> For the complete documentation index, see [llms.txt](https://docs-servers.zesty.group/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs-servers.zesty.group/security/how-to-setup-duo-2fa-on-rdp.md).

# How to setup DUO 2FA on RDP

### Video Guide / How-To Video

{% embed url="<https://www.youtube.com/watch?v=jRyeava-bEA>" %}

### Signup for Duo

Signup for Duo Trial: [**here**](https://duo.com/)

### Setup Your Application

Click on the **Protect an Application** button in the top left

![](/files/-M3jDE9xRtPQ7M19fVTk)

Search up "RDP" and you'll be able to see Microsoft RDP. This can be used for:

Clients:

* Windows 8.1
* Windows 10 (as of v1.1.8)

Servers (GUI and core installs):

* Windows Server 2012
* Windows Server 2012 R2
* Windows Server 2016 (as of v2.1.0)
* Windows Server 2019 (as of v4.0.0)

![](/files/-M3jDFxaZKdJ67CIyZqO)

We highly suggest you leave everything as default unless you know what you're doing. \
Don't forget to click save when it shows.&#x20;

![](/files/-M3jIxGVkYa80KAYOW_z)

![](/files/-M3jDK8E4LvUh63BuJ-Q)

![](/files/-M3jDMFA0tK3krC4RKEP)

### Adding a User to Duo

Default username should be "Administrator"\
You will also be able to set Administrator as an alias under different account names. \
In our case, we use zestyadmin but for ALL zesty clients, you should be using Administrator.&#x20;

![](/files/-M3jDNlrh03lo5tTMtWz)

![](/files/-M3jE9fZee7lof10IhV8)

### Add a Phone

Download the Duo Mobile app onto your phone.&#x20;

![](/files/-M3jEFo3LsKHmR84aOlV)

Back to your browser. Under the same user page, you will be able to add a phone using the "Add Phone" button.&#x20;

![](/files/-M3jGT6c9_pQHV487aNG)

You will now click on the **Activate Duo Mobile** text (in blue) under the "Device Info" section.&#x20;

![](/files/-M3jH00j_bgcdEtGtfKX)

Generate the Duo Mobile Activation Code.&#x20;

![](/files/-M3jH2tjBfiaEwq5nk-q)

Send the link to your mobile device by SMS.&#x20;

![](/files/-M3jH5ZKtD8f_Y2T8IGS)

You will then click on the link and and it will open the Duo Mobile app and add your Application & User.&#x20;

![](/files/-M3jEIVxfqtDaSKSrU4Q)

### Installing Duo onto your Server

Download and install the Duo Authentication for Windows Logon installer package onto your **server**. \
You can download that [**here**](https://dl.duosecurity.com/duo-win-login-latest.exe).

Back to your application home screen, you will see the integration key, secret key and API hostname.&#x20;

Enter in your API hostname (Copy & Paste if you can).&#x20;

![](/files/-M3jEKIy4-KUSRFsHE4c)

Enter in the Integration Key and Secret Key (Copy & Paste if you can).&#x20;

![](/files/-M3jELq9-DVK2GnTmnar)

Select "Only prompt for Duo authentication when logging in via RDP"\
Make sure this is ticked.&#x20;

![](/files/-M3jENzsgCYqhb4TCpjh)

Don't enable smart card unless you actually have one and know how to configure it.&#x20;

![](/files/-M3jEPPbxWyPCg1EzWm0)

You may now logout and then login to the server and see if it prompts on your phone.&#x20;

![](/files/-M3jEfc5svJ3sDKOxsQD)

Done!&#x20;
