Unable to exclude local admin user for Cisco Duo from ONTAP
Applies to
- ONTAP 9
- Cisco Duo
Issue
Logging in with the ONTAP admin account prompts for Duo authentication even though the account is excluded in ONTAP
Cluster::*> duo group show
(security login duo group show)
Vserver: Duckie
Group Name: Duckie\Duousers
Excluded Users: admin
Comment: -
[root@ggcentos ~]# ssh admin@10.216.xx.yy
(admin@10.216.xx.yy) Password:
(admin@10.216.xx.yy) Password:
Success. Logging you in...
>> (Not visible from the CLI, but a Duo authentication request was received for this login attempt despite admin being an excluded user)
Last login time: 2/13/2025 09:13:57
Unsuccessful login attempts since last login: 2
Duckie::> exit
