I have a saying "no is an answer too"... I appreciate the candor and not just being led on. Note no mention of the AD FS duo app which is specially what I asked them about on the phone, but "no recommended or supported VMWare VCenter/VSphere application protection with Duo" is pretty clear). Full text:
Hi Matthew,
Thanks for contacting Duo Technical Support.
I understand you wish to protect VMware Vsphere and Vcenter with Duo.
There is currently no recommended or supported VMWare VCenter/VSphere application protection with Duo.
We had previously published documentation for protecting VMWare vCenter and VSphere logins using ldap_server_auto in the Duo Authentication Proxy. We removed this documentation from the site on 10.6.2015 for security reasons.
This was removed because it was determined to be very easy to bypass Duo authentication. There is a plugin you can install that uses SSPI authentication to log in to vCenter/vSphere using your Windows session credentials. Checking the box to use this plugin bypasses Duo's LDAP authentication.
While this feature is not something that's currently available, I've associated your account with the existing feature request for this.
Feature requests are prioritized in accordance with a number of factors, such as security enhancement, bug fixes, customer demand, and alignment with our product roadmap. While an exact ETA will not be available due to these priorities changing periodically, rest assured that your feedback is important to us, and we are continually working to improve and enrich the product.
The best way to be updated on the delivery of any feature is to subscribe to our Release Notes in the Community! Here’s how to do that:
https://community.duo.com/t/how-to-subscribe-to-release-notes/5531
Thanks for your input and for helping make Duo better!
Should you have any concerns or questions, please feel free to reply to this email.
Best Regards,
Hiroaki
Want to know what we're up to? Subscribe to our Release Notes in the Duo Community!
Duo Security Support Team - Support Page https://duo.com/support
--
I asked vmware to escalate my request if possible to request vmware work on duo integration (e.g. a duo app)