How to Enable MFA on Windows Logon with DUO

Поделиться
HTML-код
  • Опубликовано: 24 июл 2024
  • I talk on my channel about enabling multi-factor authentication for cloud services such as Microsoft 365. But have you ever considered MFA for logging onto your computer? Can you even do this? Yes, you can by using a product called DUO.
    I will show you how in today's video.
    00:00 Introduction
    00:40 What is MFA?
    02:35 How to Configure DUO for Windows Logon
    03:53 Enroll with DUO Security
    05:30 Protect an application in DUO
    07:04 Install DUO software on a Windows computer
    #microsoft365 #twofactorauthentication #duo
    --------
    So who am I and what do I do?
    I am an IT expert with over 20 years of industry experience across a multitude of different areas. I am the Founder & Managing Director of Integral IT. Our mission is to deliver IT services that bring real value to each and every one of our customers, no matter how big or small.
    If you need IT support, we can help. We can help you wherever you are in the world; you just need an internet connection.
    Contact Us Today ► hello@integral-it.co.uk
    www.integral-it.co.uk/
    -- Make Sure To Follow Me On My Socials Below --
    ► INSTAGRAM: / jonathanedwardsit
    ► FACEBOOK: / jonathanedwardsit
    If you have any video ideas, or if you'd like me to make a video on anything specific make sure to let me know in the comments below!

Комментарии • 70

  • @arnabkoley8864
    @arnabkoley8864 11 месяцев назад +1

    It's too easy man, thank you so much for this very important video

  • @CircleRed3
    @CircleRed3 2 месяца назад +1

    Well done demonstration!

  • @faheemvs43
    @faheemvs43 6 месяцев назад +1

    Wow
    Excellent video, thank you!

  • @ChristianPauly
    @ChristianPauly Год назад

    Thanks Jonathan. Great tutorial.

  • @jacarts2793
    @jacarts2793 Год назад +1

    Thanks for the video. Very useful. Oddly, I find you more understandable with playback speed set to 1.25.

  • @LionRelaxe
    @LionRelaxe 2 года назад

    Well made video, thanks!

  • @roberton6977
    @roberton6977 10 месяцев назад

    Thanks for the video. It is beneficial

  • @gtoramirez
    @gtoramirez Месяц назад +1

    I’ve been binging all your videos while improving my environment. Thank you 💯.
    Can you make a video like this for install on Mac?

  • @malamdikereta
    @malamdikereta Год назад

    Thanks Jonathan. Straight forward and useful.

  • @codyappell24
    @codyappell24 7 месяцев назад +1

    I’ve got a question regarding the device setup. It looked like when you logged in at the end there was a drop down arrow to have the authentication sent to a different other than the iOS device you setup in the video. Would this be possible to set up with additional devices? Say you have an iPhone and an iPad and wanted to authenticate with either or (say your phone is charging in another room and you’re too lazy so you use your iPad next to you?) That would be convenient for what I am looking for in an Authenticator program.

  • @aldehc99
    @aldehc99 Месяц назад

    Thank you very much, I was freaking out trying to figure out the non-enrolled error, turned out to be the a mismatch between the username I was using in Duo vs the one used to login to the domain-joined pc vs the username stored in the pc as you pointed out.

  • @cptlatham6126
    @cptlatham6126 Год назад

    This was really helpful to get my first Duo 2FA set up, but I'm struggling to set up my other computers. Is it possible to link multiple computers to a single Duo user?

  • @jamstonuk
    @jamstonuk Год назад +1

    Great video Jonathan. I was looking forward to implementing this for our company. We use complex passwords for our MS365 accounts so users use a PIN or fingerprint for Windows login (Windows Hello). For me, being able to login with just a PIN isn't ideal which is why DUO sounded a great option. However I've just realised that DUO doesn't currently support Windows Hello at this time which is a big disappointment 😥

    • @bearded365guy
      @bearded365guy  Год назад

      Yes, it is!

    • @jamstonuk
      @jamstonuk Год назад +1

      @@bearded365guy With you being a DUO partner have you heard whether it's something they are maybe looking at in the future? I'm guessing there's some technical issues behind the scenes seen as though Microsoft don't even offer this! ☺

  • @ytthumbnailcreator9224
    @ytthumbnailcreator9224 2 года назад

    🔥

  • @TheCamdenboyz
    @TheCamdenboyz Год назад

    How would we be able to mix duo and non duo users on a single box?

  • @DJ_Driven
    @DJ_Driven 2 месяца назад

    Hi Jonathan,
    I'm struggling right now to get Duo implemented on some Microsoft Surface Pro X tablets for customers as showing Non-compatibility with the Arm 64 -bit processor. Was trying to work around this through M365 portal. So far still working on a solution to meet compliance regulations. If you have any recommendations please let us know.

  • @AYCHMENG
    @AYCHMENG Месяц назад

    do you know how I can add the Windows Hello feature to duo security?

  • @jonsmallwood1657
    @jonsmallwood1657 Год назад

    Stupid question. Does DUO accomplish this irregardless of the Microsoft License associated with the account? Kiosk, Plan 1, E3, P1/P2, etc. Since it has to be installeded locally to accomplish the MFA. Second question, is there a "tamper proof" setting to prevent the user from removing Duo from the PC?

    • @bearded365guy
      @bearded365guy  Год назад

      Yes, you can have MFA with any Microsoft license, so DUO will work. We recommend that users don’t have local admin access to their computers so they can’t go in and uninstall anything.

  • @Pendragon501
    @Pendragon501 Год назад

    Can DUO be setup so only specific user account in AD are forced to use DUO when signing on to any computer on the domain?

    • @codyappell24
      @codyappell24 6 месяцев назад

      Did you ever find an answer to this? I’m in need of seeing something up at work and settled on this but I’m lost.

    • @Pendragon501
      @Pendragon501 6 месяцев назад

      For cyber security insurance reasons, I setup and installed the DUO Windows login for specific computers used by people with privileged AD accounts. Unfortunately it's required for anyone that signs into that computer, Not just specific accounts. But I also now have DUO for all remote access, so everyone now has DUO anyway. From what I could tell, DUO windows login is machine and not account based.@@codyappell24

  • @Waifu4Life
    @Waifu4Life 3 месяца назад +1

    Duo is great for remoting, but a pain in the ass if you just want to use you PC locally, hence why we disabled it for a local login at the office years ago.

  • @srikanthsatyanarayana4457
    @srikanthsatyanarayana4457 Год назад

    Hi Jonathan, It's a great video and thank you for that, i have configured Duo as per your suggestion and it is working for login, but i need to enable MFA for web access and share folder access also, could you please guide me how to do.
    Thanks in advance.

  • @scottfortune1132
    @scottfortune1132 Год назад +1

    do you still use a password policy, in which you still have the users change their password every 30,60 or 90 days?

    • @bearded365guy
      @bearded365guy  Год назад +2

      No we don’t. Here in the UK the advice is for users not to change their passwords. Choose a strong random password with MFA is the way to go.

    • @scottfortune1132
      @scottfortune1132 Год назад

      @@bearded365guy Another question, if the computer goes to sleep, you still have to use the 2fa, correct, or no?

    • @bearded365guy
      @bearded365guy  Год назад

      @@scottfortune1132 if the computer locks, then yes.

  • @boedilllard5952
    @boedilllard5952 Год назад

    Sorry for being obtuse. I'm looking for something to replace Windows AD on prem. I just want anyone who has an active acount to be able to log into any of our comuters and people without accounts or disabled accounts not to be able to log in. SO it wouldn't matter if Mary wants to log in on Joe's old PC - as long as she was active (like it works with Active Directory) she could log into that computer. I'd also like to be able to decide which users have local admin rights on their PC remotely. Can duo do this? I'd like to get all servers off prem.

    • @user-bi4jp5jo1m
      @user-bi4jp5jo1m 3 месяца назад

      If you have no log on servers, there would be no centralized logon. What you are describing is Active Directories sole purpose, centralized user and device management. Duo doesn't manage accounts on your devices and why he emphasized the username you register MUST be correct. As far as I have seen there isn't a solid replacement for Active Directory. Every solution I was told to check out had at least one downfall/incompatibility, but you would need some type of directory service to manage the devices and users. Duo is only a middleman or added layer to authentication. If you do find a good AD solution tho, I'd be interested in hearing about it for some smaller clients I support.

  • @librarygirldigitalworld
    @librarygirldigitalworld 29 дней назад +1

    Good day, Can I use hardware tokens for this process instead of mobile phone? We cannot force staff to use their personal phones for MFA without requests for compensation possibly. If it is possible, can you direct me to instructions/guide

    • @bearded365guy
      @bearded365guy  29 дней назад +1

      Yes, a Yubikey.

    • @librarygirldigitalworld
      @librarygirldigitalworld 29 дней назад

      @@bearded365guy I have the Duo Tokens, will that work?

    • @bearded365guy
      @bearded365guy  27 дней назад +1

      @@librarygirldigitalworld I didn’t know DUO did their own tokens?

    • @librarygirldigitalworld
      @librarygirldigitalworld 26 дней назад

      @@bearded365guy I am still learning. Which is why I love watching your channel. But yes, we purchased the Duo Hardware Token (DUO-TOKEN) by Cisco

  • @linvlog7227
    @linvlog7227 Год назад

    Does it support AD on premise and local user without domain?

    • @bearded365guy
      @bearded365guy  Год назад

      If AD is on premise, there should be a domain?

    • @KyngD469
      @KyngD469 8 месяцев назад

      @@bearded365guy perhaps local admin?

  • @Adrisemni
    @Adrisemni Год назад

    Have you experienced Samsung not able to read and run QR code for offline access? The menu list won't appear...

  • @UniquelyControversial
    @UniquelyControversial Год назад

    Is it possible to use this as passwordless instead of password?

    • @bearded365guy
      @bearded365guy  Год назад

      Yes it is with Windows Hello
      guide.duo.com/passwordless

  • @L4zy_Titan
    @L4zy_Titan Год назад +1

    Epic beard.

  • @TecnaGamerYT
    @TecnaGamerYT Год назад +1

    When I tried setting this up this this caused my login screen to be a blank blurry page with no options

    • @bearded365guy
      @bearded365guy  Год назад

      I’ve not seen that before!

    • @TheGhostalgia
      @TheGhostalgia 10 месяцев назад

      Same, I ended up having to reset my PC. Not sure what I did wrong, would have really liked to set up properly but hopefully Microsoft will implement 2fa in the future

    • @dorian_greyy6981
      @dorian_greyy6981 9 месяцев назад

      This just happened to me, anything learned?

    • @TheGhostalgia
      @TheGhostalgia 9 месяцев назад

      It might have had something to do with using Microsoft account vs a local account, I ended up going with a local account and just using a yubikey

    • @talentflame5557
      @talentflame5557 4 месяца назад

      This happened even for me , any fixes ?

  • @scottmckeown
    @scottmckeown 10 месяцев назад

    If you unplug the network cable or turn off wifi it lets your right in. Dont understand why its that east to bypass. Why even use it? Also safe mode appears to bypass it as well.

    • @bearded365guy
      @bearded365guy  10 месяцев назад

      It shouldn’t work like that…..

    • @ppkscott
      @ppkscott 10 месяцев назад

      @@bearded365guy I agree it shouldn't but it does. It actually states it works that way in their documentation. Have you tested any other 2FA apps for windows logins? I am trying to find one that is simple enough for end users but also is actually secure. Any ideas would be greatly appreciated. Thanks

  • @HyperionBadger
    @HyperionBadger 11 месяцев назад +1

    Thank you for the tutorial. It is very strange that Microsoft doesn't just make this feature available within itself. They clearly have it in place for everything else, except for this? ... Microsoft lol.

    • @bearded365guy
      @bearded365guy  11 месяцев назад

      Yes, it would be useful.

    • @HyperionBadger
      @HyperionBadger 11 месяцев назад +1

      @@bearded365guy I spoke to soon. I followed the tutorial, I got the blurred screen of death and nearly got locked out of my computer, and I feared that I made a career ending mistake. I fixed it. No worries. Not your fault. But I highly suggest you should put a HUGE warning that when performing this set up, if a user is connected to a Microsoft Live ID, DUO will not work.

    • @1stchristopherpark
      @1stchristopherpark 10 месяцев назад

      Agree I got the same problem took me hours to figure out what I did wrong and get back into my work station @@HyperionBadger

  • @L0neSurvivoR
    @L0neSurvivoR Год назад

    this works on windows 10?

  • @icognitorinsewashcheeto6022
    @icognitorinsewashcheeto6022 Год назад +1

    I did this and now my password screen is blurred and i cannot log in to my laptop

    • @bearded365guy
      @bearded365guy  Год назад

      Oh no. Not sure where it went wrong there?

    • @icognitorinsewashcheeto6022
      @icognitorinsewashcheeto6022 Год назад +2

      @@bearded365guy it was due to my rdp account was from a live id and apparently duo blurs out the login screen if you set up the microsoft rdp protection for an account that is registered with a live id. It only works on a local account. So to really use this servi d for me, i would need to clone my account to a local account and then delete everything important from the main account and set up rdp protection for the local account. The fact that most people register thier accounts with a live id, im suprised that this is not a common precaution for all installs. Would have been a time saver if it was stated by the company in an obviously visible way like most warnings in life.

    • @marcioinfoful
      @marcioinfoful 10 месяцев назад

      Same here, did you find a solution ?

    • @talentflame5557
      @talentflame5557 4 месяца назад

      Same plz help

  • @talentflame5557
    @talentflame5557 4 месяца назад

    Scam I got loged out