Skip navigation

Risk-Based Device Registration

Last updated:

Overview

Account takeover often begins with an attacker registering their own device to a compromised account. Duo's Risk-Based Device Registration feature closes that gap by evaluating new authentication device registrations for risk and giving you the controls to block suspicious devices before they can be used for two-factor authentication.

Risk-Based Device Registration is part of the Duo Advantage and Duo Premier plans.

Relationship to Risk-Based Authentication

Risk-Based Device Registration complements Duo's existing Risk-Based Authentication (RBA) capabilities:

  Risk-Based Factor Selection Risk-Based Device Registration
When it applies During authentication During device registration
Default mode Enforcement Preview (non-enforcing)
User impact Step-up to more secure authentication factors Device quarantined pending admin review
Remediation User completes secure authentication, or admin manually clears step-up. Admin manually restores access for quarantined devices.
Risk patterns Push harassment, unrealistic travel, country code mismatch, etc. Multiple device, network, behavioral, and geographic risk signals

Both features work together to protect your organization across the complete lifecycle of Duo device management.

How Risk-Based Device Registration Works

Risk-Based Device Registration automatically identifies and mitigates suspicious device registration attempts in Duo. When Duo detects a device registration that exhibits characteristics associated with account compromise, or when the user reports a registration activity as fraudulent, the device can be automatically quarantined. Once a device is quarantined, it cannot be used to complete any two-factor authentication until an administrator reviews and restores the device.

By default, Risk-Based Device Registration runs in Preview mode. In this mode, Duo detects and reports specific risk signals during device registration but does not enforce quarantine. You can review these detections in the Activity Log and decide whether to manually quarantine any of these devices.

When you are ready to switch to automatic enforcement, you can enable it from the configuration page and select the user groups it should apply to. Under automatic enforcement, Duo automatically quarantines a device when defined risk signals are detected. You can also choose to receive email notifications for selected administrators and end users when Duo quarantines a device. Refer to Enable Risk-Based Device Registration automatic enforcement for more configuration details.

How Risk is Assessed for Risk-Based Device Registration

When a user registers a new device, Duo evaluates the registration in real time against multiple threat detection dimensions.

The following are examples of the risk patterns evaluated by Risk-Based Device Registration:

  • User marked fraudulent registration: A user reported that a device was fraudulently added to their account by clicking No, it wasn't me or Report this activity in the email or Duo Push notification (if enabled in Settings).
  • Suspicious location mismatch: A device registration attempt originated from a location inconsistent with the user's authentication history, and the registration and activation locations do not match.
  • Malicious device: A device with a history of known malicious activity was used to register with a Duo account.
  • Suspicious device registered with multiple accounts: A device with a history of suspicious activity attempted to register with multiple Duo accounts.
  • Suspicious device manufacturer: A device registration attempt was made using a device from a manufacturer with an untrusted classification.
  • Suspicious authentication activity: A device registration attempt was associated with suspicious multi-factor authentication activity.
  • Suspicious network: A device registration attempt was initiated from an Autonomous System Number (ASN) associated with malicious activity.

These descriptions are intentionally generalized. In practice, each detection also incorporates additional risk indicators and suppression logic to help identify malicious activity while minimizing the impact on legitimate user behavior.

Manual Admin Actions to Quarantine or Restore Access

Regardless of your organization's risk-based device registration configuration, administrators with applicable permissions can manually quarantine any phone or restore access to any quarantined phone from the device details page. All actions are immediate. We recommend verifying with your users before restoring access for any quarantined phones. Refer to manually quarantining and restoring access for a device for more details.

Devices Phones Details Settings Status Quarantined

Administrators with Owner, Administrator, User Manager, Security Analyst, and Help Desk roles (or Custom Admin Roles with applicable permissions configured) can manually quarantine any phone.

Administrators with Owner, Administrator, User Manager, and Security Analyst roles (or Custom Admin Roles with applicable permissions configured) can manually restore access to any quarantined phone.

If you have enabled user notifications in Settings, users will receive an email notification when you manually quarantine or restore access for a quarantined phone under their account.

Notifications settings

Limitations and Known Issues

Duo Risk-Based Device Registration covers registrations from the Self-Service Portal. Registrations completed through the Admin API or completed by Duo administrators through the Duo Admin Panel are not covered at this time.

Enable Risk-Based Device Registration Automatic Enforcement

Role required: Owner or Administrator.

By default, the Preview mode: Don't quarantine authentication devices based on risk option is selected on the Risk-Based Device Registration configuration page and is applied to all users.

To enable Risk-Based Device Registration to operate with automatic enforcement:

  1. Log in to the Duo Admin Panel and navigate to DevicesRisk-based Device Registration in the left sidebar.
  2. Select Quarantine authentication devices based on risk in the “Configuration” section.
  3. In the "Apply to user groups" section, limit the user groups you would like the automatic enforcement to apply to, if desired.
    Note: Preview mode still applies to any users or user groups not selected in this section.
  4. In the "Notifications" section, you can enable notifications for administrators or users when a device is quarantined by automatic enforcement.
  5. For “Notifications for administrators”, click Send email notifications to the following admins when Duo quarantines a device and add at least one administrator.
    Note: Only administrators with permission to un-quarantine phones can receive notifications.
  6. For “Notifications for users", click Send an email to user when their device is quarantined.
  7. Click Save to apply these changes.
Risk-based Device Registration Configuration Page

Monitor and Triage in the Activity Log

Risk-Based Device Registration offers comprehensive logging and monitoring capabilities through the Activity Log to aid in investigations.

Risk Assessment in the Activity Log

The Risk assessment column provides information about any risks detected and whether Duo performed quarantine enforcement for applicable registration events.

Navigate to ReportsActivity Log in the Duo Admin Panel. Filter by Risk assessment to narrow results to risk-based device registration activities.

Hover your cursor over "Risk detected" and "Enforcement" to see more details in the tooltips. You can also click View details to see more data captured for this activity.

Activity Log Risk Assessment

For activities flagged by Risk-Based Device Registration Preview mode, the result is displayed as "Risk-based device registration not enforced" with blue alerts and tooltips.

Risk-based Device Registration Not Enforced

For activities flagged by Risk-Based Device Registration automatic enforcement mode, the result is displayed as "Risk-based device registration enforced" with red alerts and tooltips. Additionally, the quarantine enforcement is logged as a separate activity performed by the system, which distinguishes this activity from an administrator's manual quarantine actions.

Risk-based Device Registration Enforced

Refer to the Admin API documentation for more details about retrieving these logs via API.

Troubleshooting

Need some help? Take a look at our Risk-Based Device Registration Knowledge Base articles or Community discussions. For further assistance, contact Support.