Skip to main content

Duo Authentication for Windows Logon Deployment

Summary

These custom fields are required for the "Duo Authentication for Windows Logon" deployment.

Dependencies

Details

NameLevelTypeRequiredEditableDefault Value?Description
DUO Autopush OvrrEndpointTextFalseYes<Blank>If set to "Yes," this option will automatically send a push request to the endpoint when the user attempts to log in. The default value is blank, requiring the user to request the push manually. Note: It overrides the company's custom field value.
DUO Autopush ServerCompanyTextFalseYesNoIf set to "Yes," this option automatically sends a push request to the company servers when the user attempts to log in. The default value is No, requiring the user to request the push manually.
DUO Autopush WksCompanyTextFalseYesNoIf set to "Yes," this option will automatically send a push request to the company workstations when the user attempts to log in. The default value is No, requiring the user to request the push manually.
DUO EnableOffline OvrrEndpointTextFalseYes<Blank>If set to "Yes," it will control whether offline access is permitted on the endpoint. Note: The default value is blank. It overrides the company's custom field value.
DUO EnableOffline ServerCompanyTextFalseYesNoIf set to "Yes," it will control whether offline access is permitted on servers. In the context of Duo, offline access allows users to authenticate without a real-time connection to Duo’s service, usually by using previously generated passcodes or other offline authentication methods.
DUO EnableOffline WksCompanyTextFalseYesNoIf set to "Yes," it will control whether offline access is permitted on workstations. In the context of Duo, offline access allows users to authenticate without a real-time connection to Duo’s service, usually by using previously generated passcodes or other offline authentication methods.
DUO Failopen OvrrEndpointTextFalseYes<Blank>This determines the behavior when Duo’s service cannot be reached. If set to "Yes," the system will allow the user to log in to the endpoint (fail open). If set to No or left blank, the system will deny access (fail closed). Note: It overrides the company's custom field value.
DUO FailOpen ServerCompanyTextFalseYesNoThis determines the behavior when Duo’s service cannot be reached. If set to "Yes," the system will allow the user to log in on company servers (fail open). If set to No or left blank, the system will deny access (fail closed). The default is to fail open.
DUO FailOpen WksCompanyTextFalseYesNoThis determines the behavior when Duo’s service cannot be reached. If set to "Yes," the system will allow the user to log in on company workstations (fail open). If set to No or left blank, the system will deny access (fail closed). The default is to fail open.
DUO RDPOnly OvrrEndpointTextFalseYes<Blank>When set to "Yes," Duo authentication is required only for remote logins via RDP on the endpoint. The default is blank, meaning Duo protects both. Note: It overrides the company's custom field value.
DUO RDPOnly ServerCompanyTextFalseYesNoWhen set to "Yes," Duo authentication is required only for remote logins via RDP on company servers. If set to No or left blank, Duo authentication is required for both console and RDP logins. The default is No, meaning Duo protects both.
DUO RDPOnly WksCompanyTextFalseYesNoWhen set to "Yes," Duo authentication is required only for remote logins via RDP on company workstations. If set to No or left blank, Duo authentication is required for both console and RDP logins. The default is No, meaning Duo protects both.
DUO SmartCard OvrrEndpointTextFalseYes<Blank>If set to "Yes," it allows smart card login as an alternative to Duo authentication on the endpoint. The default is blank, which does not allow smart card login without Duo approval. Note: It overrides the company's custom field value.
DUO Smartcard ServerCompanyTextFalseYesNoIf set to "Yes," it allows smart card login as an alternative to Duo authentication on company servers. If set to No or left blank, it disables the Windows smart card provider. The default is No, which does not allow smart card login without Duo approval.
DUO Smartcard WksCompanyTextFalseYesNoIf set to "Yes," it allows smart card login as an alternative to Duo authentication on company workstations. If set to No or left blank, it disables the Windows smart card provider. The default is No, which does not allow smart card login without Duo approval.
DUO Windows Login HostCompanyTextTrueYes<Blank>HOST Key for Duo Deployment
Duo Windows Login IKEYCompanyTextTrueYes<Blank>IKEY Key for Duo Deployment
Duo Windows Login SKEYCompanyTextTrueYes<Blank>SKEY Key for Duo Deployment
Duo DeploymentCompanyFlagFalseYesNoIf this checkbox is set, then the agents of the company will be added to the group for the DUO deployment. Note: Any agent with the "DUO Deployment Exclude" custom field selected will be excluded.
Duo Deployment ExcludeEndpointFlagFalseYesNoIf this checkbox is set, then the agent will be excluded from the group for the DUO deployment.
DUO Deployment ResultEndpointTextFalseNo<Blank>This stores the DUO Deployment result of "Success" or "Failure" based on the script "DUO Install & Upgrade - Latest Version" result.

Steps to Create Custom Fields

  1. Go to Settings > Custom Fields
    Step 1

  2. Click Add option
    Step 2

  3. Create Custom Field
    Provide Name: DUO Windows Login Host
    Select Level: Company
    Step 3
    Then check the Type option:
    Type: Text Box
    Step 3 Type
    Then provide Default Value and Description:
    Default:
    Description: HOST for Duo Deployment
    Editable: Yes
    Step 3 Default Value
    Note: The description is mandatory to be filled and it doesn't accept 'NEW LINE'. Write everything in one phrase to describe the detail of the custom field.

  4. Please follow the same steps to create other custom fields.