Deploying DUO Device Health

Rarsf
New Contributor

Looking to get some advice on how to deploy DUO device health via JAMF DEP. I added the package to pre-stage but when DEP completes it never launches the app or installs it. Anyone have any advice on how to deploy to new machines?

4 REPLIES 4

mainelysteve
Valued Contributor II

According to this page you must also install a mobile config that contains a trusted cert and also create an empty file in /Library/Application Support/Duo/Duo Device Health/. I'm assuming all of that is being deployed to your clients as well?

You should also check your pkg in Suspicious Package and ensure that it's signed. If it's not signed then Gatekeeper could potentially be the reason why it didn't get installed. Are you scoping a profile with the Security and Privacy payload to your clients? If so check what Gatekeeper is set to.

Rarsf
New Contributor

Thank you @mainelysteve - Spoke to DUO and it appears that you have to sign in first for the token to attach to the local user in order for the application to run.

TrentO
Contributor II

Did you find a workaround for this? The only thing I can come up with is temporarily disabling the requirement for it until a user has logged in for the first time. 

Rarsf1
New Contributor

No luck so far! Trying to find a launch daemon agent to launch app and keep it running.