IAM / Cisco Duo

Cisco Duo

Cisco Duo is a multifactor authentication and device-trust overlay that often sits in front of an existing identity provider, virtual private network, or directory. It adds phishing-resistant methods, Duo Push, adaptive policy, and passwordless options without replacing identity governance or customer identity.

Multifactor authentication overlayResearch reviewed

What you are evaluating

Duo is access security, not a full identity-governance or customer-identity platform. It integrates with Active Directory, virtual private networks, software-as-a-service, and Entra external authentication methods. It does not by itself certify entitlements or vault privileged passwords.

A useful evaluation context

This can be evaluated by an organization that already has an identity provider and needs stronger multifactor authentication and device trust in front of it.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Phishing-resistant multifactor authentication, Duo Push, and passwordless options strengthen sign-in at applications and remote access.
  • Adaptive policy and device health checks can require a healthy endpoint before access is granted.
  • Integrations front existing identity providers and virtual private networks so Duo can be added without moving the directory.

Where it fits in the work

  1. Keep the existing lab identity provider in place and add Duo as an external multifactor authentication or virtual-private-network prompt.
  2. Enroll a synthetic user with a phishing-resistant method and a device-health policy on one application.
  3. Revoke the Duo enrollment or fail a device-health check in the lab and confirm the identity provider password alone is not enough.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In a lab, protect a synthetic application with Duo behind the existing identity provider, enroll a phishing-resistant authenticator, then unenroll it and retry with password only.

Evidence to look for

The first sign-in meets the configured phishing-resistant authentication policy, and the password-only retry is denied while the applicable policy remains enforced.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which applications and virtual private networks in the lab actually honor Duo as an external method, including Entra external authentication if that is in play?
  2. What happens when a device fails the health check, and who can override that in an authorized break-glass path?
  3. Where will identity governance, customer identity, and privileged vaulting live, since Duo does not replace those products?

Names you may encounter: Duo Security. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.