Open Duo and go to Applications.
Select Protect an Application.
Search for Generic Service Provider. For the row that has Single Sign-On in the Protection Type, select Protect.
Copy the values from Condens into Duo:
SP Entity ID in Condens → Entity ID in Duo
SP Login URL in Condens → ACS URL in Duo
Ensure NameID format is set to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress.
Ensure NameID attribute is set to <Email Address>.
Ensure Signature algorithm is set to SHA256.
For Signing options, ensure both Sign response and Sign assertion are checked.
Under Map attributes, configure the following:
<Email Address> → email
Under Settings, update Name to Condens.
In Permitted groups, select the group you wish to have access to Condens.
Copy the values from Duo into Condens:
Single Sign-On URL in Duo → IdP Login URL in Condens
Entity ID in Duo → IdP Entity ID in Condens
Certificate in Duo → Certificate in Condens