300-740 · Question #42
An engineer is configuring multifactor authentication using Duo. The implementation must use Duo Authentication Proxy and the Active Directory as an identity source. The company uses Azure and a…
The correct answer is D. Configure the Identity Source as "Active Directory" on the Single Sign-On tab, and configure the. Option D is correct because the requirement explicitly calls for Active Directory as the identity source AND the Duo Authentication Proxy - both of which D configures. The Authentication Proxy is the bridge that allows Duo to communicate with an on-premises Active Directory, so…
Question
An engineer is configuring multifactor authentication using Duo. The implementation must use Duo Authentication Proxy and the Active Directory as an identity source. The company uses Azure and a local Active Directory. Which configuration is needed to meet the requirement?
Options
- AConfigure the Identity Source as "SAML" on the Single Sign-On tab in the Duo Admin Panel, and
- BConfigure the Identity Source as "SAML" on the Single Sign-On tab, and configure the
- CConfigure the Identity Source as "Active Directory" on the Single Sign-On tab in the Duo Admin
- DConfigure the Identity Source as "Active Directory" on the Single Sign-On tab, and configure the
How the community answered
(24 responses)- A4% (1)
- B4% (1)
- C13% (3)
- D79% (19)
Explanation
Option D is correct because the requirement explicitly calls for Active Directory as the identity source AND the Duo Authentication Proxy - both of which D configures. The Authentication Proxy is the bridge that allows Duo to communicate with an on-premises Active Directory, so omitting either piece breaks the solution.
Options A and B are wrong because they set the identity source to "SAML," which is used for federated identity providers (like Azure AD via SAML assertions), not for a direct Active Directory integration. Since the requirement specifies AD as the source, SAML is the wrong protocol here.
Option C is wrong because, while it correctly sets the identity source to "Active Directory," it stops at the Duo Admin Panel configuration and does not include setting up the Authentication Proxy - the required component that actually proxies authentication requests to the local AD server.
Memory tip: Think of the Authentication Proxy as the "translator" that sits between Duo's cloud and your on-prem AD. No proxy = no AD communication. Whenever a question mentions local Active Directory + Duo, the Authentication Proxy is always part of the answer. SAML is for cloud/federated IdPs, AD is for on-premises directory services.
Topics
Community Discussion
No community discussion yet for this question.