Skip navigation
Duo proximity verification deployable phishing resistant MFA.
Product & Engineering

Duo Proximity Verification: Deployable phishing-resistant MFA

Rolling out phishing resistant authentication is critical, but many organizations struggle with the complexity and cost of deploying hardware-based solutions like security keys at scale, all while trying to stay ahead of modern phishing attacks. That’s why we've introduced our new Proximity Verification feature. It removes friction, gives you a smoother and more secure experience, and it’s cost-effective for your organization.

How does this work?

Our proximity verification feature uses Bluetooth Low Energy to confirm that a user’s device is near their computer during login. Imagine logging in without entering codes or accidentally forgetting your hardware key. Proximity Verification makes this a reality.  By design, it prevents bad actors from tricking users into approving authentication requests when they are accessing a computer in a different location from end users.

Proximity verification also prevents users from clicking and entering information into malicious links by checking the origin of the website the request came from. If the request does not come from a valid domain, we will deny the authorization request. This is similar to how modern security standards like FIDO2 verify the legitimacy of login requests to block phishing attacks.

Is your organization a good fit?

Proximity verification is a great fit for organizations that want strong security without added complexity. It’s especially well-suited for teams that:

  • Are focused on securing against modern phishing attacks

  • Have limited budget or operational capacity to purchase and distribute hardware like security keys

  • Have already made significant investment in mobile authenticators for 2FA or push based login

Why you’ll love it

  • Phishing resistance that’s simpler: Stronger security that is just as secure as FIDO2 but is already included on your device via Duo Mobile. This security feature is built in, making it secure by default.

  • Cost-effective even as your company grows: allows you to securely authenticate from your laptop, no need to juggle extra devices like security keys or worry about biometric upgrades. It cuts down the operational hassles of purchasing, distributing, and managing additional hardware.

  • No more typing in codes: Bluetooth auto-fills verification codes, so users don’t have to. If you’re already using Duo, nothing changes in how you use it day to day, just a smoother experience with even stronger security behind the scenes

With Proximity Verification built into Duo’s security-first IAM solution, your organization gets strong, phishing-resistant authentication without the usual complexity and costs. It’s simple to deploy and scale, helps you meet security requirements, and keeps users protected from day one. There's no need to enter codes or carry extra hardware. Authentication just works when your device is nearby, making the log experience fast and seamless.

Want to learn more? Head to our phishing prevention page or check out our editions data sheet.

Ready to give it a try? Sign up today.