Skip navigation

MSP Delegated Access

Last updated:

Overview

Delegated Access allows users in a group on the MSP main account to authenticate into customer applications on subaccounts.

Prerequisites

  • An MSP account is required to use this feature.

  • Ensure MSP users are users with a 2FA device on the main account. Enroll MSP users that need to access subaccount applications in the main account only. Do not add the user to the Duo subaccount. The username for this user should be the same as the username that the application uses to log in to.

    • The main account user must have an active 2FA device. Delegated Access does not permit inline device enrollment.
  • The username (or user alias) cannot exist in the customer’s subaccount. If the username exists in the subaccount, Duo will not delegate the authentication to the user on the main account.

Known Limitations

Application Feature Limitations

Policy Limitations

The following restrictions apply when editing a policy with delegated access:

  • Remembered devices policies have no effect for Delegated Access to ensure a higher level of security. If you apply a remembered devices policy to Delegated Access, Duo ignores it.

  • Users in bypass status cannot use Delegated Access.

  • Duo ignores any policy that could bypass authentication, and all users must authenticate (or Duo blocks them if specified in policy). These include:

Set Up Delegated Access

Role required: Owner

To set up Delegated Access, you will need to add your users to a group, and then enable those groups to use Delegated Access. Once set up, MSP users can authenticate into their subaccount applications.

Add User to a Group

To add your user to a group or confirm groups you choose to permit to use Delegated Access:

  1. Log in to the Duo Admin Panel.

  2. On the main account, navigate to Users → Groups.

  3. Click on the group that you want to permit to use Delegated Access.

  4. Click +Add users to group. Select from the drop-down list the users you want to add to a group for use with Delegated Access.

  5. Click Add User to Group.

    Delegated Access Add User to Group
  6. Confirm which groups you intend to permit to authenticate into subaccount applications.

In the next step, you will enable these groups to use Delegated Access to access customer applications.

Enable Groups to use Delegated Access

To enable groups to use Delegated Access:

  1. While still in the main account, navigate to Accounts → Delegated Access.

  2. From the "Delegated Access" page, in the "Subaccount application access" section, select Enable for selected groups.

  3. Choose your designated group(s) from the drop-down list.

  4. Click Save access.

    Delegated Access Enable for Selected Groups
    • This setting allows only users in selected groups to log in to subaccount applications if their username exists in the application.

Edit Subaccount Policies

The "Policies" section on the "Delegated Access" page shows when and how users will authenticate when accessing subaccount applications via Delegated Access. Your global policy always applies, but you can override it with custom policies with custom group or application policies.

Duo evaluates policies on the main account, not the subaccount, when a user authenticates via Delegated Access, except for username normalization configured on the subaccount application. For more information, refer to the Policy documentation.

Delegated Access does not allow policies that bypass MFA, including Remembered Devices and Authentication policy.

Edit Settings

Use the "Settings" section on the "Delegated Access" page to add:

  • Voice greeting or message to users who use phone callback, followed by authentication instructions.
  • Notes - for internal notes.

To save your settings, click Save settings.

Delegated Access Save Settings

Authenticate Using Delegated Access

After a successful delegated authentication, the MSP main account user can log in with any of their existing authentication methods. There will be no enrollment prompt. If the user chose Duo Push as the authentication method, then the Duo Push notification will specify "Delegated Access - [Application Name]".

If the user receives an enrollment prompt, completing enrollment adds the user to the subaccount; this disables Delegated Access for that user until an admin deletes them from the subaccount.

The following diagram shows how Duo makes user decisions during delegated access.

Delegated Access User Decision Flow

Validate Authentication

To validate that Duo delegated the authentication to the user on the main account:

  1. Navigate to Reports → Authentication Log from the main account. If successful, you will see that the user was approved via Delegated Access. The user column will have the following structure: {Subaccount name} - {Subaccount application name}.

  2. You may also filter your Authentication Log by the Delegated Access application to see all attempts at delegated authentications.

You can view authentication logs for Delegated Access on the subaccount by switching to the subaccount and navigating to Reports → Authentication Log. The user column will have the following structure: Delegated Access:{main account user username}.

Frequently Asked Questions

Does Delegated Access work with all applications?

  • No, it does not support SSO applications.

How is policy evaluated?

  • Duo evaluates policy entirely on the main account. Regardless of what policy you configure on the subaccount and subaccount application, Duo only considers policy applied on the main account's "Delegated Access" page.

How are usernames normalized?

  • If a subaccount application has username normalization toggled on, usernames arrive at the main account already normalized. If the subaccount application does not enable username normalization, Duo only matches the username with the username on a main account if it is an exact match.

Can the delegated users be on a subaccount?

  • No, they must be on the main account.

Can you restrict which subaccounts an MSP user may use Delegated Access for?

  • No, not at present. If your organization needs this, please let us know.

Troubleshooting

Need some help? Take a look at our MSP Knowledge Base articles or Community discussions. For further assistance, contact Support.