Secure Mobile Access 12.4 Administration Guide

Additional Authentication Methods

In addition to the methods that are available with user devices, SMA1000 can authenticate users using a Cisco Duo Security MFA bypass code or codes already obtained in a batch via SMS.

The batch code and bypass code options are configurable by admin as they are available in SMA1000 AMC.

If these options are disabled, users will not see option to enter bypass codes and batch codes during login. Enable these only if application policy under Duo admin portal is configured to allow bypass codes and batch codes.

To use additional authentication methods do the following

  1. In the AMC, navigate to System Configuration > Authentication Servers > Cisco Duo Security MFA.

  2. Under the Additional Authentication Methods section, select the following options:

    Enrollment method Description
    Prompt users to enter codes from current SMS batch Enable if SMS batch size is more than one under Duo SMS passcode settings
    Prompt users to enter bypass codes Enable if bypass codes are available to users
  3. Click Save.

Some notes on Cisco Duo Security MFA server:

  • Cisco Duo Security MFA sever can only be added as secondary authentication server under a realm.
  • During user login, username entered by the user for primary server authentication should match with the username enrolled with Duo.

  • If the format differs, for example when username entered by the user is "user@example.com" but Duo server lists just "user" without any domain name, change the "Username normalization" setting to "Simple" under application policy on Duo admin portal.

  • Connect Tunnel clients installed on user devices should be upgraded to 12.4.3 and above for them to support Duo MFA server.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden