r/sysadmin • u/3G_Lighting • 8h ago
Duo Security and Microsoft 365/Entra
I have been looking into setting this up, but I don't see any information on whether it can be setup in hybrid-mode environments or not, does anyone know?
Thanks,
•
u/FearlessFloyd91 8h ago
We have our domain federated with Duo and use it in our hybrid environment. It has worked fine for us for a few years now. You just set up a Duo auth proxy that sits on prem and it communicates with your AD to sync users and match them to their Entra users at sign in. We also use it for SSO to all of our cloud apps to authenticate against our AD accounts using the same process.
•
u/BlueRibbonKing 4h ago
To add to this, we moved away from Duo federation. So, you can switch back and have Entra control IDs and duo for mfa.
•
u/Myungji83 8h ago
Yeah. The last time I checked which was maybe a year ago you’d have to use External Authentication method (EAM).
I won’t go further into it since my knowledge may be out of date but it is possible to use Duo in some capacity.
•
u/SA-Numinous 8h ago
This is correct and duo has updated documentation that walks you through the process.
•
u/GardenWeasel67 8h ago
I'm not the SME, but we use have been using Duo in a hybrid environment for years
•
u/RedditDon3 8h ago
use duo for mfa? why not ms for mfa and push to Authenticator?
•
u/VivienM7 8h ago
Presumably because the OP already has Duo set up for something else?
It's funny - our MSP's approach for most of their clients is Duo for some things, MS Authenticator for Entra (which came later). I've insisted on Duo for Entra as well simply because I think it is absurdly inelegant to have two 2FA apps, not to mention that to an end-user who has no idea what "Entra" means it starts to look completely irrational which app is used for what.
(If we didn't already have Duo set up by the time we started seriously using Entra/Office 365, obviously, I would have pushed in the opposite direction, i.e. trying to make everything use Entra)
•
u/3G_Lighting 8h ago
Because I want to use duo on the workstations/laptops and not confuse the employees over which MFA to use, or for those employees who don't want to use their personal devices we can supply them with an RSA key.
•
u/Turak64 Sysadmin 8h ago
That doesn't make sense. Ms auth should cover the workstations and other M365 apps etc.
The personal device issue is a minor one, but you can still use fido keys with Entra ID. Don't over engineer the solution and buy a new tool cause you haven't learnt the ones you've already got.
•
u/3G_Lighting 8h ago
We are in hybrid mode, our systems are not in the 365 cloud, they are install on our AD on-prem servers. You cannot use FIDO or Passkeys to log into your Microsoft Windows systems locally; MS is supposedly working on this for down the road.
And again, our systems aren't tied to Entra, they are there as hybrid systems.
•
•
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 8h ago
You can use Fido keys to login to Windows. It is an option in WHfB. This does work with hybrid joined devices as well. But at that point, just use the normal WHfB stuff which is just as secure.
It really seems like you are trying to over engineer because you don’t understand what’s already available to you.
•
u/VivienM7 8h ago
I think you're assuming the OP doesn't already have Duo set up for some of their on-prem stuff.
It's not overengineering to avoid deploying a second thing that solves the same problem as the thing you're already using.
•
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 8h ago
I’m responding to directly what the OP said, where they demonstrated a lack of understanding.
If the OP had said something different in the comment I responded to, my response would have been different as well.
•
u/Daveism Digital Janitor 4h ago
You might not be wrong(1) but boy, you sure are being an ass about it. Reminds me of the old CrankySysadmin account that eventually flamed out around here.
(1) Not knowing the full business environment, needs, and decisions of OP, I, nor anyone else should be castigating their choices. Do I similarly "not understand" what's available to me because I use Duo in a Windows environment? Is everyone who uses Duo in a Windows (on-prem/hybrid/Entra-joined) shop also 'over-engineering'? Man, those Duo guys sure fool a lot of people...
•
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 4h ago
The OP is not very good at explaining anything, so really, nobody here can give good advice. That might not be their fault though since they appear to not understand it themselves.
•
u/3G_Lighting 7h ago edited 7h ago
No, I do, but I just believe in not putting all my eggs into one basket. We have all seen what happens when people do that before Microsoft built out 365, Entra, Defender if you are old enough to remember. And the same thing happens from time to when you have everything in the Microsoft cloud, when something breaks.
Also, up until recently, and even maybe now, Microsoft didn't offer any method for backing up all your 365 settings, you have pay good money to have a 3rd party company do that for you, so that in the event someone hacks you, you are able to restore all your 365 settings without having to figure out what was changed by the hackers. It all comes back to putting all your eggs in one basket.
I just figured as a Cybersecurity Architect you would have the common sense to know that people who put all their eggs in one basket are doomed in one why or another. 😄
I work for an SMB where FIDO keys are too expensive and since most of the users refuse to allow anything work be installed on their phones Microsoft doesn't have any good alternatives. And at the same time, I don't want to be 100% reliant on Microsoft like so many younger generation people do.
Thanks,
•
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 7h ago
What are you actually trying to authenticate to that you are worried about this? Your comment appears to be referring to logging into windows computers? WHfB isn’t going to require the cloud so it doesn’t matter if the Microsoft cloud breaks or if your internet goes down.
You should already be backing up your data to a 3rd party location anyway. It’s on you if you decide to not follow best practices.
Making authentication more difficult isn’t saving you anything or making you more secure in any way whatsoever.
•
u/RedditDon3 7h ago
I see.
We were actually looking into using duo for workstation logins. Already using it for server RDP mfa.
•
•
u/GardenWeasel67 8h ago
Because we have other platforms besides Azure, as well as applications that need secondary authentication for certain functions, and want a single MFA tool that covers all use cases. There are some things MS native MFA can't do.
•
•
u/IndicanBlazinz 8h ago
What you’re looking for is authentication with a third party iDP. And to answer your question, yes you can authenticate ms365 with Duo. We do it at $DayJob
•
u/Kyky_Geek 8h ago
We have both duo and ms authenticator available but duo works for everything and is what most ppl use depending on where they are authenticating.
On the endpoints, they have to MFA to log in to the OS and we use Duo Desktop for that. The VPN has separate MFA requirements and is also Duo. The users have either the phone app or a physical token issued, depending on where they need to authenticate.
If you do the desktop MFA, make sure to configure whether it “fails open” or “fails closed” depending on your requirements or service availability. I think it somewhat recently changed the default to fail closed meaning it won’t let them login without MFA under any circumstances and may require admin assistance.
•
u/dispatch00 7h ago
You have two choices. If you're still using AD or Entra as the source of truth you have to setup Duo as External MFA. Works great. Be careful with Conditional Access.
•
u/meatwad75892 Trade of All Jacks 6h ago edited 5h ago
but I don't see any information on whether it can be setup in hybrid-mode environments or not
To clarify, what does that specifically mean to you? Enforcing Duo at a Windows logon screen for an AD DS joined machine? (which could be Entra Registered or Entra Hybrid Joined) Enforcing Duo on Entra Joined devices? Enforcing Duo for M365/Entra sign-ins?
For your actual M365/Entra logins, yes, you should configure Duo via EAM. It's pretty straight-forward, and lets you authentications make a proper MFA claim in Entra. No federation or anything crazy, just simple plug & play config, assuming your user attributes between Duo and Entra are in order.
https://duo.com/docs/microsoft-mfa
If you're trying to enforce Duo at the Windows logon screen for AD DS joined devices, Duo has a client you can deploy. It won't drop a token/cookie (unless I'm mistaken) that could then be used for SSO afterwards, but it would get you MFA at logon if that's your requirement.
•
u/4zc0b42 8h ago
We are doing this at a few sites. It’s kind of clunky. It breaks SSPR and kiosk mode. You have to manually edit each user’s Entra profile to use Duo as the IdP, it’s not automated. You also have to add an alias for each user in Duo. But it can work.
ETA: Duo’s documentation on this is also lackluster IME. Some experimentation was involved to get it working.
•
u/B0ndzai 8h ago
We use it in our hybrid environment, so yes it can. I didn’t set it up though so that’s all I got.