AI OnAI Off
Is your Epi site setup to use federated security? I know Auth0 supports Duo so that's one thing you could look at using.
It does not seem that Azure AD support DUO but it has it's own way of two factor that works well
https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication/
We've standardized internally with Duo and would like to apply this to our remote box.