Identify applications at risk from malicious attack by launching phishing assessments directly from the Duo Admin Panel. Send a customized email to recipients selected from your enrolled Duo users. Monitor the progress of your phishing campaign with custom reports. Once you’ve identified your most vulnerable users, you can implement granular user and device-based policies, including two-factor authentication.
If any of your users do enter their login information after clicking a link in your simulated email they'll see some tips about how to identify phishing emails in the future. Don't worry! Duo Insight doesn't see, collect, or record any of your users' credentials.
Role required: Owner, Administrator, or Phishing Manager.
Log in to the Duo Admin Panel and click Phishing in the left side bar. Once the "Phishing Campaigns" page loads, click the Create Campaign button.
Review the four steps to campaign creation, and then click Next.
Select a Duo group containing the users whom you want receiving these phishing email messages. Click Next.
Duo users need to have email addresses present in their account details to receive the phishing emails. If no members of the selected group have associated email addresses you'll receive an error trying to continue with campaign creation. Select a different group of users with email addresses, or update the details for your users to include email addresses via directory sync, CSV import, or manual entry.
Choose the email domain you'd like to use for the outgoing email address in the phishing emails. Click Next.
Select the recipients for your phishing campaign, and then click Next.
You'll be redirected to Duo Insight to complete campaign creation using your selected recipients.
Choose an application as the basis for your simulated emails, and then click Select Document Type in the lower right.
Choose a document type for your phishing email. You'll see different template options depending on the application you selected in the previous step. Click Craft an Email after selecting a document type.
Enter some information to identify the disguised phishing link. Click Edit Sender.
Enter a sender name and email address for the phishing simulation.
You'll need permission to run the campaign from your messaging or corporate security team. Select one of the well-known email domain administrator recipients from the list. Duo Insight sends an approval request to that address. Make sure the destination address you select can receive emails from external recipients!
Review all your specified options and click Launch Campaign! if everything is correct. You can send yourself a test phishing email before launching the campaign by clicking the Send a test phish to... button near the top.
You've created your phishing campaign! Once you return to the Duo Admin Panel you'll see the new campaign in the Pending Campaigns table.
When the administrator specified in step 11 approves the new campaign, Duo Insight emails your selected recipients.
Check in on your phishing campaign's progress from the Active Campaigns table in the Duo Admin Panel.
As your targeted users open the phishing email and take any additional actions the campaign summary information updates.
Click on the name of your phishing campaign to see more information, like the number of users who clicked the link or who entered their credentials on the Duo phishing site.
You'll see how many users opened the phishing email, clicked the link in the email, or entered their login credentials at the Duo phishing site. Duo also gathers information about outdated operating system versions, browsers, and browser plug-ins used to access the phishing site.
Click the User Activity tab lists all the campaign email recipients and their activity.
Duo Insight also emails you if any of your users enter their login information in the simulated application.
Any user who submits their login credentials gets reassured that their information wasn't actually captured, along with guidance on how to protect themselves against real phishing attacks in the future.
Use the results of your phishing campaigns to identify vulnerable applications in need of strong authentication, or create policies to notify users of outdated software or block all outdated devices from accessing your network, protecting from malware and associated vulnerabilities.