Hello,
We found the issue to our problem, which was not listed in that article or other places. I had to allow the forms authentication type for Intranet users and also had to allow all users to access the relying party trust. It seems each documentation covers the integration side of the setup without going over the (rather simple) user settings. I believe there was one other thing I did but cannot recall at the moment... I just looked at the AD FS logs and kept fixing errors until it worked.
In the end, it turned out that the Duo setup wants my SAML Idp to be publicly accessible, which is a big no for our AD FS server. I eventually redid the setup with something else acting as the Idp, with Active Directory acting as the user database in the back end.
Thank you for looking into the problem @Gloria Gu ,
Zane