duo trusted endpoint check failing on compliant devices
Fixes Duo trusted endpoint checks failing on compliant devices: verify MDM compliance, the Duo device certificate, and the trusted-endpoints report. Use when Duo says the endpoint is untrusted but the MDM says compliant. Not for push delivery issues.
TL;DR
The Duo trusted-endpoint check fails when the Duo device certificate is missing from the device, the management profile is gone, or the device fell out of compliance. Verify the device is compliant in the MDM first, then confirm the Duo certificate is present, then check Duo's trusted-endpoints report.
The query
duo trusted endpoint check failing on compliant devicesUse this when
- Duo blocks access saying the endpoint is not trusted
- device shows compliant in Intune or Jamf but Duo disagrees
- check starts failing after an OS update
Not for
- Duo push notifications not arriving (different symptom)
- unenrolled or unknown devices (enroll them first)
- Duo policy misconfiguration blocking everyone
Steps
- In the MDM, confirm the device is compliant and the management profile is installed. Expected output: compliant status with the profile present
- On the device, confirm the Duo device certificate exists in the certificate store and is valid. Expected output: the certificate is present and valid
- If it is missing, push the certificate or profile again from the MDM, or re-enroll the device. Expected output: the certificate installs successfully
- Check the Duo admin panel trusted-endpoints report for the device. Expected output: the device is listed as trusted
- If compliance recently flipped, have the device check in with the MDM and retry. Expected output: fresh compliance state and the check passes
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_BpJM-1qpNqqLHiJp4Apchw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.