollment option. In case if a phone is lost, the user must reach the admin to remove the lost device from Duo admin portal so that the user can see the enroll option during next login.

To configure new user enrollment with Cisco Duo Security MFA, do the following

  1. In the AMC, navigate to System Configuration > Authentication Servers > Cisco Duo Security MFA.

  2. Under the User Enrollment section, choose the following enrollment methods for the users:

    Enrollment method Description
    Display a link to the Duo Security portal
    • User can enroll their mobile phone number to avail Push notification, mobile code, Phone call, text message and other OTP methods.
    • After enrollment, user can continue with Duo MFA authentication.

    This option is enabled by default.

    Show QR code during first login
    • New users are shown a QR code that can be scanned using Duo mobile app. This associates the mobile with user account.
    • User can enroll for push and mobile code authentication methods.
    • After enrollment, user can continue with Duo MFA authentication.
    Do not prompt users to enroll during the login process Users who are not enrolled with Cisco Security Duo MFA server will not be able to log in to SMA.
  3. Select additional authentication methods for users to enroll the devices. See Additional Authentication Methods