Skip navigation

Duo Identity Security with Cisco Identity Intelligence

Last updated:

Duo Identity Security provides you with insights, signals, and remediation features across your multi-vendor identity environment.

Overview

Duo Identity Security combines Duo’s strong attack mitigation and remediation capabilities with cross-vendor identity insights powered by Cisco Identity Intelligence.

Cisco Identity Intelligence

Cisco Identity Intelligence (CII) is a multi-sourced, vendor-agnostic solution that works across your existing identity stack and brings together authentication and access insights, enabling you to proactively address vulnerabilities and risks in your multi-vendor identity environment.

Duo Premier and Duo Advantage editions include all Cisco Identity Intelligence features and capabilities.

Learn more about Cisco Identity Intelligence.

Requirements

To provision Cisco Identity Intelligence, you need:

  • A Duo Premier or Duo Advantage plan.
  • A Duo administrator with the Owner or Administrator role.
  • Everyone in your organization whom you want to be able to access the Cisco Identity Intelligence dashboard via Duo Single Sign-On should exist as an end-user in your Duo account or your SAML or Active Directory external authentication source, if you use them.
Duo User Data Requirement

If you sync users into Duo from Active Directory or Microsoft Entra ID, Cisco Identity Intelligence uses the source directory's unique identifiers to associate Duo identities with matching identities in other vendors.

If you do not sync users into Duo from Active Directory or Microsoft Entra ID, you must provide an email address in the username or email field for your Duo users in order for Cisco Identity Intelligence to map Duo user identities to corresponding identities in other data integrations. The email address used in Duo must match an email address in another integrated platform (e.g., Okta, Google Workspace, AWS).

Provision Your Cisco Identity Intelligence Tenant

Most customers have Cisco Identity Intelligence provisioned automatically. You can check your provisioning status by navigating to Identity IntelligenceProvision in the Duo Admin Panel.

  1. Log in to the Duo Admin Panel as an administrator with the Owner or Administrator admin role.

  2. Navigate to Identity IntelligenceProvision.

  3. Review the information on the "Cisco Identity Intelligence" page. Click the Connect to Cisco Identity Intelligence button to continue.

    Connect Cisco Identity Intelligence
    Most customers have Cisco Identity Intelligence provisioned automatically. If you see "Configuration Details" information instead of a connect button, skip to step 5.
  4. Duo automatically provisions your Duo integration with Identity Intelligence to enable your new Identity Intelligence tools to consume and analyze Duo user and authentication data.

    Cisco Identity Intelligence Duo SSO Configuration
  5. You should verify the user access and group mappings for the new CII SSO application. Click the Setup SSO Access button on the Cisco Identity Intelligence "Duo SSO" tab to view the SSO application.

  6. The CII provisioning process creates three groups in Duo for mapping CII role access: CII Admins, CII Help Desk, and CII Read-Only. For new tenants, Duo automatically adds the account owner to the CII Admins group. You should see that the "User access" setting for your autogenerated Cisco Identity Intelligence SSO application defaults to Enable only for permitted groups with the three CII role groups automatically selected. If these groups do not exist, you may create them manually. You may also add any Duo groups you already created that contain your CII administrators.

    Cisco Identity Intelligence Duo SSO User Access Restricted to Permitted Group

    Learn more about user access to applications.

  7. Scroll down to the "Role-based Access" section of the CII SSO application page. You should see default mappings in place as follows:

    CII role mapping Duo groups
    CII Admins CII Admins
    CII Help Desk CII Help Desk
    CII Read-Only CII Read-Only

    If you have other Duo groups containing your CII console access users, you can add them to the default CII role mappings with the drop-down selector.

    Cisco Identity Intelligence Service Provider Group Mappings

    If you do not plan to use one of the CII roles, you may remove it. Use the Add button to restore a CII role you've deleted. You may not add additional roles.

  8. If you made any changes to user access or to the group mappings, scroll down and click Save.

  9. Navigate to UsersGroups and populate the three CII groups with the Duo users who should have access to the CII dashboard by clicking each one's name and then clicking Add users to group.

    While you can't add users synced from external directories as members of the CII default groups, you can add groups managed by directory sync to the role mappings as described in the previous steps.

    Cisco Identity Intelligence Duo Groups

    See the Using Groups documentation for more detailed group management instructions.

  10. You can now use your Identity Intelligence tenant. Navigate to Identity IntelligenceIdentity Insights and click Open Identity Intelligence in the top right. This launches the Identity Intelligence dashboard from the Duo Admin Panel. Duo administrators logged into the Admin Panel with any role assigned can access the Identity Intelligence dashboard from this link to log in via Duo SSO.

    Make sure that any Duo admins accessing Identity Intelligence also exist as an end-user in Duo who is a member of the group granted access to the CII SSO application. Active Duo users in the permitted groups whose effective policy requires MFA can sign in to Cisco Identity Intelligence via Duo SSO. Active Duo users whose effective policy requires MFA who are not members of one of the CII permitted groups will receive an access error from Duo SSO. Review the warnings about user access.

    If you use an external identity source for SSO, also ensure the CII dashboard user exists there for primary authentication.

Next Steps After Provisioning

Duo automatically begins ingesting and analyzing your data after provisioning. Depending on how many identities exist in your environment, it can take a few days for all the data to fully synchronize in the Cisco Identity Intelligence tenant.

Create Additional Integrations

Set up additional available integrations to maximize the cross-vendor visibility that Cisco Identity Intelligence provides and to ensure protection of your full identity ecosystem.

View the status of your connected CII integrations in the Duo Admin Panel from the "Duo SSO" tab on the "Provision" page. Click Connect integrations or View all integrations to launch the relevant page for that action in the CII console.

Cisco Identity Intelligence Integration Status

Allow Write from CII to Duo

You may wish to permit CII to write information back to Duo, for example, to take remediation actions like disabling a compromised user or removing a suspicious phone. To enable this access:

  1. Navigate to Identity IntelligenceProvision and click on the Settings tab.

  2. Toggle on the Grant write resource option and look for confirmation that the setting has changed.

Identity Security Insights

The "Identity Security Insights" page provides a high-level summary of your identity security environment with data provided by Cisco Identity Intelligence. Duo administrators who are members of the appropriate Cisco Identity Intelligence SSO RBAC groups can view the "Identity Security Insights" page.

Navigate to Identity IntelligenceIdentity Insights to review your organization's current top risks. You can also launch Cisco Identity Intelligence directly from this page by clicking Open Identity Intelligence in the top right.

CII Identity Security Insights Page

Trust Levels in the Admin Panel

After provisioning, the Duo Admin Panel displays Cisco Identity Intelligence trust levels on the "Users" list page and individual user detail pages.

Users List

The "Users" page displays a "CII Trust Level" column. You can sort by trust level or use the single-click filter at the top of the page to show only untrusted users.

List of Users

User Detail Page

A user's details page shows their CII trust level information. Duo administrators who are members of the appropriate Cisco Identity Intelligence SSO RBAC group also see a View User in Identity Intelligence link, which launches the CII "User360" page for the selected user in a new tab.

CII Trust Level Information in User Details

Trust Level Values

Trust Level Meaning
Trusted Normal identity behavior; low risk.
Favorable Mostly positive signals with minor risk indicators.
Neutral Baseline trust level. Insufficient data to assess trust in either direction.
Questionable Some risk signals detected. Review is recommended.
Untrusted Significant risk signals detected. Action is recommended.
Unknown Not yet calculated (insufficient data, or the integration is not yet fully active).

For more information about CII trust levels, refer to the User Trust Level documentation.

Visibility and Cross-Launch Privileges

Any Duo administrator role with access to the "Users" page and user detail pages can view trust levels and associated tooltips. Only administrators who are members of the appropriate CII RBAC group see the link to cross-launch the related page in Cisco Identity Intelligence.

Integrations

Cisco Identity Intelligence can integrate with a number of vendors for data ingestion, ticketing, notifications, and SIEM usage.

You can read more about the integrations and find configuration instructions by following the links below.

Cisco Identity Intelligence can ingest data from the following sources:

Additionally, integrations are available for notifications, ticketing, and SIEMs:

Identity Security Insights

Identity Security Insights provides a high-level summary view of your identity security environment with data provided by the CII engine. Note that this page is only available to users in the appropriate CII RBAC groups.

To review your top risks across your environment:

  1. Log in to to the Duo Admin Panel as an administrator with the Owner or Administrator admin role.

  2. Navigate to MonitoringCisco Identity IntelligenceIdentity Insights.

  3. Review the information on the "Identity Security Insights" page.

You can also launch CII by clicking Open Identity Intelligence in the top-right corner.

Troubleshooting

Need some help? Take a look at our Identity Security Knowledge Base articles or Community discussions. For further assistance, contact Support.