Skip to main content

Cisco Duo

Cisco Duo is a multi-factor authentication (MFA) service. This connector brings in your Duo users, including whether each has enrolled a second factor, and, where your Duo plan includes it, the endpoints (computers) Duo has seen.

Beta. This connector was built from Duo’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact [email protected].

At a glance

Data providedUsers, Devices
AuthenticationDuo Admin API integration key and secret key
Where to configureConnectors → Add a Connector → Cisco Duo

Required permissions

Create a dedicated Admin API application in the Duo Admin Panel and give it only the Grant resource - Read permission. No write permissions are needed.

Setup

  1. In the Duo Admin Panel, go to Applications → Application Catalog and search for Admin API, then add it. Fill out the details there.
  2. Under Permissions, check only Grant resource - Read, then save.
  3. Copy the API hostname (it looks like api-XXXXXXXX.duosecurity.com, or api-XXXXXXXX.duofederal.com for Duo Federal), the Integration key, and the Secret key. Treat the secret key like a password.
  4. In Navigator, go to Connectors → Add a Connector → Cisco Duo.
  5. Enter the API hostname, integration key and secret key, then save. Navigator validates the credentials and enqueues a first sync immediately.

Duo’s own guide: Admin API.

If you change the application’s secret key in Duo, update it here too, or the sync will start failing.

What data this connector provides

  • Users: every Duo user, with username, email, name, whether the account is enabled (active or bypass) or not (disabled, locked out, pending deletion), whether the user has enrolled a second factor, and the kinds of factor they have (push, SMS, phone call, passcode app, hardware token, WebAuthn).
  • Devices: computers (Windows, macOS, Linux and ChromeOS) that Duo has recorded, with hostname, model, operating system and version, disk-encryption status, when Duo last saw them, and the last user.

How MFA is reported

A user counts as having MFA only when they have enrolled a second factor and are not set to bypass. Duo lets a bypass user skip the second factor entirely, so enrolling a phone doesn’t protect them. A user who hasn’t enrolled yet has no second factor.

Known limitations

  • Devices need a Duo plan that includes endpoint information. If yours doesn’t, the sync still succeeds for users and notes that no devices were available. Duo removes an endpoint’s record after 30 days of inactivity.
  • Mobile devices are not synced. Duo names a phone after what its owner calls it, not a hostname, so it wouldn’t match the same device in other tools. Phones that only hold a Duo Mobile authenticator aren’t endpoints either.
  • Serial numbers aren’t taken from Duo yet, because its device identifier isn’t always a serial number.
  • Groups, aliases, last login time, and each user’s individual phones and tokens are not shown in Navigator yet.
  • Duo accounts with sub-accounts (MSP) are not supported; connect each account on its own.

Troubleshooting

  • The sync fails with a message that the source rejected the saved credentials. Check the hostname, integration key and secret key match the Admin API application, and that the secret key hasn’t been regenerated.
  • The sync fails with a message that access was denied. The application doesn’t have Grant resource - Read. Enable it in the Duo Admin Panel and save.
  • Users sync but no devices appear. Your plan may not include endpoint information, or all of your endpoints are mobile devices.