New Duo Restore feature with 1Password?

I am uncertain how this works at the moment but Duo now has a Duo Restore feature and 1Password is one of the supported apps.

https://help.duo.com/s/article/ka10g000000btPGAAY/duo-restore?language=en_US

"Enabling Duo Restore in the Duo Admin Panel

In order to enable Duo Restore, you must specify a web-based application that can handle user's primary credentials before displaying the Duo Prompt. By making your users complete both primary and secondary authentication before recovering an account, Duo Restore maintains your organization's security posture while reducing internal support needs. See a list of all applications that display the Duo Prompt here. If you do not currently protect a web-based application with Duo and want to use this feature, you can deploy a Duo Access Gateway or create a WebSDK-based application.

Note: Users must be able to complete two-factor at the Duo Prompt in order to recover their account. They may use phone callback authentication, a hardware token passcode, an SMS passcode, an administrator-issued Bypass Code, or a different Push-enabled device that they have previously associated with their account. Any policies specified in the Duo Admin Panel will also be taken into account in the authentication workflow. If your users do not have access to SMS or phone callback authentication, your organization may not be a good fit for Duo Restore.

To enable Duo Restore in the admin panel:
Log in to the Duo Admin Panel.
In the left-side navigation, select Settings.
Scroll down to the Duo Mobile App section.
Select a web application.
In the URL field, paste in the URL that your users go to to log in to this application.
Click Save Changes at the bottom of the settings page."

For iOS devices, iCloud or from iTunes, encrypted backups must be enabled.

https://help.duo.com/s/article/ka070000000kANZAA2/1085?language=en_US

The list of Duo supported applications can be found above.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Sync Type: Not Provided

Comments

  • thightower
    thightower
    Community Member

    @wkleem

    I don't have teams, only families. However this is really a nice find, I can see it being very useful to me personally. Many thanks for sharing.

  • wkleem
    wkleem
    Community Member

    No problem! I am not seeing the feature in my Duo Mobile app for iOS.but I am seeing it in my Android phone oddly enough.

  • Thanks for posting about this, @wkleem! It should be a cool feature to have around :)

  • wkleem
    wkleem
    Community Member

    @Jacob: You're welcome. I am waiting for iOS 11 which should be out next week with the iPhone 8 announcement.

  • Indeed. iOS 11 looks to be pretty exciting. :)

    Ben

  • wkleem
    wkleem
    Community Member
    edited September 2017

    @Ben, I haven't had any lockout issues since I reported my problem to Agilebits and Duo over 5 months ago in April 2017 but the restore feature may come in handy!!

  • Here's to a happy future then!

  • wkleem
    wkleem
    Community Member
    edited September 2017

    Hi

    There is a 2 part requirement for Duo Restore to work which must be set up in Duo Admin. I thought Agilebits might want to know. First part is simple but the second part, where to send users?

    I have not had a need to do a restore yet so there is some guesswork involved.

  • I believe the URL they're looking for there is just the sign-in URL for 1Password Teams. So something like https://fillion.1password.com.

    Rick

  • wkleem
    wkleem
    Community Member

    Thanks @rickfillion!

    I will test things out when I can. Duo Mobile for Android backs up to Google Drive and Duo Mobile for iOS relies on iCloud Backup.

  • Lars
    Lars
    1Password Alumni

    Thanks, @wkleem! :)

  • wkleem
    wkleem
    Community Member

    Is it necessary to add to this thread? Duo Mobile have now with their latest versions added more recovery features, for example, Third Party 2nd factor recovery for WhatsApp, etc?

This discussion has been closed.