We are currently working on configuring Jamf Connect to get away from local AD binding. I have the initial login to macOS working (Google SSO Prompt and Duo MFA is working well.) After initial account creation when you’re prompted by Self Service + to sync your Google Account password to your local account, that is where it fails. The error is: “invalid password.”
In testing... any account outside or bypassed from Duo can query LDAP successfully. Accounts encompassed by Duo receive the same “invalid password” message via Self Service + or when running the LDAP query manually via terminal.
I’ve already spoken with Jamf support. They did some minor config changes, log searching, asked me to speak with Duo and then resolved the ticket. I have a support request into Duo at the moment but haven’t heard back. I’ve looked through both Duo’s policies and in Google Admin and haven’t come up with anything.
Regarding the link you have provided, please note that the LDAP integration specifically is for use between an Authentication Proxy and an LDAP application which authenticates to Active Directory. I have included the network diagram below:
Primary authentication initiated to application or service
Application or service send authentication request to the Duo Security Authentication Proxy
Primary authentication using Active Directory
Duo Authentication Proxy connection established to Duo Security over TCP port 443
Secondary authentication via Duo Security’s service
Duo Authentication Proxy receives authentication response
Application or service access granted
While in theory there is a possibility that you may configure this application to authenticate against Google/AD, this integration method is not supported by Duo. The only supported method to integrate with Google would be via Duo SSO which is currently in use on your tenant. If you are able to integrate Duo in this way, we will be limited in troubleshooting capacity and support. While we are able to review logging and provide best effort support, you may need to engage outside resources for assistance.
So, in so many words - get a better IdP. Jamf Connect works awesomely with OIDC and <insert favorite MFA here>.
Google is limited on what it can do - I’ve hit walls like this with them numerous times.
Regarding the link you have provided, please note that the LDAP integration specifically is for use between an Authentication Proxy and an LDAP application which authenticates to Active Directory. I have included the network diagram below:
Primary authentication initiated to application or service
Application or service send authentication request to the Duo Security Authentication Proxy
Primary authentication using Active Directory
Duo Authentication Proxy connection established to Duo Security over TCP port 443
Secondary authentication via Duo Security’s service
Duo Authentication Proxy receives authentication response
Application or service access granted
While in theory there is a possibility that you may configure this application to authenticate against Google/AD, this integration method is not supported by Duo. The only supported method to integrate with Google would be via Duo SSO which is currently in use on your tenant. If you are able to integrate Duo in this way, we will be limited in troubleshooting capacity and support. While we are able to review logging and provide best effort support, you may need to engage outside resources for assistance.
Regarding the link you have provided, please note that the LDAP integration specifically is for use between an Authentication Proxy and an LDAP application which authenticates to Active Directory. I have included the network diagram below:
Primary authentication initiated to application or service
Application or service send authentication request to the Duo Security Authentication Proxy
Primary authentication using Active Directory
Duo Authentication Proxy connection established to Duo Security over TCP port 443
Secondary authentication via Duo Security’s service
Duo Authentication Proxy receives authentication response
Application or service access granted
While in theory there is a possibility that you may configure this application to authenticate against Google/AD, this integration method is not supported by Duo. The only supported method to integrate with Google would be via Duo SSO which is currently in use on your tenant. If you are able to integrate Duo in this way, we will be limited in troubleshooting capacity and support. While we are able to review logging and provide best effort support, you may need to engage outside resources for assistance.
So, in so many words - get a better IdP. Jamf Connect works awesomely with OIDC and <insert favorite MFA here>.
Google is limited on what it can do - I’ve hit walls like this with them numerous times.