Datto Partner Portal: Setting up Two-Factor Authentication (2FA) with Duo

Follow

Topic

This article describes how to set up Two-Factor Authentication (2FA) for the Datto Partner Portal using Duo 2FA.

Environment

  • Datto Partner Portal

Description

DUO is a multi-factor authentication application with a wide variety of authentication methods that make it easy for every user to securely and quickly log in. Duo Push, sent by the Duo Mobile authentication app, lets users approve push notifications to verify their identity.

You cannot configure Duo for your user if you belong to multiple companies/resellers

Index

Initial setup steps for Security Admins

A user from your company who is assigned the role of Security Admin must complete the initial Duo setup. 

You must have a valid Datto Partner Portal account and a valid Duo account to complete this process. 

In the Datto Partner Portal

1. Click the Admin tab, then select Company Settings from the Drop-Down menu. Only users with the Role of Security Admin will be able to see the Company Settings page.

mceclip0.pngFigure 1: the Datto Partner Portal (click to enlarge)

2. In the TWO-FACTOR AUTHENTICATION section of the Company Settings page, click SET UP ORGANIZATION 2FA.

mceclip0.pngFigure 2: Two-Factor Authentication setup on the Company Settings page (click to enlarge)

3. On the 2FA SET UP screen, select Duo, then click NEXT.

mceclip1.pngFigure 3: Duo selection (click to enlarge)

The Setup screen will show three fields, into which you will enter the appropriate information the Duo Web Application provides.

mceclip2.pngFigure 4: API authorization entry (click to enlarge)

In the Duo Admin Portal

1. In another browser tab, log into Duo.

mceclip0.pngFigure 5: The Duo login screen (click to enlarge)

2. In the Duo Dashboard, select Applications in the left-hand navigation bar, then select Protect an Application from the drop-down menu.

mceclip2.pngFigure 6: The Duo dashboard (click to enlarge)

3. In the search bar, search for 'Web SDK,' then click the Protect button. 

sdk.pngFigure 7: The application selector (click to enlarge)

4. Copy the information within the following fields into the corresponding fields in the partner portal, as shown in Figure 4:

  • Integration key
  • Secret key
  • API hostname.

For more information on these fields, click the link for Duo Web SDK documentation.

mceclip5.pngFigure 8: Web SDK key and API information (click to enlarge)

Duo mobile device setup steps for users

Enable the Duo app on your mobile phone

1.. Install the Duo app from either the Apple App Store or Google Play Store.

mceclip1.pngFigure 9: Duo Mobile in the Google Play Store (click to enlarge)

2. On the Duo Mobile welcome screen click Get Started. Accept any permission requests.

3. In your business email account, open the email from Duo Security titled Duo Security Enrollment, then click the enrollment link within the email. 

Set up Duo in the Datto Partner Portal

1. Log into the Datto Partner Portal, The system will prompt you to authenticate your login through your current third-party 2FA application, if applicable.

mceclip6.pngFigure 9: The Datto Partner Portal login screen (click to enlarge) 

2. The Duo setup dialog box will appear. Click the Start setup button to begin.

Screen_Shot_2020-05-14_at_3.38.14_PM.pngFigure 10: The Duo setup dialog box (click to enlarge) 

3. Specify the type of mobile device you will use to authenticate your login requests.

Screen_Shot_2020-05-14_at_3.38.32_PM.pngFigure 11: Device type selection (click to enlarge) 

4. Enter your mobile telephone number.

Screen_Shot_2020-05-14_at_3.38.50_PM.pngFigure 12: Mobile phone number entry (click to enlarge) 

5. Select your phone's operating system type (iPhone, Android, Windows Phone, or other).

Screen_Shot_2020-05-14_at_3.39.00_PM.pngFigure 13: Phone OS selection (click to enlarge) 

6. On your computer, click the I have Duo Mobile installed button.

mceclip4.pngFigure 14: Duo enrollment, app install confirmation (click to enlarge)

7. Open the Duo Mobile app on your mobile device, then scan the QR mode on your computer screen. 

mceclip5.pngFigure 15: Duo enrollment, QR code (click to enlarge) 

Verifying 2FA enablement

In the Datto Partner Portal, click your username in the upper right-hand corner of the screen, then select User Settings from the drop-down menu.

mceclip3.pngFigure 16: Partner Portal User Settings (click to enlarge) 

The Two Factor Authentication card will show a SECURED badge. 

mceclip4.pngFigure 17: The Two-Factor Authentication card in User Settings (click to enlarge)  

Removing Organization 2FA using Duo

1. In the Datto Partner Portal, click the Admin tab, then select Company Settings from the Drop-Down menu. Only users with the Role of Security Admin will be able to see the Company Settings page.

Figure 18: The Datto Partner Portal (click to enlarge)  

2. In the Two Factor Authentication card on the Company Settings page, click RESET ORGANIZATION 2FA.

mceclip0.pngFigure 19: The Two-Factor Authentication card in Company Settings (click to enlarge)  

3. Click CONFIRM.

mceclip1.pngFigure 20: The CONFIRM link on the Reset Two-Factor Authentication screen (click to enlarge)  

mceclip0.pngFigure 21: The DONE link on the Reset Two-Factor Authentication screen (click to enlarge)  

The system will send an email to all affected users acknowledging that Duo has been removed for organizational 2FA.

mceclip3.pngFigure 22: The Removal acknowledgment email (click to enlarge)  

4. The system will send a temporary one-time passcode to your email upon their next login. If you do not receive the token, click the Email link to receive a new one. 

mceclip4.pngFigure 23: The Resend Token link (click to enlarge)  

5. Click your account name and select User Settings from the drop-down menu.

mceclip5.pngFigure 24: The Users menu in the Datto Partner Portal (click to enlarge)

6. Click CONFIGURE.

mceclip0.pngFigure 25: The Two-Factor Authentication card (click to enlarge)

7. Select the Third Party Authenticator App radio button, then click Enable 2FA to configure your two-factor authentication with the third-party authenticator app of your choice. 

mceclip1.pngFigure 26: The Two-Factor Authentication configuration box (click to enlarge)

Additional Resources 


Was this article helpful?

0 out of 0 found this helpful

You must sign in before voting on this article.

Want to talk about it? Have a feature request?

Head on over to our Datto Community Forum or the Datto Community Online.

For more Business Management resources, see the Datto RMM Online Help and the Autotask PSA Online Help .

Still have questions? Get live help.

Datto Homepage