Skip to main content

Duo Security (Cisco)

Status: Scaffold — content in progress

Duo Security (acquired by Cisco in 2018) is a market-leading MFA and Zero Trust Network Access (ZTNA) platform. It is primarily an MFA overlay — it integrates with existing authentication systems (AD, VPN, SSH) rather than replacing them.

Integration Modes

ModeHow It Works
Duo Authentication ProxyOn-prem agent that intercepts RADIUS/LDAP auth and adds 2FA step
Duo SSOSAML IdP with Duo MFA built-in
Duo for Windows LogonWindows login + 2FA via RDP or local logon
Duo Universal PromptBrowser-based MFA flow embedded in app authentication

Duo MFA Factors

FactorPhishing Resistance
Duo PushNo — push bombing target
Duo Push with number matchingSignificantly harder
TOTPNo
SMSNo
Duo hardware tokenNo
Security key (FIDO2)Yes
BiometricYes

Attack Surface

AttackDescription
Duo Push fatigueFlood push notifications → user approves accidentally
Authentication Proxy compromiseOn-prem proxy has credentials to Duo service + LDAP/AD
Admin panel takeoverFull Duo policy control
Bypass via legacy authIf legacy auth protocols (basic auth, RADIUS without Duo) are still enabled
TopicLink
MFA Technologiesmfa-technologies
MFA Fatiguemfa-fatigue
RADIUSradius