SMA1000 allows users to enroll their devices with Cisco Duo Security Multi-Factor Authentication during login.
Users who are not added to Cisco Duo Security MFA server on admin portal or for users who are added at the server but without any devices attached, can be allowed to enroll their devices for MFA during login. For the users who already have a device (phone or token), irrespective of whether they are in-possession or lost, will not see the enrollment option. In case if a phone is lost, the user must reach the admin to remove the lost device from Duo admin portal so that the user can see the enroll option during next login.
To configure new user enrollment with Cisco Duo Security MFA, do the following
In the AMC, navigate to System Configuration > Authentication Servers > Cisco Duo Security MFA.
Under the User Enrollment section, choose the following enrollment methods for the users:
| Enrollment method | Description |
|---|---|
| Display a link to the Duo Security portal |
This option is enabled by default. |
| Show QR code during first login |
|
| Do not prompt users to enroll during the login process | Users who are not enrolled with Cisco Security Duo MFA server will not be able to log in to SMA. |
Select additional authentication methods for users to enroll the devices. See Additional Authentication Methods