Duo (or MFA) after Microsoft SSO
P
Previous Gecko
Problem
When Microsoft SSO (SAML) is enabled, users who sign in via SSO are signed into Hudu immediately after a valid SAML assertion. Hudu Duo and Hudu TOTP are not prompted on that path. Customers who want SSO + Duo push on every login (web and mobile) cannot get that from Hudu Duo today—MFA must be enforced only at the IdP (e.g. Entra Conditional Access / Duo for Microsoft).
Desired behavior
Add an optional account setting such as “Require Hudu Duo / 2FA after SSO.”
When enabled, after a successful SAML login Hudu should still send the user through Duo (or TOTP if Duo is off), the same way password login does today.
Why it matters
Many MSPs require Microsoft SSO and still want Duo as the consistent second factor inside Hudu on web and mobile, without relying only on Entra configuration.
Acceptance criteria
- Admin toggle: enforce Duo/2FA after SSO (default off to preserve current behavior)
- Works for web and mobile SSO flows
- Password-login Duo behavior unchanged
- Portal users / exempt groups follow existing SSO exemption rules where applicable