Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device.
Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device. Atlassian cookies and tracking notice, (opens new window)
Duo admin users use the email address for username
Each user can have 1 and only 1 role
In your prod env you should have an email routable EPPN from SSO and setup and require SSO for administrators
The provisioner can send an email invite for new users (since a new user cannot use Duo as an administrator until they accept an email invite previously sent)
Note, other environments cannot have admins with same login (email) as other envs. Its a best practice to have a standard email suffix for each env (non-prod vs prod)
Note, if a user is an admin of another Duo env (e.g. not at your institution) using their eppn, then they need to change that login id
Its possible if you do not have a standard email address to set that with entity metadata (i.e. set it in the provisioning settings for a subject in grouper)
The role name can be the display extension of the group, or could be metadata. It must match exactly the role in Duo
If someone is in multiple roles in Grouper, the provisioner will select the most important role and use that (since they can only have one)
If someone doesnt have a role, and entities are set to be deleted, then their account will be deleted in Duo
Manage administrators in Duo
Attributes
Group fields and attributes
Grouper name
Type
Required
Description
role
String
required
role name
Entity fields and attributes
Grouper name
Type
Required
Description
role
String
required
role name. Check this doc for most recent available roles. e.g. Owner, Administrator, Application Manager, User Manager, Help Desk, Billing, or Read-only
id
String
required
admin id
name
String
required
name of the admin
email
String
required
unique email address of the admin
send_email
String
optional
1 send email for new users, 0 dont (default)
Example configuration
This folder is provisioner and has a group for all the admin roles