Skip to main content
Solved

Jamf Connect w/Google SSO & Duo MFA - LDAP Query Failure

  • June 22, 2026
  • 4 replies
  • 61 views

Forum|alt.badge.img+7

Hello,

 

We are currently working on configuring Jamf Connect to get away from local AD binding. I have the initial login to macOS working (Google SSO Prompt and Duo MFA is working well.) After initial account creation when you’re prompted by Self Service + to sync your Google Account password to your local account, that is where it fails. The error is: “invalid password.” 

 

In testing... any account outside or bypassed from Duo can query LDAP successfully. Accounts encompassed by Duo receive the same “invalid password” message via Self Service + or when running the LDAP query manually via terminal. 

 

I’ve already spoken with Jamf support. They did some minor config changes, log searching, asked me to speak with Duo and then resolved the ticket. I have a support request into Duo at the moment but haven’t heard back. I’ve looked through both Duo’s policies and in Google Admin and haven’t come up with anything. 

 

What am I missing? 

Best answer by Chubs

Here’s Cisco’s response to using direct bind: https://duo.com/docs/ldap

 

Regarding the link you have provided, please note that the LDAP integration specifically is for use between an Authentication Proxy and an LDAP application which authenticates to Active Directory. I have included the network diagram below:

Image_2026-06-22_14-46-49.png
 

  1. Primary authentication initiated to application or service
  2. Application or service send authentication request to the Duo Security Authentication Proxy
  3. Primary authentication using Active Directory
  4. Duo Authentication Proxy connection established to Duo Security over TCP port 443
  5. Secondary authentication via Duo Security’s service
  6. Duo Authentication Proxy receives authentication response
  7. Application or service access granted

While in theory there is a possibility that you may configure this application to authenticate against Google/AD, this integration method is not supported by Duo. The only supported method to integrate with Google would be via Duo SSO which is currently in use on your tenant. If you are able to integrate Duo in this way, we will be limited in troubleshooting capacity and support. While we are able to review logging and provide best effort support, you may need to engage outside resources for assistance. 

 

 

So, in so many words - get a better IdP.  Jamf Connect works awesomely with OIDC and <insert favorite MFA here>.

Google is limited on what it can do - I’ve hit walls like this with them numerous times.

4 replies

Chubs
Forum|alt.badge.img+26
  • Jamf Heroes
  • June 22, 2026

For clarity - this all works without Duo in the mix, correct?

I got money that Duo is blocking the “direct bind” method that Jamf Connect is probably using - it’s a legacy protocol.  

I’m curious what response you’ll get from Cisco...keep us posted!


Forum|alt.badge.img+7
  • Author
  • Valued Contributor
  • June 22, 2026

Yep, works without Duo in the way. 

 

Edit*: Cisco responded and basically pointed the finger at Google & Jamf. 


Forum|alt.badge.img+7
  • Author
  • Valued Contributor
  • June 23, 2026

Here’s Cisco’s response to using direct bind: https://duo.com/docs/ldap

 

Regarding the link you have provided, please note that the LDAP integration specifically is for use between an Authentication Proxy and an LDAP application which authenticates to Active Directory. I have included the network diagram below:

Image_2026-06-22_14-46-49.png
 

  1. Primary authentication initiated to application or service
  2. Application or service send authentication request to the Duo Security Authentication Proxy
  3. Primary authentication using Active Directory
  4. Duo Authentication Proxy connection established to Duo Security over TCP port 443
  5. Secondary authentication via Duo Security’s service
  6. Duo Authentication Proxy receives authentication response
  7. Application or service access granted

While in theory there is a possibility that you may configure this application to authenticate against Google/AD, this integration method is not supported by Duo. The only supported method to integrate with Google would be via Duo SSO which is currently in use on your tenant. If you are able to integrate Duo in this way, we will be limited in troubleshooting capacity and support. While we are able to review logging and provide best effort support, you may need to engage outside resources for assistance. 

 

 


Chubs
Forum|alt.badge.img+26
  • Jamf Heroes
  • Answer
  • June 23, 2026

Here’s Cisco’s response to using direct bind: https://duo.com/docs/ldap

 

Regarding the link you have provided, please note that the LDAP integration specifically is for use between an Authentication Proxy and an LDAP application which authenticates to Active Directory. I have included the network diagram below:

Image_2026-06-22_14-46-49.png
 

  1. Primary authentication initiated to application or service
  2. Application or service send authentication request to the Duo Security Authentication Proxy
  3. Primary authentication using Active Directory
  4. Duo Authentication Proxy connection established to Duo Security over TCP port 443
  5. Secondary authentication via Duo Security’s service
  6. Duo Authentication Proxy receives authentication response
  7. Application or service access granted

While in theory there is a possibility that you may configure this application to authenticate against Google/AD, this integration method is not supported by Duo. The only supported method to integrate with Google would be via Duo SSO which is currently in use on your tenant. If you are able to integrate Duo in this way, we will be limited in troubleshooting capacity and support. While we are able to review logging and provide best effort support, you may need to engage outside resources for assistance. 

 

 

So, in so many words - get a better IdP.  Jamf Connect works awesomely with OIDC and <insert favorite MFA here>.

Google is limited on what it can do - I’ve hit walls like this with them numerous times.