<![CDATA[The Duo Blog]]> https://duo.com Duo's Trusted Access platform verifies the identity of your users with two-factor authentication and security health of their devices before they connect to the apps you want them to access. Mon, 24 Aug 2026 16:52:13 +0000 en-us info@duosecurity.com (Amy Vazquez) Copyright 2026 3600 <![CDATA[How Cisco Duo secures identity for education institutions]]> jsulliv3@cisco.com (John Sullivan) https://duo.com/blog/duo-identity-security-education https://duo.com/blog/duo-identity-security-education AI Security Thu, 27 Aug 2026 04:00:00 +0000

Security leaders at universities, colleges, technical schools, and local K-12 school districts all share a common goal: to make learning safe and enjoyable for students and teachers from any location, and any device. With ransomware attacks targeting education rising 23% year over year in 2025, security teams face a formidable set of challenges around securing identity. Identity and access management (IAM) for education is the practice of verifying and controlling access for large, fast-changing populations of students, faculty, and staff across campus, remote, and BYOD environments. The core challenges include:

  • Keeping track of large, constantly changing user populations

  • Protecting sensitive personal information like social security numbers, payment data, and medical records

  • Rapid change as infrastructures evolve to support remote learning, BYOD, and cloud-based learning applications

  • Increasing risk from AI-powered phishing and MFA fatigue attacks targeting credentials

Whatever goals and hurdles they face, Cisco Duo helps CISOs at learning institutions level the playing field.

Many schools operate with limited budget and skills to level-up identity security. With limited resources compared to other sectors, security leaders are under pressure to protect highly privileged information and offer a fast, flexible user experience at the same time.

Duo offers an end-to-end identity and access management (IAM) solution that scales to help learning institutions protect thousands, or even tens of thousands of identities while improving their user experience and security posture at the same time. Diverse examples of learning institutions turning to Duo to solve identity security challenges include:

  • The University of Toronto, a global leader in learning, teaching and research, saw account compromise drop to nearly zero after rolling out Duo across more than 124,000 users. Duo also lowered operational costs by reducing the analyst hours spent on account recovery.

  • Eastern Michigan University (EMU), comprised of seven colleges and schools, was one of many colleges and universities to use Duo to strengthen its phishing-resistant authentication, protecting 26,000+ user accounts and secure servers across its multi-site infrastructure.

  • The School District of Philadelphia's Office of IT Security (OITS) relies on Duo to deliver strong security and an optimal user experience city-wide.

  • Trident Technical College, a two-year community college in South Carolina, leverages Duo in tandem with other Cisco Security solutions to advance its Zero Trust journey.

  • Virginia-based Washington and Lee University, one of the oldest colleges in the United States, used Duo's complete IAM solution to streamline cloud migration and support remote access.

Hundreds of other schools, colleges, and universities have adopted Duo's flexible, phishing-resistant multi-factor authentication (MFA), single sign-on (SSO), and identity intelligence to achieve similar benefits, sometimes choosing Duo over "free" MFA that comes bundled with basic security suites.

"Microsoft was free and easy, but we chose Duo because we trust Duo more," Trident College's CIO M.G. Mitchum explains, adding that, "For privileged accounts, for the real crown jewels, we put them behind Duo."

Complicated security is sometimes akin to no security at all because students and staff members will go to great lengths to avoid using it. Duo delivers security-first IAM that includes MFA, SSO, directory capabilities, and a completely passwordless authentication that's easy to adopt and even easier to use.

The University of Toronto's acting CISO Deyves Fonesca said, "The biggest concern for most researchers when it comes to a new solution is whether it will create more friction: Will it stand between them and the work? Can they still use the software that allows them to work most effectively?"

Andrew Speese, Deputy CISO at the School District of Philadelphia's Office of IT Security (OITS), a Duo Advantage customer since 2021, echoes the need to balance user satisfaction and strong security. "It's always about usability both on the IT admin side and user side," Speese says. "Duo gives us tons of options and flexibility to make the user experience very easy. We can go from SMS authentication to using tokens and run it all from one platform, and it all integrates and works 'super-easy' both for users and for my team."

Noting the Duo application makes it easy for non-technical people to ramp up identity security quickly, Speese calls this usability advantage "the number one reason I recommend Duo to other CISOs."

Cisco's recent survey of CISOs from a variety of industries highlighted the growing challenge of managing the "joiner, mover, leaver" (JML) lifecycle, especially as organizations extend more trust and privileges to AI agents and other non-human identities (NHIs). The challenge is front-and-center for security teams at high schools and higher education institutions where roughly a quarter of their user populations turns over every year.

Duo helps streamline the identity account management lifecycle with easy onboarding, flexible authentication options, and support for organizations' bring-your-own-device (BYOD) initiatives.

Users can self-enroll in MFA from any location without needing IT support, and IAM teams can quickly terminate access as students graduate or accumulate too many privileges. Complete visibility and granular control that decrease the risks associated with phased rollouts, overprovisioning, and centralized management of campus- or even city-wide deployments.

Duo helps progressive institutions like the University of Toronto extend flexible MFA options to users logging in from campus buildings, home, remote sites, and public Wi-Fi hotspots like coffee shops and bus stations. Further, higher education must protect a greater variety of operating systems and browsers. Fonesca recalls leading the university through a rapid transition to remote learning during COVID.

"A one-size-fits-all approach was off the table," the acting CISO said. "We had to find creative solutions to address the diversity of our campus while quickly maturing our cyber capabilities."

While allowing users to choose from a range of popular authenticators for a familiar login experience, Duo equips security analysts to enforce risk-based authentication policies that protect both school-issued laptops and personal devices from being compromised.

Schools also face challenges in supporting and securing BYOD initiatives that go hand-in-hand with hybrid learning. Trident College CIO M.G. Mitchum says Duo's ease of enrollment and onboarding helps the college support and extend phishing-resistant MFA across its growing BYOD initiative.

"We just have . . . too many endpoints that we don't own and we don't control, that we're being required to allow access. So, the challenge going forward, from a Zero Trust perspective, is ensuring those devices are in fact secure and that we do trust [them]," Mitchum says. "People saw how simple it was to implement, so it's been a very seamless and very, very good experience."

Washington and Lee University in Virginia is one of many academic facilities to implement Duo MFA with Cisco Identity Intelligence (CII) across the college to bridge the gap between authentication and access and provide deeper insights into identity-based risk. As one of the oldest liberal arts universities in the U.S., the university's small security team plans to continue leveraging Duo's integration with CII to improve IAM into the future. Goals include consolidating and correlating more user data across the district's various security stacks.

IT Systems Analyst Karla Bunn says, "Cisco Identity Intelligence has already been invaluable in identifying attacks—for example, a student apparently trying to log in from multiple countries at the same time—and finding and removing old unused accounts."

Looking to the future, the next major challenges will likely center around AI. Like many learning institutions, the OITS team has already noticed "an explosion of different security-related use cases" stemming from the rise of generative AI. Speese says, "We're definitely seeing an uptick in phishing incidents and internal-facing phishing attacks in our environment."

Many large, well-established organizations maintain decades-long investments in Active Directory. To support the consolidation and centralized management of identity providers (IdPs), Duo's Active Directory Defense capabilities deliver MFA insertion for legacy applications and hard-to-protect privileged access. It also adds rich on-prem context to Cisco Identity Intelligence, bridging visibility gaps and accelerates investigation and resolution of user issues.

Even schools whose mission includes fostering life-changing innovation struggle with their own modernization journeys. "Everyone is trying to digitize all the time and roll out new applications," says OITS's Andrew Speese, whose team manages nearly 25,000 Duo licenses as they protect employee and contractor identities across Philadelphia. "There's always some new educational app, or city-wide or district-wide initiative that's technology-enabled, and we end up playing in it."

While looking to adopt new learning applications, IT and security teams must maintain older, deeply entrenched technologies longer than other industry sectors. "We still have a lot of legacy systems so some of the things we inherited aren't great," Speese explains, noting the City of Philadelphia uses Central Authentication Service (CAS), an open source SAML platform as a more cost-effective solution for enabling SSO than Microsoft Active Directory (AD). Duo helps bridge the gap between affordability and control.

"We use the Duo reporting feature constantly because it sits at the front door for everything and pulls everything in," explains Speese. "We get all this nice context-driven data that's difficult to achieve with any other tool because every other identity tool on the market was developed for Active Directory."

Trident College uses the Duo Advantage edition in conjunction with other Zero Trust, WiFi, and firewall solutions from Cisco as part of a coordinated effort to protect more than 14,000 students. CIO M.G. Mitchum says working with one strategic partner delivers greater value than implementing a bunch of point solutions.

"Chasing the best of breed was not working for us," he explains. "It was expensive; we weren't implementing it." Standardizing around Cisco security solutions also helps the college reduce costs by making it easier for analysts to ramp up and manage multiple technologies. "It takes time to get people up to speed," Mitchum notes. "I needed technology that looked similar, acted similar, and had the same support structure so I didn't have to reinvent the wheel each time."

The success stories described here are just a few examples of how educational institutions and other organizations use Duo's complete IAM solution to resolve a wide range of identity security challenges. Browse through our Resource Center to read these and other case studies in their entirety.

Learn more about Duo for Higher Education and Duo for K-12 Education, or reach out and see how Duo can help your organization today.

]]>
<![CDATA[Identity security is now a business change agent]]> mcaulfie@cisco.com (Matt Caulfield) https://duo.com/blog/identity-security-2026 https://duo.com/blog/identity-security-2026 AI Security Sun, 23 Aug 2026 18:30:00 +0000

In identity security, the hardest questions often sound simple.

Who should have access? What should they be allowed to do? What happens when they change roles, leave the company, join as contractors, or create AI agents to act on their behalf?

These questions are not new, but the speed, scale, and stakes around them have changed. To better capture how identity is shifting, Cisco Duo engaged third-party research firm AimPoint Group to interview more than two dozen CISOs and security executives across industries and company sizes.

The final 2026 CISO Perspectives report shows how identity has become both a challenge and a potential change agent. Here are four key takeaways.

Artificial Intelligence (AI) adoption has renewed urgency around identity and access management (IAM). Identity security is a top-three priority for most organizations; AI-driven business questions run through security, and nearly every important security question now runs through identity.

If you do not know who or what has access to your environment, what credentials they are using, what they can reach, and what data they are touching, you cannot make good security decisions.

For years, security and IT teams have been trying to solve this problem for human users. The joiner, mover, leaver (JML) lifecycle has always been harder than it looks: people change roles, contractors come and go, legacy systems get passed from admin to admin, and privileges silently accumulate.

In the report, security leaders identified the traditional JML lifecycle, third-party access, and non-human identities (NHIs) as contributors to identity sprawl and complexity. More than half expressed concern about managing leavers in particular. In our previous report on the State of Identity Security, we found that a significant 86% of leaders expressed concern about inadequate controls for contractors and third-party access.

"Any issues with an identity usually come down to lifecycle management."

-Head of Identity Governance and Architecture, electric utility company

"A successful IAM program relies on collaboration across multiple departments and partners. It involves your security team, provisioning team, HR, management, and vendor partners working together to define and uphold appropriate processes, roles, and permissions."

-Monique Hart, CISO, Piedmont Healthcare

That lifecycle gap matters because identity risk is not limited to login. Identity security extends across the full lifecycle: enrollment, access, authorization, privilege changes, device posture, session activity, help desk flows, and eventual deprovisioning. CISOs must reduce real risk while maintaining business continuity.

Every CISO we spoke with mentioned agentic AI, and for good reason. But if you work in identity, you immediately see the second-order questions: How do we give access to agents? How do we monitor their behavior? And how do we control things like data exfiltration?

Security leaders repeatedly pointed to agentic AI as a force that could exponentially increase identity sprawl, or a rapid expansion of identities, permissions, and access paths without consistent visibility or control.

"Agentic AI is not two or three years away; it's here, and there's little governance over it."

-Head of Identity Governance and Architecture, electric utility company

"I think the agentic AI footprint, as it starts to manifest, is going to create a ton of issues for us, and nearly all of them involve identity. Because these are machine identities, there's going to be an inherent trust with the agent-to-agent communication."

-Business Information Security Officer, Product Security, data management platform provider

AI agents are not just another application category; they are autonomous actors that can query data, trigger workflows, communicate with other systems, and operate at machine speed. They may inherit credentials or touch sensitive resources in ways existing identity systems were never designed to govern.

To secure these new workflow demands, organizations need identity, access, and behavior working together. We can give agents the right tokens all day long. But unless you are in the path between the agent and the resource, you cannot enforce anything or look at the specific actions being taken in real time.

That is why leaders believe agentic AI will become a catalyst for broader security modernization, forcing organizations to address what secure access looks like while closing gaps in visibility, cleaning up overprivileged accounts, and improving lifecycle controls.

While we’d all love to spend our time just focused on the new stuff, the reality is organizations still face existing identity infrastructure challenges.

The board wants AI, the business wants speed, and yet security must stay comprehensive. Underneath a drive for digital transformation, organizations may still be holding on to legacy identity systems, generations of service accounts, and applications with password-only systems that were never designed for the world we are moving into.

"AD has been in place for 20 years, it's a foundational piece and people are trying to move away, but there've been so many hands inside of AD that it's indecipherable, and unfortunately, you drag that baggage with you."

-CISO, ecommerce company

Active Directory and other legacy identity providers remain foundational, but they also carry decades of operational baggage. Take overused service accounts as an example. You use it for one script, then you just borrow the same service account for the next script you write—no harm done.

Now imagine that same pattern in an agentic AI environment: every agent spun up could be using the same old service account that was created years ago, with very little tracking around what it can access or why it still exists.

Modernization has to be practical. Most organizations cannot rip and replace identity infrastructure overnight. They need ways to consolidate, improve visibility, add stronger controls, and protect legacy authentication flows while keeping the business running.

Sometimes reducing risk means cleaning up traditional NHIs or extending MFA into a legacy environment. While not glamorous, this is where reducing tech debt can meaningfully reduce risk.

"With AI, phishing is more convincing, deepfakes are more convincing, and now you can automate credential stuffing. All of a sudden it's . . . you don't sleep nights."

-Joe Russo, Vice President IT and Security, ISAAC

AI makes phishing, deepfakes, credential stuffing, and social engineering more convincing, scalable, and adaptive. It can be used to find and exploit “edge case” weaknesses in security.

One of the most important themes in the report is that CISOs are not just blindly adopting the newest controls. Rather, they are adapting existing Zero Trust principles of zero standing privileges and continuous verification to new scenarios.

"A success is not having a breach that is attributed to an identity and recognizing that the majority of the breaches start with some sort of credential theft or credential compromise."

-Anahi Santiago, CISO, ChristianaCare

Identity modernization is not just about reducing logins or simplifying user experience, but also about building a Zero Trust identity program that can automate and adapt as AI changes both threat and defender landscapes.

My takeaway from the interviews is this: the organizations that move fastest will not be the ones that pretend they can skip the hard identity work. They will be the ones that build visibility, accountability, and security into identity from the start, while modernizing what already exists.

At Duo, we think about that as security-first IAM grounded in Zero Trust principles: deployable phishing-resistant authentication, identity verification at critical workflows, and tools to secure both legacy AD environments and the agentic systems emerging now.

For more CISO perspectives, head to duo.com/CISO and download CISO Perspectives: Identity is a Challenge and Change Agent in 2026 to hear from your peers on the priorities of today and what they believe will matter most in the year ahead.

]]>
<![CDATA[Cisco Duo Federal Edition High Class D Now Generally Available]]> aldavids@cisco.com (Alair Davidson) https://duo.com/blog/duo-federal-edition-fedramp-high-class-d-ga https://duo.com/blog/duo-federal-edition-fedramp-high-class-d-ga Industry News Tue, 11 Aug 2026 00:00:00 +0000

I’m excited to announce that Duo Federal Edition FedRAMP High Class D certification is now generally available! This represents a significant milestone in our commitment to supporting U.S. Federal, State, and Local Government agencies with enterprise security solutions that meet strict compliance requirements.

Cisco Duo Federal Edition High Class D is a FedRAMP High Class D (IL4) authorized instance of our authentication solution, purpose-built specifically for U.S. Government requirements and compliance standards. It’s a cloud-delivered multi-factor authentication solution grounded in zero trust principles that provides seamless, transparent, and phishing-resistant user access from both desktop and mobile devices to any application—whether internet-based, SaaS, or private applications hosted in the cloud or on-premises.

Duo Federal Edition FedRAMP High Class D is built for the environments you actually operate in:

  • Federal agencies handling mission-critical workloads

  • Contractors supporting defense and national security programs

  • Organizations navigating CMMC requirements

  • Hybrid workforces accessing systems from anywhere

Whether you're securing privileged access, contractor access, or distributed users, Duo helps ensure that every login is verified, contextual, and trusted.

For organizations in the Defense Industrial Base (DIB), CMMC 2.0 places a renewed emphasis on protecting Controlled Unclassified Information (CUI) through stronger identity and access controls. Requirements aligned to NIST SP 800-171—such as multi-factor authentication, device access control, and continuous monitoring—are foundational to achieving compliance. Duo Federal supports these outcomes by delivering phishing-resistant authentication, verifying device health at access, and enforcing adaptive policies that align with Zero Trust principles expected in CMMC environments.  Read more: National Security Agency: Selecting Secure Multi-factor Authentication Solutions.

We often hear this from customers: “We already have MFA—why do we need Duo?” The answer is simple: because modern threats have evolved faster than traditional authentication.

Here’s where Duo stands out:

  • Authentication + device trust in one solution
    Many organizations use separate solutions for identity and endpoint visibility. Duo brings them together at the point of access.

  • Phishing resistance built in—not bolted on
    With support for FIDO2 and PIV/CAC, Duo helps reduce exposure to many credential-based attack techniques through phishing-resistant authentication.

  • Works across everything—not just one ecosystem
    Duo supports a wide range of platforms and application environments

    • Microsoft apps

    • Non-Microsoft apps

    • Legacy systems

    • Contractor access scenarios

  • Fast to deploy, easy to use
    Security only works if users adopt it. Customers often cite Duo’s simple user experience, rapid deployment, and streamlined administration.

This isn’t just another point solution. Duo is a critical part of our SASE - Secure Access Services Edge solution for customers requiring TIC3.0 compliance. The Cisco Security Cloud for Government certification includes:

And for a complete solution, Cisco also offers:

Most solutions stop at authentication.  Duo combines strong authentication with device context and adaptive access policies to help organizations enhance access security and support alignment with evolving regulatory requirements.

Cisco Duo Federal Editions meet the authorization and compliance requirements that matter most to government agencies:

  • FedRAMP High (IL4) Class D and FedRAMP Moderate (IL2) Class C authorizations

  • Government Community Cloud ready

  • GovRAMP (formerly StateRAMP) authorized

  • TX-RAMP authorized for State governments

  • Meets CONUS, FIPS 140-3, and NIST 800-53 standards

  • Helps government contractors meet Cybersecurity Maturity Model Certification (CMMC) requirements

Ready to modernize your agency’s security posture with zero trust architecture? Explore the comprehensive resources available:

Documentation and Resources

Technical Release Notes

Cisco Duo Federal Edition represents our commitment to delivering mission-critical security solutions that meet the unique needs of government agencies.

]]>
<![CDATA[SAML, OAuth, or OIDC: How to choose the right protocol]]> duo@duo.com (Cisco Duo) https://duo.com/blog/authentication-protocol-decision-guide https://duo.com/blog/authentication-protocol-decision-guide Product & Engineering Mon, 20 Jul 2026 18:30:00 +0000

Choosing the right authentication protocol depends on your applications, your user types, and the protocols supported by your identity provider. This article considers these three main factors, and others, explaining how modern organizations deploy protocols, their best use cases, and common security risks introduced during configuration.

  • Most organizations use more than one protocol. Match each protocol to the right use case and manage them through a single identity platform, not to consolidate onto one standard.

  • SAML remains widely deployed for enterprise single sign-on, with a market projected to grow through 2033. Use it for legacy applications and deployments that do not neatly communicate with newer protocols like OIDC.

  • OIDC and OAuth 2.0 are built for modern and mobile applications. OIDC verifies who the user is. OAuth 2.0 governs what a third-party application can do with their account. If your stack is moving toward cloud-native architectures, these are the protocols that fit.

  • No protocol is inherently more secure than another. Each has specific implementation risks. These include XML signature validation for SAML, token lifetime management for OIDC and OAuth, and scope creep for OAuth. Security depends on configuration, not which standard you chose.

Not yet. Claims that "SAML is dead" surface in identity discussions every year or two, as newer standards emerge. Security Assertion Markup Language (SAML) 2.0 was standardized in 2005, which makes it old by software standards. However, asking whether SAML is outdated is different from asking whether it's obsolete. The SAML authentication market was valued at roughly $1.2 billion in 2024 and is projected to grow at a 15.3% CAGR through 2033. That is not the trajectory of a dying standard.

SAML remains the backbone of enterprise single sign-on, with large organizations running SAML integrations across applications like Salesforce, Workday, AWS Console, and Microsoft 365. When an employee at one company needs to access a partner's application without a separate login, SAML is typically what makes that work. The "dead" narrative reflects the rise of OpenID Connect (OIDC) and OAuth 2.0 for newer use cases, including mobile apps, single-page applications, and API-first architectures. SAML’s XML-based approach doesn’t naturally fit these cases.

The question is not whether SAML is dead. It’s which protocol fits your specific needs. For a detailed technical comparison of all three protocols, see our article, SAML vs. OAuth vs. OIDC explained.

Choosing an authentication protocol is a practical decision influenced by three factors: your applications, your users, and your identity infrastructure.

SAML was designed for traditional web applications that run on a server and communicate through browser redirects. It exchanges XML assertions between the identity provider, which stores user information, and the service provider—the app itself.

This model maps cleanly to the way enterprise web applications have worked for two decades. If most of your applications are server-rendered enterprise tools with established SAML integrations, then SAML may be the only protocol they support, or at least the one they were designed to run on. Providing they are properly configured, there’s nothing wrong with keeping those integrations in place.

OIDC and Open Authorization (OAuth) 2.0 were designed for a different architecture. Single-page applications, mobile apps, and API-first services don't communicate through browser redirects and XML. They use Representational State Transfer (REST) endpoints and JSON, which are lighter, faster, and native to the way modern applications are built.

OIDC handles authentication in this context: it verifies who the user is and returns that identity as a JSON Web Token. OAuth 2.0 handles authorization: it governs what a third-party application can do with a user’s account, without ever sharing the user's password. If your application portfolio is moving toward cloud-native architectures, these are the protocols that fit.

Workforce identity has historically run on SAML. Employees log in to internal tools and SaaS applications through an enterprise identity provider, and most of those providers ship with SAML support built in. Most SaaS vendors accept SAML assertions for single sign-on (SSO). Learn more about the difference between SAML and SSO here. For enterprise workforce SSO, the choice between SAML and OAuth comes down to what is already in place. If your organization already has these integrations running, SAML is doing its job.

Customer identity tells a different story. Consumer-facing applications, partner portals, and mixed user populations lean toward OIDC because it supports social login flows ("Sign in with Google" for example), handles mobile authentication cleanly, and uses JSON Web Tokens (JWTs) that modern frontend frameworks can parse directly.

The OpenID Foundation reports that OpenID Connect is now used by billions of people across millions of applications. If your user base includes customers, partners, or contractors who authenticate outside your enterprise directory, OIDC is designed for these users.

Most modern cloud identity platforms support both SAML and OIDC. The deciding factor often comes down to what your applications accept. Some legacy applications only speak SAML. Some modern applications only speak OIDC. Understanding when to use SAML, OAuth, and OIDC [LINK TO: Learn article C30] at the protocol level helps inform which integrations require which protocol.

Is OAuth more secure than SAML? Is OIDC safer than either? No protocol is inherently more secure than another. The difference between a secure implementation and a vulnerable one comes down to configuration, not which standard you choose. That said, each protocol has characteristics that affect security in practice.

  • SAML assertions are XML-signed and validated against the identity provider's certificate. The assertion is self-contained, so the service provider can verify it without calling back to the identity provider.

    • The risk: XML signature validation can be complex to correctly implement, and gaps in that logic could expose the system to signature wrapping attacks.

  • OAuth 2.0 access tokens are opaque to the client. The application passes them along without inspecting their contents. This limits exposure if client-side code is compromised.

    • The risk: The client has no way to detect a tampered or expired token on its own. It relies entirely on the authorization server.

  • OIDC uses JSON Web Tokens (JWTs) with standardized validation libraries available in most languages. Implementation is straightforward.

    • The risk: Developers who skip signature verification or fail to check the issuer and audience claims can undermine the entire validation chain.

  • SAML assertions have short validity windows, typically measured in minutes. A stolen assertion expires quickly on its own.

    • The trade-off: short lifetimes mean more frequent re-authentication, which can create friction for users in long work sessions.

  • OAuth 2.0 supports refresh tokens that let applications request new access tokens without forcing the user to log in again. Sessions stay alive without re-exposing credentials.

    • The trade-off: refresh tokens can persist for days or weeks. A stolen refresh token stays useful until explicitly revoked, so teams need active token rotation and revocation built into their implementation.

  • OIDC inherits OAuth 2.0's refresh token model and adds session management capabilities through its session management specification.

    • The trade-off is the same: long-lived tokens require disciplined lifecycle management, or a compromised token becomes a persistent backdoor.

  • SAML: Signature wrapping attacks and assertion replay are the primary risks. Both are preventable with proper validation, but the XML signature model has more surface area for implementation mistakes than JSON-based alternatives.

  • OAuth 2.0: Open redirect vulnerabilities and scope creep. Teams often grant applications broad permissions during development and never tighten them for production. Every scope should be as narrow as the application's function allows.

  • OIDC: Omitting the nonce and state parameters in authentication requests can allow token replay attacks. These parameters are easy to include and easy to forget, especially when developers copy example code that skips them.

All three protocols require TLS (Transport Layer Security) for transport. None is inherently safer than the others. The question is which security model your team is better equipped to implement and maintain correctly.

The protocol you choose matters less than how carefully you implement it. Most authentication vulnerabilities trace back to misconfiguration, not protocol design.

In practice, most enterprises do not pick a single protocol; they use several. A 2025 analysis found that 72% of enterprises now run multi-protocol SSO environments. SAML is commonly deployed for legacy enterprise application SSO, while OIDC enters the picture for modern and mobile applications, and OAuth 2.0 for API authorization, with all managed through a single identity platform.

The goal is not to eliminate SAML or consolidate onto one protocol. Instead, adopt the right protocol for each use case and unify management. An organization might have 200 SAML integrations with established SaaS vendors and a growing set of OIDC integrations with newer cloud applications. Both can coexist, and both can be governed from the same identity provider. The risk is not in having multiple protocols. The risk is in managing them through separate, disconnected systems with potentially inconsistent policy enforcement and session revocation.

Identity platforms like Cisco Duo support both SAML 2.0 and OIDC through Duo Single Sign-On, which means organizations can manage hybrid protocol environments from one place. Duo also supports passwordless authentication built on OIDC and FIDO2/WebAuthn standards—so the same platform that handles legacy SAML integrations can also support the modern authentication protocols organizations are moving toward.

See how Duo handles SSO for SAML and OIDC apps.

Ready to simplify how your organization handles authentication across protocols? Try Duo for free.

]]>
<![CDATA[Why your identity architecture needs a cloud-native rethink]]> duo@duo.com (Cisco Duo) https://duo.com/blog/identity-orchestration-cloud-native-iam https://duo.com/blog/identity-orchestration-cloud-native-iam Industry News Fri, 17 Jul 2026 00:00:00 +0000

Most organizations have outgrown their identity infrastructure. The Identity Provider (IdP) configurations and directory services that worked five years ago were not designed for distributed workforces, hundreds of cloud applications, and machine identities that outnumber people. Here, we cover the principles of designing an identity architecture that keeps up.

Explore Duo's approach to identity

  • Legacy identity infrastructure creates security blind spots and operational drag that compound as organizations grow.

  • Cloud-native IAM is not just cloud-hosted identity. It is an identity built for API-driven, distributed, continuously verified environments.

  • Identity orchestration platforms coordinate authentication across multiple identity sources, devices, and risk signals to make dynamic access decisions.

  • An identity management roadmap starts with consolidation and ends with continuous verification. Most organizations are somewhere in between.

Most identity infrastructure was designed for a specific moment: everyone works in the same building, every application runs on the same network, and the IT team provisions accounts by hand. That moment has passed.

The directory services and IdP configurations many organizations still rely on were built for on-premises environments with a fixed number of users and applications. They work well in that context. But when the workforce goes remote, applications move to the cloud, and contractors need access alongside employees, these systems face pressure they were not designed to handle.

Remote or distributed environments add complexity. Provisioning a new employee can take days instead of minutes when accounts have to be created manually across dozens of applications. Offboarding is worse. A forgotten account in a decommissioned system can become an unmonitored entry point—still active, still holding permissions, but no longer on anyone's radar. Password reset tickets consume help desk capacity that could go elsewhere. And every disconnected identity tool adds a gap that security teams have to monitor separately.

None of this makes legacy systems bad. They are simply a mismatch for this environment. That gap is where most identity management transformation efforts begin.

Cloud-native IAM is not the same thing as cloud-hosted identity. Hosting an on-premises directory in someone else's data center does not make it cloud-native. In that case, the infrastructure may change location, but the architecture remains the same.

Cloud-native IAM means the system was designed from the start for how modern organizations work: API-driven, elastically scalable, protocol-flexible. These are built to handle distributed users, devices, and applications without requiring the IT team to manage the underlying infrastructure.

At the center of any cloud-native IAM strategy is the identity provider, the system responsible for authenticating users and passing verified identity to applications. The IdP is the foundation. Our complete guide to identity providers explains how IdPs work, what to look for, and how to evaluate your options. Cloud-native IAM extends that foundation with capabilities like adaptive authentication, device trust, automated provisioning, and centralized policy enforcement across every connected application.

For organizations managing SaaS identity and access management across dozens of applications, this distinction matters. A cloud-hosted IdP may still require manual configuration for each new application. A cloud-native identity platform handles that integration through standard protocols and automated provisioning, which can reduce the time from days to minutes.

Modern identity architecture design starts with a principle: separate authentication from the applications that depend on it. When applications manage their own credentials, every application becomes a potential point of compromise because each one stores and verifies passwords independently. When a centralized IdP handles authentication and passes signed assertions to applications, credentials live in one place and security policy applies consistently.

That separation is the foundation. The architecture built on top of it determines whether the organization can adapt as requirements change.

The IdP is the first decision in any identity architecture because it defines so many others downstream. Protocol support determines which applications can connect. MFA enforcement determines how well the authentication layer resists phishing. Directory integration determines whether existing employee records can carry over or need to be rebuilt. Automated provisioning, device trust, and adaptive access all build on what the IdP provides.

An IdP that supports SAML for legacy enterprise applications, OIDC for modern cloud tools, and SCIM for automated account provisioning gives the organization protocol flexibility without requiring application-by-application configuration. That flexibility becomes critical as the number of connected applications grows.

A single IdP works well when the organization has one identity source and one set of access policies. Most organizations have outgrown that model. Common issues include:

  • A company acquires another company that runs a different IdP.

  • Contractors arrive with their own identity credentials.

  • Customer-facing applications require a separate authentication flow from internal tools.

This is where an identity orchestration platform fits in. Rather than replacing what already works, orchestration coordinates authentication across multiple identity sources. It routes each access request to the right provider based on who the user is, what they are trying to reach, and what risk signals are present. Device posture, location, login behavior, and time of day all factor into the decision.

The result is not a bigger IdP. It is an identity layer that sits above the IdPs and makes dynamic access decisions across all of them. Identity-related incidents affected 90% of large organizations in 2024, with 84% reporting a direct business impact (IDSA, 2024). Consistent policy enforcement and centralized credential management shrinks the gaps between disconnected tools. And during acquisitions, teams can authenticate through their existing IdP from day one instead of waiting for a full migration.

Identity management transformation does not happen in a single project. It happens in phases. Each phase delivers immediate value while setting up the next. Here is a practical sequence that works regardless of where the organization starts.

  1. Consolidate identity providers. Audit how many IdPs, directories, and authentication tools the organization uses today. Identify redundancies. The goal is not to collapse everything into one system overnight. It is to map what exists so the organization can make informed decisions about what to keep, what to merge, and what to retire.

  2. Enable cloud-native SSO and MFA. Connect applications to the consolidated IdP using standard protocols. Enforce MFA at the IdP layer so every connected application inherits the same authentication standard. Prioritize phishing-resistant methods like passkeys and biometrics over SMS codes.

  3. Add device trust and risk signals. Authentication answers who someone is. Device trust answers whether the device they are using is secure and up to date. Combining both gives the IdP the context it needs to make better access decisions. A known user on a compromised device is still a risk.

  4. Move toward continuous verification and orchestration. Replace point-in-time authentication with continuous assessment. Layer in orchestration to coordinate across multiple identity sources. This is the phase where the identity architecture becomes adaptive, making real-time decisions based on behavior, risk, and context rather than static rules.

If the roadmap is straightforward, why do so many organizations stall at phase one?

Legacy application dependencies limit your options
Some applications were built to authenticate against a specific directory and cannot easily point elsewhere. These applications anchor the organization to its current identity infrastructure regardless of what the rest of the environment needs. The workaround is federation or protocol bridging, not a full migration.

Organizational inertia slows buy-in
Identity infrastructure touches every user and every application. Teams that have managed the same directory for a decade may resist a transition, not because the current system works well, but because the cost or perceived risk of getting the transition wrong feels higher than the cost of staying put.

Budget constraints prioritize other projects
Identity projects compete with every other security and IT priority. The business case is clearest when the organization can quantify the cost of the current state: hours spent on manual provisioning, tickets generated by password resets, incidents traced to identity gaps. Without those numbers, identity modernization stays in the backlog.

Skills gaps leave teams uncertain
Cloud-native IAM requires different expertise than managing an on-premises directory. Protocols like OIDC, concepts like device trust, and tools like SCIM-based provisioning are not part of every IT team's current skill set. Training and hiring are part of the roadmap, not a prerequisite.

None of these blockers are permanent or insurmountable. And they respond to the same approach: start with the audit, quantify the cost of the current state, and build the business case one phase at a time.

Whether you are consolidating identity providers, evaluating cloud-native IAM platforms, or planning your first step toward orchestration, a conversation with someone who has seen the full range of environments can save months of trial and error.

Talk to a Cisco Duo identity security expert to map your current state and identify where to start.

Explore Duo's approach to identity

]]>
<![CDATA[Why your Active Directory needs a modern security strategy]]> duo@duo.com (Cisco Duo) https://duo.com/blog/active-directory-security-strategy https://duo.com/blog/active-directory-security-strategy Product & Engineering Wed, 15 Jul 2026 00:00:00 +0000

Microsoft’s Active Directory (AD) manages user identities for roughly 90% of Fortune 1000 companies. It controls who can log in, what they can access, and which security policies apply to every connected device. That reach is exactly why attackers treat it as a high-value target, and why security teams should develop strategies that adapt to emerging threats.

  • Active Directory is involved in 9 out of 10 cyberattacks, according to the Semperis 2024 Ransomware Risk Report. Its centrality to enterprise identity makes it the highest-value target in most organizations.

  • Traditional Active Directory hardening—static policies, periodic audits, perimeter firewalls—leaves gaps that attackers routinely exploit between review cycles.

  • A modern Active Directory security strategy layers adaptive authentication, single sign-on, device trust, and continuous verification on top of existing directory infrastructure.

  • Cloud directory services let organizations extend or replace on-premises directories without rebuilding their identity architecture from scratch.

New to directory services? Start with our guide to LDAP vs. Active Directory to understand the building blocks of your identity infrastructure.

Many Active Directory security solutions were designed for a world that no longer exists: one where every user, device, and application sits inside a corporate network. Hybrid work, cloud applications, and an expanding ecosystem of non-human identities challenge this security model and have forced teams to adapt.

Active Directory is the identity backbone of most enterprises. Compromising it can unlock access to everything the directory controls. The Semperis 2024 Ransomware Risk Report found that AD is the target in nine out of 10 cyberattacks, and that 83% of surveyed organizations were targeted by ransomware in the prior 12 months. IBM’s X-Force Threat Intelligence Index 2024 tells us why: 80% of enterprise cyberattacks use Active Directory to perform privilege escalation and lateral movement.

What do we mean by privilege escalation and lateral movement? These are pathways of attack that follow a familiar pattern.

  1. An attacker gains initial access—often through a phishing email or a stolen credential from a previous breach—and lands inside the network with an ordinary user account.

  2. From there, the goal is to move from that standard account to one with administrative rights. Attackers look for misconfigured permissions, unpatched domain controllers, or service accounts with excessive privileges that have not been rotated in months or years. This is privilege escalation.

  3. Once they reach an administrative account, they move laterally, which means using one compromised system to access others. They pivot from machine to machine using the credentials and access the directory grants. At that point, the attacker effectively controls the organization’s identity infrastructure.

The Verizon 2024 Data Breach Investigations Report found that stolen credentials appeared in 31% of all breaches over the past decade, and accounted for 38% of analyzed breaches in the most recent reporting period. Directory infrastructure is where those credentials live.

We established above that the workforce has moved beyond the corporate network. What does that shift mean for the security controls most organizations still rely on.

Most Active Directory security best practices center on three mechanisms:

  1. Perimeter firewalls between the internet and domain controllers

  2. Static group policies applied uniformly to domain-joined devices

  3. Periodic manual audits to catch misconfigurations

Each of these has a specific blind spot in today’s environment. Let’s break them down:

Perimeter firewalls protect domain controllers inside the network. They do not protect credentials traveling over a VPN, a cloud authentication service, or a remote desktop connection from an employee’s home network. When half the workforce authenticates from outside the perimeter, the perimeter is no longer the relevant security boundary.

Static group policies work well when every device is domain-joined and every user follows a predictable access pattern. In hybrid environments, employees use personal devices, contractors access internal applications through cloud portals, and service accounts authenticate around the clock. Here, a single set of static rules cannot account for the range of risk each session carries.

Periodic audits catch misconfigurations—eventually. A quarterly access review might surface an over-privileged service account, but an attacker who gains access between reviews has weeks or months to operate undetected.

Active Directory hardening protects the directory itself. But the users, devices, and applications it governs now operate in environments that hardening alone cannot reach.

Modern Active Directory security solutions start with the assumption that no user, device, or session should be automatically trusted, regardless of where the request originates. This is known as zero trust. For AD, zero trust means replacing the old model of trusting the network and verifying at the gate with continuous, context-aware evaluation.

To do so, security teams layer several capabilities on top of existing directory infrastructure:

Single sign-on (SSO)
SSO lets users authenticate once and access multiple applications without re-entering credentials for each one. Integrating Active Directory SSO with a cloud identity platform reduces the number of passwords users manage and gives security teams a single point to enforce authentication policies, monitor access, and revoke sessions.

Device trust
Instead of trusting every device on the network, a modern strategy evaluates device health before granting access. Is the operating system patched? Is disk encryption enabled? Is the device managed by the organization? These checks happen at authentication time, not once a quarter.

Adaptive authentication
Rather than applying the same login requirements to every session, adaptive authentication adjusts based on risk signals. A user logging in from a recognized device on a familiar network might authenticate with a single factor. The same user from a new device in an unfamiliar location faces additional verification.

Continuous verification
Authentication does not end at login. Continuous verification evaluates trust throughout the session, checking for changes in device posture, network context, or behavior patterns that might indicate a compromised account.

A cloud directory service takes on the infrastructure burden that on-premises Active Directory requires: hardware, patching, replication, disaster recovery. But the benefit extends beyond operations.

Cloud identity platforms centralize authentication, SSO, user provisioning, and policy enforcement into a managed service. Organizations can extend identity management to users and applications that on-premises Active Directory was never designed to reach, including remote contractors, SaaS applications, and non-human identities like service accounts and API keys.

The transition does not require replacing Active Directory overnight. Most cloud identity platforms support directory sync, which means organizations can run existing Active Directory alongside a cloud directory and migrate users and policies at their own pace.

Modernizing directory security is a phased effort. Identity leaders who approach it as a strategic initiative, rather than a one-time infrastructure upgrade, tend to make more durable progress.

Take these steps to start this process:

  1. Assess your current state. Map every system that authenticates against Active Directory. Include the ones easy to overlook: service accounts, legacy applications using LDAP, VPN appliances, and network devices. You cannot secure what you have not inventoried.

  2. Identify the gaps that matter most. Where are credentials exposed? Which accounts have excessive privileges? How many service accounts have not had their passwords rotated in the past year? Prioritize based on exploitability.

  3. Evaluate cloud identity options. Before choosing a modernization path, make sure your team understands the foundational differences between LDAP and Active Directory. Our guide to LDAP vs. Active Directory explains what each technology does, how they relate, and when to use each one. That foundation will help your team evaluate which cloud identity platform fits your environment.

  4. Plan a phased migration. Start with the use cases where cloud identity delivers the clearest value: SSO for cloud applications, multi-factor authentication for remote access, automated provisioning for contractors and third-party users. Each phase reduces the attack surface while the core Active Directory infrastructure remains in place.

Ready to see how cloud-based identity can strengthen your directory security? Start a free Duo trial and explore Duo Directory

]]>
<![CDATA[Duo + PlainID: dynamic authorization meets enterprise identity]]> cmedfisch@duo.com (Colin Medfisch) https://duo.com/blog/duo-plainid-dynamic-authorization-meets-enterprise-identity https://duo.com/blog/duo-plainid-dynamic-authorization-meets-enterprise-identity Partnership Mon, 06 Jul 2026 00:00:00 +0000

Duo is joining PlainID's IDP Authorizer program. Your tokens are about to get smarter.

When a user authenticates through an IdP, the resulting token carries claims that downstream applications use to make access decisions. In most enterprise environments today, those claims are static. They reflect what was mapped at configuration time, not what the user should actually be able to do right now.

A user whose role changed this morning still carries yesterday's entitlements in their token. An employee who moved from Engineering to Sales still has access to developer tools until someone manually updates the IdP mapping. The token does not know what changed, it only knows what was configured.

Organizations that have invested in dedicated authorization engines like PlainID have already solved the "what can this user do" problem. They have policies, context, and real-time evaluation. But that investment only pays off if the IdP can call out to the authorization engine at token issuance time and inject those decisions as claims.

Duo has not supported this pattern. Until now.

We are partnering with PlainID to bring deeper dynamic authorization to Duo's access flows. Duo is joining PlainID's IDP Authorizer program, which means PlainID customers can use Duo as their identity provider without giving up fine-grained, policy-driven token enrichment.

PlainID evaluates authorization policies at authentication time and returns claims that Duo injects into the token before it reaches the application. Applications get context-aware access decisions without needing their own integration to PlainID.

The integration is powered by a new capability in Duo: Inline Hooks. These are synchronous callout points in Duo's token issuance pipeline that let external services enrich tokens and assertions with dynamic claims.

  1. A user authenticates through Duo SSO

  2. Before token issuance, Duo calls PlainID with user and session context

  3. PlainID evaluates its authorization policies and responds with claims to include

The integration starts with token enrichment and assertion modification:

  • Token Inline Hooks: Enrich OIDC/OAuth tokens with dynamic claims from PlainID at issuance time

  • SAML Assertion Inline Hooks: Modify SAML assertions with dynamic attributes before signing

External Authorization Hooks, which route runtime permit/deny decisions to PlainID for use cases like MCP tool access, will follow as the platform matures.

The underlying hook platform is engine-agnostic by design. PlainID is our first partner and validates the pattern, but the contract works with any HTTP-based policy decision point.

For teams running PlainID today: You no longer need to choose between Duo and your authorization investment. Duo handles identity. PlainID handles what users can do. The hook connects them at the moment it matters most.

For teams migrating to Duo: Token extensibility has been a blocker for some organizations. With this integration, that blocker is going away.

For teams planning for AI agents: As agents interact with enterprise systems, authorization decisions get more complex, not less. Having PlainID's policy engine available during Duo authentication flows means those decisions can be made consistently whether a human or an agent is requesting access.

Token and SAML Assertion Inline Hooks are entering Alpha (limited availability with select design partners for validation and feedback) soon. We will be working with design partners to validate the integration before broader availability.

This is early, and we are sharing it now because the partnership is real, the architecture is taking shape, and we want to hear from teams who have been waiting for this.

This integration expands on Duo’s list of hundreds of technology partnerships. You can learn more about our complete ecosystem of integrations at ecosystem.duo.com.

If you are interested in participating as a design partner, or if PlainID integration has been a factor in your identity strategy, reach out to your Duo contact today and get connected with the Duo Product team.

]]>
<![CDATA[Continuous identity security: secure every account and session]]> ankaushi@cisco.com (Anshul Kaushik) https://duo.com/blog/continuous-identity-security https://duo.com/blog/continuous-identity-security Product & Engineering Sun, 05 Jul 2026 00:00:00 +0000

Enterprise identity has changed a lot over the last few years.

Users are no longer sitting behind a single network perimeter, accessing a small set of applications from managed devices. Today, they work from anywhere. Applications sit across SaaS, private data centers, cloud platforms, and partner environments. Devices can be managed, unmanaged, personal, mobile, or sometimes simply unknown.

And then there are the identities.

Human and non-human identities (NHIs), such as service accounts, SaaS accounts, cloud identities, legacy accounts, and now even AI-driven workflows are adding to the mix. Identity sprawl has become one of the biggest challenges security teams are trying to solve.

Attackers have noticed this shift too. They are not always trying to force their way in through exposed infrastructure. Increasingly, they are logging in with valid credentials, abusing excessive privileges, hijacking sessions, and blending into everyday user activity.

That means identity can no longer be treated as a one-time login check. We need to know which accounts exist, how they are being used, what sessions are active, and whether the level of trust should change as risk changes.

When we talk to customers about identity security, three (3) challenges usually come up.

Fragmented identity visibility: Most organizations have more than one identity source. There may be Microsoft Entra ID, Active Directory, SaaS directories, cloud accounts, privileged accounts, service accounts, and third-party identities. Each system has its own view of users, permissions, activity, and risk. The security team is often left trying to piece it all together manually and understand overall identity posture along with this.

Inconsistent access enforcement: Organizations usually have security controls in place, but they do not always work as one system. MFA may sit in one place. Device posture may be checked somewhere else. SaaS access, private app access, and network access may all follow separate policy models. That makes it hard to apply zero trust consistently across users, devices, applications, and environments.

Static decisions in a dynamic world: A user may pass MFA in the morning and get access. But what happens if the account starts behaving unusually later in the day? What if the device posture or device location changes? What if the session becomes risky? What if an account has more privileges than it should?

Identity risk is not static. So, security cannot afford to be static either.

This is where zero trust needs to evolve from a one-time authentication decision into a continuous, per-session context-aware model. Identity becomes the new control plane.

Cisco brings a platform approach to identity security by connecting identity visibility, access enforcement, network control, and threat response through Cisco Security Cloud.

At the center of this approach is Cisco Identity Intelligence, which helps organizations understand identity activity, discover risky accounts, identify excessive privileges, and close the gap between authentication and access.

But visibility on its own is only half the job. The real value comes when identity intelligence can drive action.

  • Cisco Duo helps verify trusted users and trusted devices with strong MFA, device trust, posture checks, and risk-based access.

  • Cisco Secure Access extends identity-aware enforcement across SaaS, internet, and private applications, helping users reach the applications they need without giving them broad access to everything behind the network.

  • Cisco ISE brings identity deeper into the network, supporting identity-based access for campus, branch, wireless, wired, VPN, and segmentation use cases.

  • Splunk helps bring identity signals together with broader security telemetry, giving teams better context to detect, investigate, and respond faster across the environment.

Together, these capabilities help organizations move away from static access decisions and toward continuous identity security.

Not just: did the user log in?

But: is this account trusted, is this device healthy, is this session behaving normally, and should this access continue?

Let’s make this real.

Imagine a finance user accessing a sensitive application. In a traditional model, the decision may be fairly simple. The user belongs to the Finance group. MFA is complete. Access is allowed.

That is useful, but it does not tell the whole story.

With Cisco, the decision can include much richer context.

  1. Duo verifies the user and checks whether the device is trusted and healthy.

  2. Cisco Identity Intelligence looks at the account itself. Is this identity behaving normally? Does it have excessive privileges? Has it shown unusual access patterns? Is there a signal that should change the access decision?

  3. Cisco Secure Access applies the right policy at the application level. If the user, device, and session look trusted, the experience stays simple. If something looks risky, access can be challenged, limited, or blocked.

  4. Splunk can correlate that identity activity with other security signals from across the environment. This helps the security team understand whether the event is isolated or part of a larger attack path.

That is the balance customers are looking for: tighter control when risk is high, and a smoother experience when trust is strong.

Cisco’s approach is different because identity is not treated as a standalone control.

Identity connects to access.
Identity connects to the network.
Identity connects to threat response.
And identity connects to the broader security operations workflow through Splunk.

Every account needs visibility. Every session needs context. Every access decision needs risk awareness. And every control point needs to work together.

This matters even more as organization adopt more SaaS, more cloud, more remote access, more third-party users, and more AI-driven workflows. The number of identities will keep growing. The number of sessions will keep increasing. And attackers will keep looking for the weakest identity path within the ever-growing attack surface.

The answer is not to add yet another disconnected identity tool and create more work for already stretched security teams. The answer is a connected security platform that can see identity risk early, enforce the right access policies, extend control into the network, and help teams respond to incidents faster.

Organizations should assess where identity visibility gaps, inconsistent access policies, and unmanaged risks exist across their environment, and explore how Cisco and its partners can help build a connected zero trust architecture that protects every account and every session. Learn more about our zero trust solution.

]]>
<![CDATA[Phishing-resistant MFA for Salesforce]]> leihung@cisco.com (Lei Hung) https://duo.com/blog/phishing-resistant-mfa-for-salesforce https://duo.com/blog/phishing-resistant-mfa-for-salesforce Industry News Thu, 02 Jul 2026 00:00:00 +0000

For years, multi-factor authentication has been the baseline for protecting accounts, but not all MFA is created equal. Attackers have grown adept at phishing their way past weaker methods like SMS, phone calls or one-time passcodes, tricking users into handing over the very factors meant to keep them safe. In response, Duo continues to invest in phishing resistant authentication like passkeys and Duo Mobile Proximity Verification to make sure our customers are able to widely adopt these methods and better protect your organizations.

Phishing-resistant authentication is moving from a best practice to a hard requirement for many, starting with the accounts that matter most: your administrators and privileged users.

Salesforce is now one of those platforms. Beginning July 20, 2026 Salesforce requires phishing-resistant MFA for all privileged users in production, including anyone with the System Administrator profile or permissions like Modify All Data, View All Data, Customize Application, or Author Apex. This applies whether those users log in directly to Salesforce or through a single sign-on (SSO) provider.

Note: Duo’s Microsoft integration using Azure Conditional Access Custom Control does not provide Authentication Method Reference (AMR) signals required during authentication by design. Please make sure to migrate your privileged users to the new Duo Entra ID External MFA integration or Duo SSO for Salesforce as soon as possible to avoid user lockout.

In practice, this means the methods many admins rely on may no longer get them in the door. Legacy factors like SMS passcodes, phone callbacks, and one-time passcodes don't meet the bar for phishing resistance, and users relying on them will be prompted to enroll a stronger method. For organizations logging in through an identity provider, Salesforce doesn't dictate the specific tool. Instead, it looks for a signal from the IdP confirming that a phishing-resistant authentication took place. The takeaway for admins is simple: the era of "any MFA will do" is over, and it's time to make sure your privileged users are authenticating with phishing-resistant methods.

The good news: meeting Salesforce's bar doesn't require ripping out everything. Duo offers two phishing-resistant options that you can roll out side by side, depending on what fits your users.

Passkeys (platform and roaming authenticator) are the industry standard for phishing-resistant authentication, built on the open FIDO2/WebAuthn specification. What makes them phishing-resistant is simple: a passkey registered for Salesforce only works for Salesforce. If a user lands on a malicious login page, the passkey just won’t work there.

Duo Mobile Proximity Verification is our proprietary solution on phishing-resistant authentication, designed for organizations that heavily depend on Duo Mobile, and love the user experience! With Duo Desktop doing origin binding and Bluetooth handshake between the Duo Desktop and Duo Mobile confirming the user has access to both devices, Duo Mobile Proximity Verification protects users from common phishing attacks such as social engineering and attacker-in-the-middle style attacks.

Both methods are governed through Duo's authentication methods policy, so enabling phishing-resistant auth for your Salesforce admins is a group policy change, not a project. Scope it to your privileged-access group, set the allowed factors, and the policy does the rest. Users keep the Duo experience they already trust; you get a clean signal back to Salesforce that a phishing-resistant authentication took place without disrupting your admins' workflow.

The July 20, 2026 deadline is a forcing function, but it doesn't have to be a fire drill. Salesforce is asking for a stronger signal at the front door for your most sensitive users, and Duo is built to deliver exactly that signal, without massive undertaking.

Whether your organization standardizes on passkeys, leans on Duo Mobile Proximity Verification, or deploys both across different user populations, Duo gives you the policy controls to roll out phishing-resistant MFA at the pace your business can absorb. Group-based policies mean you can start with your System Administrators and expand coverage to other privileged roles over time - all from the same Duo Admin Panel your team already operates in.

This is the partnership we want to be for our customers: helping you stay ahead of mandates like Salesforce's while protecting the user experience that keeps adoption high and helpdesk tickets low. Phishing resistance shouldn't come at the cost of usability, and with Duo, it doesn't have to.

Experience Duo's seamless authentication with a quick interactive Proximity Verification product tour, or get started adding phishing resistance with a 30-day free trial.

]]>
<![CDATA[Hanging Up on Telephony: How to move from SMS and phone to stronger MFA]]> bbacques@cisco.com (Brittany Bacques) https://duo.com/blog/from-sms-mfa-to-stronger-authentication https://duo.com/blog/from-sms-mfa-to-stronger-authentication Product & Engineering Wed, 24 Jun 2026 00:00:00 +0000

When it comes to multi-factor authentication (MFA), not all methods provide the same level of protection. Telephony-based MFA, including SMS passcodes and phone callback verification, was once considered a reliable and accessible option. Today, evolving security standards and an increase in sophisticated cyberattacks has rendered these methods increasingly vulnerable, and many organizations are replacing SMS MFA with stronger alternatives like Duo Push notifications, security keys, and biometric authentication.

This blog post explains why telephony-based MFA is no longer sufficient, what stronger MFA options are available, and how to migrate your organization away from telephony methods step by step. Whether you are just starting to evaluate the change or ready to execute, this guide gives you a clear path forward.

Explore the versatility of Duo’s authentication methods and how they support a modern security strategy.

Phone call and SMS-based MFA methods are vulnerable to several well-documented attack techniques. These include:

  • SIM swapping: Attackers convince a carrier to transfer a phone number to a new SIM card, intercepting all SMS codes sent to that number.

  • Phishing: Fake websites trick users into entering one-time passcodes, which attackers capture and use in real time.

  • Social engineering: Phone scams manipulate users or carrier support staff into revealing information or approving fraudulent requests.

  • Message interception: Attackers exploit weaknesses in telecommunications protocols to intercept SMS messages in transit.

These are not theoretical risks. While the National Institute of Standards and Technology (NIST) encourages organizations to adopt phishing-resistant authentication methods, Duo specifically recommends moving away from telephony-based MFA such as SMS and phone calls due to vulnerabilities like SIM swapping and message interception. Federal cybersecurity guidance and many cyber insurance policies increasingly require stronger, phishing-resistant MFA to protect critical systems and data.

Beyond security, telephony-based MFA carries ongoing costs. Every phone call and SMS message used for authentication incurs a per-transaction fee. For organizations with large user populations, these costs add up quickly compared to push-based or token-based methods that do not rely on telephony infrastructure.

User experience is another factor. Missed calls, delayed SMS codes, and poor cellular reception create friction that frustrates users and increases help desk ticket volume. Is two-factor authentication with SMS still safe enough for your organization? For most, the answer is no.

Cisco Duo offers several authentication methods that provide better security, lower cost, and a smoother user experience than phone call and SMS. Understanding the types of multi-factor authentication available helps you choose the right fit for your organization.

Duo Push and Verified Duo Push
Duo Push sends a login request directly to the Duo Mobile app on a user's smartphone, and the user taps to approve or deny. Verified Duo Push adds a verification step by requiring the user to enter a code displayed on the login screen, which helps prevent accidental approvals. Push-based authentication eliminates the SMS channel entirely, removing the risk of SIM swapping and message interception.

Security keys and FIDO2/WebAuthn
Hardware security keys use cryptographic authentication that is bound to the specific website requesting it. This makes them phishing-resistant by design because the key will not respond to a fraudulent site. FIDO2 and WebAuthn are the open standards behind this technology

Biometric authentication
Fingerprint and facial recognition verify identity using something the user is, rather than something they know or receive. Biometric methods are fast, convenient, and difficult to replicate remotely.

Hardware tokens
Hardware tokens generate one-time passcodes without relying on a phone or network connection. While they carry an upfront cost, they eliminate the ongoing per-transaction fees associated with telephony.

The benefits of MFA improve significantly when organizations move from telephony to these stronger methods. Push-based and phishing-resistant options reduce risk while also reducing friction for users and costs for the organization.

This section walks you through the process for retiring phone call and SMS authentication in your Cisco Duo environment. These six steps are based on real-world experiences supporting organizations navigate this transition successfully. Each step includes the rationale behind it and guidance for executing it in your Duo Admin Panel.

A note before you begin: Every organization is different. Use these steps as a framework and adapt the details to fit your user population, directory configuration, and support capacity.

Before making any policy changes, you need a clear picture of who is currently authenticating with telephony methods. This allows you to scope the migration accurately and avoid surprising users with unexpected changes.

Use the Authentication Log in your Duo Admin Panel to identify these users:

  • Navigate to Reports and open the Authentication Log.

  • Set filters for two-factor authentication (2FA) methods, selecting Phone Call and SMS Passcode.

  • Adjust the time range to capture as many unique users as possible. A 30 to 90 day window is a good starting point.

  • Export the filtered log to compile your list of unique telephony users.

Group your identified telephony users together so you can manage their transition incrementally. This exemption group allows these users to continue using phone call and SMS while you work through the migration, without affecting users who already use stronger methods.

  • If your users are managed directly in Duo, create a new user group in the Users section of the Duo Admin Panel.

  • If your organization syncs a directory to Duo, create the group in your directory.

  • Add all telephony users identified in Step 1 to this exemption group.

Before you disable telephony methods globally, you need to make sure users in the exemption group can still authenticate. Create a custom policy that allows phone call and SMS and apply it to the exemption group.

  • Create a new policy: Navigate to Policies, select Add Policy, and give it a clear name such as "Telephony Exemption Policy."

  • In the Authentication Methods section, enable Phone Callback and SMS Passcodes along with any other methods your organization allows.

  • Save the policy.

  • Apply the policy to the exemption group: Navigate to Policies, locate the new policy, select Actions, and then Apply. Choose the exemption group and reorder policies as needed for your configuration.

Now disable telephony methods in the Global Policy. This change will have minimal impact because the users affected are already authenticating with non-telephony methods. It also prevents anyone from migrating backward to telephony during the transition.

  • Navigate to Policies and open the Global Policy editor.

  • Under Authentication Methods, uncheck SMS Passcode and Phone Callback.

  • Save the policy.

Communicate before you save. Even though this change primarily affects users who do not rely on telephony, it removes the option from their login screens. Let affected users know in advance using Duo's prepared communication templates for policy enforcement changes.

This step is the most people-focused step. Map out how and when you will migrate the exemption group to stronger authentication methods.

Decide on your approach. You can migrate all remaining telephony users at once or in phases. Consider the following factors:

  • How many users are in the exemption group

  • What devices your users have access to (smartphones, security keys, hardware tokens)

  • How much help desk capacity you have during the transition period

  • Whether certain teams or departments should migrate before others

A phased approach gives you room to communicate effectively, help users adjust, and catch issues before they affect the entire group. A simultaneous cutoff can work for smaller groups but risks higher help desk volume and user frustration if problems arise.

Set clear deadlines. Define when phone call and SMS will be disabled for telephony users and communicate those dates early and often.

Draft your communications. Include the following in your messages to affected users:

  • What is changing and why

  • Instructions for switching to a stronger method like Duo Mobile

  • How to obtain a security key or hardware token if applicable

  • The transition timeline with specific dates

  • Where to get help

Duo provides a "Promoting Duo Push" knowledge base article with additional resources to support this campaign.

As users in the exemption group switch to stronger authentication methods, remove them from the group. When project deadlines arrive, remove any remaining users.

  • Monitor the exemption group and remove users as they confirm successful enrollment in a new method.

  • Once the group is empty and all users are authenticating with non-telephony methods, delete the custom exemption policy. The Global Policy now applies to everyone.

  • Review the Authentication Log after the final cutoff for any login issues related to the change.

The technical migration is only half the work. Clear, empathetic communication makes the difference between a smooth transition and a flood of help desk tickets.

Keep these MFA best practices in mind when communicating with end users:

  • Lead with the why. Help users understand that this change protects them and the organization, not just that IT decided to change something.

  • Use plain language. Not every user knows what SIM swapping or phishing-resistant MFA means. Explain the change in terms they relate to.

  • Give them time. Announce the change well before deadlines so users can transition at their own pace.

  • Make it easy. Provide step-by-step instructions for enrolling in Duo Push or setting up a security key. Link directly to the resources they need.

  • Offer support channels. Tell users exactly where to go if they need help, whether that is a help desk ticket, a Slack channel, or a dedicated FAQ page.

Duo provides communication templates you can customize for your organization.

Moving away from telephony-based MFA is a significant project, and you do not have to do it alone. Duo Care is Duo's dedicated support program designed to help your team through every stage of your security journey, including migrations like this one.

With Duo Care, your organization gets:

  • Personalized planning and guidance from a dedicated team that understands your environment and helps you build a migration plan tailored to your users, applications, and goals.

  • Access to experienced security professionals who provide best practices, answer technical questions, and help troubleshoot challenges throughout the project.

  • Proactive health checks that review your Duo account regularly, helping you identify potential issues before they affect users and keeping you informed about new features and recommendations.

  • Reduced disruption and faster adoption through expert-guided deployment, which minimizes help desk tickets and user frustration.

  • Training and enablement resources so everyone in your organization, from IT administrators to end users, feels confident and prepared.

Get started with Duo Care to plan your telephony migration.

]]>
<![CDATA[Cisco Duo Identity Summit: Making Sense of Identity in 2026 and Beyond]]> mcaulfie@cisco.com (Matt Caulfield) https://duo.com/blog/cisco-duo-identity-summit https://duo.com/blog/cisco-duo-identity-summit Industry Events Thu, 18 Jun 2026 00:00:00 +0000

Agentic AI is rapidly changing the world, creating opportunities for growth and innovation we couldn’t even have imagined just a few years ago. And threat actors are taking notice, using these same advanced AI models to penetrate an expanding threat surface, take over systems, steal sensitive information, and create chaos in their wake.

It’s clear we’re at a tipping point in the industry where fast-moving, AI-led innovation on both sides of the fence is putting immense pressure on people like us who are tasked with securing this brave new world. Trust in identity has never been more critical.

The Cisco Duo Identity Summit brings together industry experts to bring clarity and trust to identity into your organization in 2026 and beyond. We will unpack the exact trends shaping the current threat landscape, while learning how to secure the new agentic workforce, defeat advanced social engineering attacks, achieve true phishing resistance and how to, ultimately, create trust across your organization. If you are responsible for identity and access management at your organization, you’ll want to be there.

The event promises more than great speakers and content. The virtual experience will be filled with interactive features, peer-to-peer networking opportunities, and an extensive resource library to keep you engaged during and after the event. We’ll even be rolling out a new identity-focused, Space Invaders inspired 8-bit video game that attendees will be able to play between sessions. The person with the highest score at the end of the day will earn bragging rights and win one of our signature green Duo shirts.

  • Keynote: Identity Security for the Agentic Era I’ll be kicking it off in the keynote. The identity threat surface is outpacing traditional access controls as automation, identities, devices and applications continue to multiply. The rise of Agentic AI is changing how work gets done, and it is also changing how attackers operate. My keynote frames identity not as a checkpoint, but as a foundational and living trust layer across the enterprise. I’ll explore where identity is headed, why trust must be continuously earned and how to prepare for AI-driven risk.

  • Identity Security at Work: How Box Balances Security and Productivity including Akhila Nama, Global Head of Enterprise Security at Box.

  • Securing Identity at Scale: The School District of Philadelphia’s Path Forward with Andrew Speese, Deputy CISO at the School District of Philadelphia.

  • Outsmarting AI-Driven Social Engineering Tactics with Cisco Talos’s Joe Marshall, and experts from Persona. Learn about the current top social engineering tactics and how to stop them in their tracks.

  • Technical Masterclass: Deployable End-to-End Phishing Resistance with Danny Paul, Cisco – We all know we need end-to-end phishing resistance, but complexities and high costs prevent many organizations from doing everything they can to stop this common threat. Danny Paul walks us through the process of making enrollment easier and more seamless so we can improve adoption.

  • Is Active Directory still your Weak Link? With Joe Duggan. As agentic AI expands the identity threat surface, trust has to be continuously earned across every user, device, application, and agent, making Active Directory protection even more urgent.

  • A Zero Trust Playbook for the Agentic Workforce with Chris Anderson, Cisco – Agentic AI has moved artificial intelligence from the sandbox to the real world. But what does this mean for identity in this brave new world? Cisco’s Chris Anderson walks us through how identity is changing and why trust is becoming your greatest asset in the age of AI.

Duo is a mainstay in the identity world and we're happy that we can pull so many awesome speakers and attendees together for a day of honest and enlightening conversation and presentations. Genuinely looking forward to this event and kicking it off on Wednesday, June 24 with all of you. Please join us.

]]>
<![CDATA[Duo brings identity and authorization across AI agent gateways]]> cmedfisch@duo.com (Colin Medfisch) https://duo.com/blog/duo-brings-identity-and-authorization-across-ai-agent-gateways https://duo.com/blog/duo-brings-identity-and-authorization-across-ai-agent-gateways AI Security Wed, 17 Jun 2026 00:00:00 +0000

At RSAC 2026, we introduced Duo Agentic Identity—identity, authorization and audit purposed for AI agents operating at machine speed across enterprise environments. The launch laid out three capabilities that together close the agent governance gap:

  • Discovery, built on Cisco Identity Intelligence, to surface every agent in your environment, including the shadow ones you didn't know existed.

  • Identity lifecycle, built on Duo Directory, to make every agent a first-class non-human identity tied to an accountable human owner.

  • Least-privilege authorization, enforced at every tool call through a gateway that intercepts agent requests and evaluates them against Duo's fine-grained authorization policy engine.

The first two capabilities are infrastructure-agnostic by design. Today, we're closing the loop on the third: per-tool-call authorization now works with different AI gateways you run.

Since RSAC, the agent infrastructure landscape has only diversified. Enterprises aren't converging on a single gateway. Teams are choosing infrastructure based on their cloud provider, existing stack, and operational maturity. Some are deploying open-source gateways for new AI projects. Others are extending service mesh infrastructure they already run, or building on cloud-native platforms like AWS. And many are running Cisco Secure Access alongside the rest of their security fabric.

One question we kept hearing from customers: How do I get consistent identity and authorization controls when my agent infrastructure is diverse?

Without a consistent answer, organizations face a familiar set of risks amplified by machine speed: over-privileged agents accessing tools they shouldn't, no audit trail connecting agent actions to accountable humans, and inconsistent controls that vary gateway by gateway. The same compliance gap that plagued human access a decade ago is now emerging in the agent layer—except agents operate 24/7 and execute in milliseconds.

Gateways handle routing and enforcement well, but routing alone doesn't answer the critical question: who should be able to access which tools, and on whose behalf?

Duo Agentic Identity is expanding to serve as the authorization engine for any agent gateway. The architecture is simple: Duo decides; your gateway enforces. Regardless of which gateway sits between your agents and your tools, Duo provides the identity and authorization intelligence behind every decision. This means per-tool-call authorization; not just "can this agent connect to this server," but rather "can this user's agent invoke this specific tool on this specific server, right now." Authorization decisions are made in real time, based on Duo group membership and the fine-grained policies you define.

Further, every tool call produces an identity-correlated audit log: human → agent → tool → action. This complete chain of accountability maps every autonomous action back to a human identity. Built on OAuth 2.1 and OIDC, the integration is standards-based and works with the MCP clients your developers already use: VS Code, Cursor, Claude Code, and custom agents, alongside emerging protocols as the ecosystem evolves.

Duo is shipping an authorization connector that plugs directly into supported gateways. No proprietary lock-in required to get enterprise-grade authorization.

Not every organization is ready for a fully managed gateway, and they shouldn't have to be. Duo meets you where you are:

  • AgentGateway or Envoy: Deploying a new AI project from scratch? Install the Duo Authorization Connector and get per-tool-call access control in minutes.

  • AWS Bedrock AgentCore: Building on AWS? Duo integrates as the identity provider with gateway interceptors that enforce fine-grained policy on every tool call.

  • Arcade.dev: The actions runtime for enterprise AI agents, with 7,500+ pre-built integrations. Duo SSO serves as Arcade's OAuth 2.1 provider, so users authorize tools through Duo, and Arcade enforces which actions each user's agents can take based on user permissions and Duo-issued scopes. Every action is logged for full governance. No separate gateway required.

  • Cisco Secure Access: Best for enterprise-grade security. Full managed gateway with network-level enforcement, deep traffic inspection, and enterprise resilience. The tightest integration and most complete experience in the Cisco portfolio.

One Duo Admin Panel manages policies across all of them. Same authorization logic, same audit logs, same group-based policies, regardless of the enforcement point.

Your policies travel with you. Start with whichever gateway fits today; your agents, identity mappings, and policies carry forward if your enforcement point changes tomorrow. For customers who want identity and network controls converged in a single managed plane, Duo paired with Cisco Secure Access delivers that integrated experience. For customers running other gateways, Duo brings the same authorization logic and audit fidelity to whatever enforcement point you've chosen.

You can start configuring least-privileged access for agents today. The Duo Admin Panel now includes a Getting started with agentic AI experience, a guided checklist that walks administrators through securing their agent infrastructure:

  1. Get Duo Premier. Start a 30-day free trial of Duo to unlock full agentic security capabilities.

  2. Connect a gateway. Choose between Cisco Secure Access, AgentGateway, AWS AgentCore or Envoy.

  3. Protect with Duo authentication. Configure OAuth 2.1 / OIDC for agent workflows.

  4. Add authorization. Create fine-grained, tool-level access policies for groups.

  5. Register agents. Control which agents can access which MCP tools and resources.

  6. Monitor activity. View agent activity with full identity correlation.

The Duo Admin Panel shows connected gateways, discovered MCP servers and their tools, active policies, and enforcement status, all in one place. Duo works with Cisco Secure Access, open-source AI/MCP gateways, and AWS Bedrock AgentCore Gateway today, with Cisco AI Defense integration coming soon.

Agentic AI governance shouldn't require ripping out your infrastructure or committing to a single vendor's gateway. Duo Agentic Identity provides the authorization layer with per-tool-call access control, identity-correlated audit, and unified policy management—on top of whatever gateway you're already running, and at the pace your organization is ready for.

For early access to Duo's gateway integrations and to help shape what comes next, reach out to your Cisco contact and work directly with our product and engineering team.

Learn more about Cisco's zero trust for agentic AI workforce at cisco.com/go/securing-agentic-ai

]]>
<![CDATA[Passwordless for Microsoft 365 starts with federation]]> ahassevo@cisco.com (Andrew Hassevoort) https://duo.com/blog/passwordless-for-microsoft-365-starts-with-federation https://duo.com/blog/passwordless-for-microsoft-365-starts-with-federation Product & Engineering Wed, 03 Jun 2026 00:00:00 +0000

There’s a pattern I see regularly when talking with enterprise customers about Microsoft 365: they want to go passwordless, they’re already using Cisco Duo for multi-factor authentication (MFA) through a conditional access integration, but they assume the next step would require a massive identity migration project. It’s a reasonable assumption, but it’s wrong. Federation is simpler than its reputation suggests, and it doesn’t require moving your existing applications anywhere.

Many organizations come to me already using one of our conditional access integrations with Entra ID, either the custom control or the newer Microsoft Entra External MFA (formerly known as Microsoft External Authentication Methods, or EAM) integration. Both of these integrations are great at what they do: they let you enforce Duo MFA after users authenticate with their Microsoft password. The experience is familiar, the rollout is quick, and you can be up and running in minutes.

But here's the thing: these integrations kick in after the password. Microsoft handles the initial password validation, then hands off to Duo for the second factor. That architecture works well for MFA, but it means passwordless authentication isn't on the table. You can't eliminate the password when someone else is asking for it first.

With federation, the dynamic shifts. When you federate your domain to Duo SSO, Microsoft recognizes your users by their email domain and immediately redirects them to Duo before they ever see a password prompt. Duo owns the entire authentication process, which means we can offer passwordless options like passwordless Duo Push and passkeys right from the start. For your users, this means the login experience shifts slightly: instead of entering their password on a Microsoft page, they'll enter it on a Duo page—or skip the password entirely if you've enabled passwordless authentication.

Want to understand how federation compares to other single sign-on (SSO) approaches? Read our guide to federated identity management vs. SSO.

This is probably the most common concern I hear, and it's completely understandable. Organizations often have hundreds or even thousands of applications connected to Entra ID for SSO. The thought of migrating all of those to a new identity provider sounds like a massive undertaking.

Here's the key insight: you don't have to. When you federate your domain to Duo, your existing Entra ID-connected applications continue to work. The federated authentication flow just adds a step: users are redirected from Entra ID to Duo, authenticate with Duo (including passwordless if you've enabled it), and then get redirected back through Entra ID to their application. These redirects happen so quickly that users barely notice, especially if you're using features like Duo Passport to reduce friction across multiple apps.

I've worked with customers who had legitimate concerns about this: they imagined months of migration work, application-by-application. In practice, most of them had federation up and running in an afternoon (in their sandbox—can’t forget about change control), with all their existing apps working exactly as before. The difference is that now their users can go passwordless.

Another common misconception is that federating to Duo means abandoning your Entra ID conditional access policies. This isn't the case. Your conditional access policies continue to apply to federated logins, they just evaluate after the user has completed authentication with Duo and been redirected back to Entra ID.

This gives you flexibility. You can keep your existing conditional access policies in place, or you can consolidate enforcement to the Duo side using Duo's policy engine—or some combination of both. Many customers find that Duo's policy framework is easier to manage, especially for things like device trust checks, but the choice is yours.

If you're currently using our conditional access custom control integration, you may be aware that Microsoft is moving toward their Entra External MFA (formerly known as Microsoft External Authentication Methods, or EAM) framework as the replacement for custom controls. Many customers are evaluating the jump from custom controls to External MFA right now, and it's worth considering federation as part of that conversation.

Both External MFA and the custom control integration share the same fundamental limitation: they operate after the password. They're both excellent for enforcing MFA, but neither unlocks passwordless. If passwordless or features like Duo Passport for seamless cross-context authentication are on your roadmap, federation is the path that gets you there.

External MFA does have some advantages over the custom control integration, particularly around satisfying Microsoft’s built-in MFA requirements for admin portals and privileged identity management. But it also has limitations: For instance, Microsoft restricts you to a single External MFA integration per Entra ID tenant, whereas with custom controls you could create multiple integrations for granular visibility and control. Federation shares this one-integration-per-tenant limitation with External MFA, but it offers something neither conditional access integration can: a consistent, unified authentication experience across all your applications, and the ability to go passwordless.

One point worth clarifying: federation and External MFA aren’t mutually exclusive. In fact, most customers I work with end up using both. Federation handles authentication for your federated domain—the users with email addresses like jdoe@example.com who make up the bulk of your organization. But there are authentication scenarios that federation doesn’t cover.

For example, you may have accounts on your default “onmicrosoft.com” domain, such as service accounts, break-glass admin accounts, or guest accounts. These non-federated accounts still authenticate directly with Microsoft and can still be protected by Duo via EAM. Similarly, Entra ID Privileged Identity Management (PIM) verification prompts and other flows that aren’t traditional authentication flows can be protected using EAM.

The practical takeaway: think of federation as your primary integration for everyday user authentication, with External MFA providing coverage for the edge cases and administrative scenarios that fall outside the federated flow.

A common question I get: “Can we start with IT, then roll out to marketing, then sales?” The short answer is that federation is a hard cutover at the domain level—you can’t selectively federate some users in a domain while leaving others unfederated.

That said, if you have multiple domains in your Entra ID tenant, you can stage your rollout domain by domain. Each domain is a separate federation configuration, so you could start with a smaller domain to build confidence before federating your primary domain. And if you want hands-on experience before touching production at all, you can federate a test domain in your production tenant or use a sandbox Entra ID tenant. If you’ve been looking for an excuse to buy a fun domain name, here it is. Trying the federation process yourself is a great way to get familiar with the architecture and the PowerShell commands involved.

One important note about subdomains: once you verify a domain in Entra ID, any subdomains you verify afterward will inherit that domain’s federation configuration. So if you verify example.com and then test.example.com, you can’t independently federate the subdomain. If you’re setting up a greenfield environment and anticipate needing independent subdomain configurations, verify your subdomains first.

I want to address something I sense from customers sometimes: a hesitation around whether federation is a proven approach. Maybe it feels like a bigger architectural change than it really is, or maybe the word “federation” just sounds intimidating.

The reality is that federation is how enterprise identity has worked for decades. If your organization ever used Active Directory Federation Services (AD FS)—and many enterprises did—you were already federating. The difference is that Duo SSO is dramatically easier to set up and manage than AD FS ever was. The actual federation process typically takes just a few minutes: verify the prerequisites in Entra ID, create the application in the Duo Admin Panel, run the preconfigured PowerShell script we provide, and you're done.

I've walked through this process with healthcare systems managing thousands of clinicians, with law firms protecting sensitive client data, with financial institutions under strict regulatory requirements. The pattern is consistent: what seems like a big step turns out to be straightforward, and the capabilities it unlocks—passwordless authentication, simplified authentication flows, centralized policy management—make it well worth the investment.

If you're interested in exploring federation for your organization, here's what I'd recommend. First, take a look at our Duo Single Sign-On for Microsoft 365 documentation. It walks through the prerequisites and federation process in detail. The main requirements are straightforward: a verified domain in Entra ID, and users synced via Entra Connect Sync (though Duo's new directory capabilities are opening up even more options here).

If you're a current Duo Care customer working through this decision, reach out to your Duo Care team. We've had these conversations many times, and we're happy to help you think through the architecture that makes the most sense for your organization. The goal isn’t to push everyone toward federation regardless of their situation; it’s to make sure you’re aware of the full range of options and what each one unlocks. That said, if passwordless is on your roadmap, federation is likely the path you’re looking for.

Explore the Duo Single Sign-On for Microsoft 365 documentation to get started or contact your Duo Care team to talk through your options.

]]>
<![CDATA[Your admins have too much privilege]]> ayousufz@cisco.com (Aamir Yousufzai) https://duo.com/blog/custom-admin-roles-least-privilege https://duo.com/blog/custom-admin-roles-least-privilege Product & Engineering Fri, 29 May 2026 00:00:00 +0000

You apply least privilege to your end users. You verify their devices, scope their access, and monitor what they can reach. But what about the admins managing your security tools every day?

Admin accounts are some of the highest-value targets in any organization. A compromised admin with broad permissions can generate bypass codes, weaken MFA policies, or modify single sign-on (SSO) configurations—quietly undermining the security layer your business depends on. That is why we are bringing the same least privilege discipline to the people managing Duo.

Custom Admin Roles is now generally available for all Duo customers. You can create your own administrator roles with granular permission controls, so every admin on your team gets exactly the access they need and nothing more.

Ready to get started? Log in to the Duo Admin Panel to create your first custom admin role.

You already apply least privilege to your end users. Your admins deserve the same protection.

Depending on the privilege level, a compromised admin account can cause widespread damage across your identity security configuration. Role-based access control (RBAC) reduces that risk by ensuring each admin operates within a clearly defined scope—one that matches their actual job, not a generic role that happens to be close enough.

Duo has long offered eight built-in admin roles with a fixed set of permissions:

  • Owner

  • Administrator

  • Application Manager

  • User Manager

  • Help Desk

  • Billing

  • Read-only

  • Integration Manager

These built-in roles give you role-based access control with clear segregation of duties right out of the box. For many teams, they are a good fit. But they are not always a perfect match for how your organization actually operates.

Maybe you want an admin with all the permissions of both User Manager and Application Manager, but without the ability to manage policy that comes with the full Administrator role. Or maybe you have multiple levels of help desk—some who need to see sensitive user attributes, and others who should not.

Until now, you had two options: give admins more privilege than they need, or build manual processes that are hard to maintain and harder to audit. Neither approach supports a strong security posture.

Custom Admin Roles removes that tradeoff. You can now create administrator roles that reflect your organization's actual structure, not a predefined template.

Here is what's now available to any Duo admin with the Owner role:

  • Create unlimited custom roles tailored to your organization's operational structure

  • Set granular permissions across five categories: Users & Groups, Devices, Features, Applications, and Accounts

  • Start from templates by basing a new role on any existing built-in or custom role, then adjust individual permissions up or down

  • Assign custom roles anywhere you already use existing roles, including subaccount administration for Managed Service Providers (MSPs) and Administrator Sync

  • Edit roles on the fly – permission changes take effect immediately for every administrator assigned to that role

  • Assume roles without logging out to verify a role’s configuration before rolling it out to your administrators

  • Compare roles any time after creation to highlight the differences and get a full understanding of each role’s privileges

Permissions default to the most restrictive setting unless you apply a template, so you're always building up from least privilege by design.

While every organization structures its security team differently, a few patterns come up often:

  • Tiered help desk: Create a Tier 1 help desk role that can reset MFA devices but cannot view sensitive user attributes, and a Tier 2 role with broader visibility for escalations.

  • User Identity Manager: Grant full management of users but restrict security-sensitive actions, like putting users into bypass mode.

  • Subaccount Lifecycle Manager: Create, configure, and decommission child accounts but disallow any modification of users, policies, or security settings on the parent account.

These scenarios were not possible with built-in roles alone. Custom Admin Roles changes that.

Creating a custom role takes just a few steps right from the Duo Admin Panel:

  1. Navigate to Users > Administrators > Admin Roles

  2. Click Add custom admin role

  3. Name your role, optionally apply a template from an existing role, and expand each permission category to fine-tune access to match your security goals

  4. Click Add

That's it! Your new role is ready to use immediately. The role can be assigned anywhere standard roles can be assigned – when manually creating an admin, from an admin’s profile, from the role details page, via Admin API or through admin directory sync.

Before rolling a new role out to your team, we recommend using Assume Role to temporarily experience the Admin Panel exactly as that role will. This lets you verify the configuration matches your intent without affecting a real admin account.

Custom Admin Roles is available now for customers on Duo Essentials, Advantage, and Premier edition. Any admin with the Owner role can start creating custom roles immediately.

To see the feature in action, watch the video below or visit the Custom Admin Roles documentation for a complete walkthrough.

Already a Duo customer? Log in to the Duo Admin Panel to get started.

New to Cisco Duo? Start a free trial to see Custom Admin Roles and the full identity security platform in action.

]]>
<![CDATA[Identity-based attacks: How attackers bypassed MFA four times in one month]]> tmishoe@cisco.com (Tessa Collinge) https://duo.com/blog/identity-threat-brief-mfa-bypass https://duo.com/blog/identity-threat-brief-mfa-bypass Industry News Wed, 27 May 2026 00:00:00 +0000

This is the first edition of a new monthly identity threat brief for the Cisco Duo blog. Each month, I examine the identity-based attacks shaping the current threat environment, the structural weaknesses they exploit, and the defenses that hold up against them.

Identity-based attacks target authentication systems, credentials, and identity infrastructure rather than application code or encryption. In recent weeks, four incidents made the pattern clear: attackers stole authentication tokens from compromised routers, breached a national identity agency, abused a trusted vendor's notification system to deliver phishing, and compromised messaging-app accounts to read encrypted communications.

None of these attacks broke cryptography. None defeated multi-factor authentication (MFA) head-on. Each one went around the authentication layer instead of through it. These incidents are a clear opening case for this series: identity is now the primary attack surface, and the authentication layer is where attackers concentrate effort.

Across the four incidents, the pattern is consistent. Attackers did not try to defeat the strong cryptographic controls protecting modern systems. They targeted the trust relationships, session artifacts, and infrastructure that surround authentication.

Stolen tokens granted access without credentials. A breached government identity system exposed citizen data at scale. Legitimate vendor infrastructure delivered phishing that passed every standard email authentication check. Compromised endpoints gave attackers plaintext access to encrypted conversations.

The strategic implication for identity teams is direct: controls designed to verify credentials cannot stop attackers who already hold authenticated sessions or who never needed credentials in the first place. The identity attack surface now extends well beyond the login prompt.

Each incident exploits a different surface, but the underlying logic is the same.

APT28 did not phish credentials or defeat MFA. The group exploited known vulnerabilities in end-of-life Mikrotik and TP-Link SOHO routers, modified DNS settings to point to attacker-controlled servers, and intercepted OAuth tokens after users had already authenticated successfully.

Because OAuth tokens are issued after MFA verification, the stolen tokens granted fully authenticated sessions. No further credentials or one-time codes were required. Krebs on Security reported the campaign and noted the technique is highly effective at evading malware-focused detection.

This is an MFA bypass in the most practical sense: MFA worked exactly as designed, and the attacker waited for the token it produced.

The compromised ANTS data included login credentials and the personal information used to verify identity in administrative procedures. The Record reported the breach as the latest in a series targeting French government identity infrastructure, including a February 2026 breach of France's National Bank Accounts File that exposed information on roughly 1.2 million accounts.

Stolen identity data of this kind feeds downstream attacks: account takeover, fraudulent document applications, and credential reuse against unrelated services.

BleepingComputer reported that attackers embedded fraudulent transaction notices and callback phone numbers inside genuine Apple account-change emails. Because the messages originated from Apple's verified sending infrastructure, they passed every email authentication check designed to detect spoofing.

The attack does not exploit a technical vulnerability. It exploits the gap between sender verification and content trust.

The CISA and FBI joint advisory stated explicitly: attackers did not break the encryption of the messaging platforms. They compromised individual user accounts through credential phishing, session token theft, SIM swapping, and exploitation of weak authentication.

Once inside an account, attackers had plaintext access to historical messages, real-time conversations, and contact lists they could use to expand the attack.

MFA, SPF, DKIM, DMARC, and end-to-end encryption are strong controls. They are also narrow controls. Each verifies one specific thing: that a user holds a second factor, that an email originated from an authorized sender, or that a message was encrypted in transit.

None of them verify that the session in use is legitimate, or detect when a trusted platform delivers malicious content. None of them protect a credential database or a token store. The four recent incidents land at exactly these gaps.

The structural defense against this pattern is to make stolen credentials and stolen tokens harder to use, and to detect identity misuse when it occurs.

Phishing-resistant MFA uses cryptographic protocols such as FIDO2 (Fast Identity Online 2) and WebAuthn that bind authentication to the specific origin a user is signing into. Unlike one-time codes, push notifications, or SMS, phishing-resistant MFA cannot be replayed, intercepted on a fake site, or approved by a confused user.

It addresses the structural weakness behind credential phishing and many forms of session hijacking. For identity teams reviewing their authentication stack, phishing-resistant MFA is the highest-leverage control available today.

Token binding ties an authentication token to the device that obtained it. A stolen token cannot be replayed from an attacker's infrastructure. Conditional access policies add risk-based checks at session reuse, not just at sign-in. Together, they reduce the value of a stolen OAuth token of the kind APT28 harvested.

Detection of identity-based attacks depends on observing what authenticated identities do, not just whether they authenticated. Behavioral monitoring, anomalous-session detection, and analysis of token activity surface compromise even when credentials and MFA were not defeated.

Cisco Duo's identity threat detection and response capabilities operate at this layer. They pair with identity security posture management to surface the configuration weaknesses attackers target.

None of these controls work in isolation. They sit inside an identity security program that connects authentication, posture management, detection, and response.

For a Director of Identity reading this brief, the recent incidents translate into four practical actions.

  • Treat the authentication layer as an attack surface, not a control surface. Authentication is no longer just something the identity team configures. It is something attackers actively target. Inventory where authentication tokens live, how long they last, and who can use them.

  • Move toward phishing-resistant authentication. Deprecate SMS and push-only MFA on a defined timeline. Each of the recent incidents demonstrates the limits of authentication factors that can be intercepted, replayed, or socially engineered.

  • Invest in identity-specific detection. Endpoint detection and network detection do not see identity misuse. Detection of session anomalies, token replay, and unusual authentication patterns requires identity-layer telemetry.

  • Treat identity infrastructure breaches as catalysts for downstream attacks. A breach like the ANTS disclosure does not end with the disclosed agency. The exposed data feeds account takeover, credential stuffing, and impersonation across unrelated services.

This is the first in a series of recurring monthly briefs. Each edition examines the identity-based attacks shaping the threat environment that month, the structural weaknesses they exploit, and the defenses that hold up against them. Attackers are adapting quickly. I will track how that adaptation unfolds and what identity teams need to know.

Visit the Duo blog to follow the identity threat intelligence series and get each monthly edition as it publishes.

]]>
<![CDATA[How Duo Directory automates user lifecycle management]]> sgrebe@duo.com (Scott Grebe) https://duo.com/blog/user-lifecycle-management-duo-directory https://duo.com/blog/user-lifecycle-management-duo-directory Product & Engineering Fri, 15 May 2026 00:00:00 +0000

User lifecycle management is the process of creating, updating, and removing user access to applications and systems as employees, contractors, and partners join, change roles, or leave an organization. Done well, it protects the business without slowing people down. Done manually, it introduces errors, delays, and orphaned accounts that attackers can exploit.

Organizations no longer deal with a simple, centralized workforce logging in from a single corporate office. Today’s IT environments are hybrid, user populations are highly diverse, and the perimeter has dissolved into a network of cloud applications, remote endpoints, and third-party integrations.

To secure this dynamic environment, you need comprehensive identity lifecycle management.

In a recent episode of our Duo 3 in 30 webinar series, I sat down with Cisco Customer Solutions Engineer Reetam Mandal to explore three Duo features that automate identity lifecycle management from onboarding to departure: Duo Directory, Directory Sync, and Custom Attributes.

If you missed the live session, this post provides a deep dive into the three pillars covered in the webinar 3 in 30: Identity Lifecycle Management, Duo Directory, Directory Sync, and Custom Attributes.

Duo Directory is a cloud-based user directory that stores and manages user identities for authentication and policy enforcement.

Identity management can quickly become a tangled web, especially if your organization operates within a hybrid environment or relies on a mix of internal employees, contractors, and partners. Duo Directory cuts through this complexity by offering incredible flexibility, acting as the foundational component for managing your user identities.

It centralizes the user information relevant to Duo’s authentication and policy enforcement, giving IT and security teams a unified pane of glass to view and control exactly who accesses corporate resources. During the webinar, we covered three primary deployment scenarios:

Not every organization needs a massive Active Directory (AD) environment or a heavy-duty identity provider (IdP). For small-to-medium businesses, startups, or organizations adopting a strict cloud-first strategy, Duo Directory can serve as your primary, standalone identity store.

Administrators can create, manage, and configure users directly within the Duo Admin Panel. You can set required password options, manage credentials, and enforce enrollment policies without routing through an external ID source. When users enroll in Duo for the first time, they can be prompted to set a password, allowing Duo to handle the entire authentication lifecycle. This provides a simple, agile, and scalable option for securing access without the overhead of additional infrastructure.

For larger enterprises that have heavily invested in existing IdPs like Active Directory, Microsoft Entra ID, or Okta, Duo Directory doesn't force you to rip and replace. Instead, it acts as an intelligent identity broker.

In this setup, Duo Directory sits in front of your existing identity providers. It mediates authentication requests, applies Duo's phishing-resistant multi-factor authentication (MFA) and adaptive access policies, and then passes the authenticated user back to your primary IdP. This allows you to maximize existing infrastructure investments while layering on advanced security. Every login is protected by strong authentication and context-aware policies.

To manage multiple directories seamlessly, Duo utilizes routing rules. An admin can create custom rules dictating how different users are processed. For example, if a user attempts to log into Duo Central, Duo’s single sign-on portal, and their email originates from a subsidiary’s domain, their request is automatically routed to Active Directory. A default fallback rule ensures that anyone not matching custom criteria is still securely authenticated.

One of the most common headaches for IT administrators is managing access for external users—contractors, vendors, partners, or temporary interns. These individuals need access to specific corporate resources, but adding them to your primary corporate directory clutters your environment and introduces significant security risks.

Duo Directory offers a practical approach. You can run Duo Directory side-by-side with your existing IdP. This allows you to create and manage third-party users directly within Duo, keeping them completely segregated from your main identity store. You maintain strict, granular control over what these external users can access, apply specific security policies to them, and keep your core directory clean and secure.

Directory Sync is an automated process that synchronizes users and groups from external identity stores (Microsoft Entra ID, Active Directory, Google Workspace, OpenLDAP, Okta) into Duo Directory.

Having a robust directory is only the first step. The real challenge lies in keeping that directory accurate as your workforce constantly changes. Employees are hired, promoted, transferred, and eventually leave the organization. Managing these state changes manually is slow, error-prone, and creates security gaps.

This is where Directory Sync comes in. Working hand-in-hand with Duo Directory, Directory Sync automates user onboarding and offboarding by synchronizing users and groups from your existing external directories directly into Duo. Currently, Duo supports seamless synchronization with Microsoft Entra ID, Active Directory, Google Workspace, OpenLDAP, and Okta.

Let’s explore the three major operational and security benefits of implementing Directory Sync:

Manual user provisioning is tedious, time-consuming, and highly prone to human error. When a new batch of employees starts, IT teams often scramble to manually create accounts across dozens of applications.

Directory Sync eliminates this friction. Administrators can set synchronization schedules—for instance, automatically syncing with Active Directory every 12 hours. When a new employee is added to your primary directory, they are automatically provisioned in Duo. You can even automate the onboarding process by configuring Duo to automatically send enrollment emails to newly synced users. By removing these tedious administrative tasks, your IT team is freed up to focus on strategic, high-value security initiatives.

While onboarding is important for productivity, offboarding is critical for security. One of the most severe security vulnerabilities an organization can face is the "orphaned account"—an active account belonging to an employee who has already left the company. These dormant accounts are prime targets for threat actors.

Directory Sync drastically reduces this window of vulnerability. When a user is deactivated, terminated, or removed from your master directory, Directory Sync ensures their access to all Duo-protected applications is immediately revoked. In the Duo Admin Panel, administrators can clearly see a user's status change to "Pending Deletion" the moment they are deprovisioned. This automated, immediate revocation prevents potential data breaches and strengthens your overall security posture.

Effective security policies rely on accurate data. If your identity system thinks a user is in the marketing department, but they transferred to finance three months ago, your access policies are fundamentally broken.

Directory Sync ensures that the user and group information within Duo is always a true, accurate reflection of your primary authoritative identity source. During the setup process, administrators have granular control over exactly what gets imported. You can define specific groups (e.g., fetching only the "Interns" or "UX Team" groups) and map exact user attributes like usernames, email addresses, and display names.

By automating this synchronization, you eliminate data discrepancies. This is not only crucial for ensuring context-aware security policies function correctly; it is also a strict requirement for many regulatory compliance frameworks that demand up-to-date, auditable user records.

Custom Attributes are user-specific tags that extend the default user schema, enabling context-aware access policies based on role, clearance, department, or status.

With your directories established and your synchronization automated, you have a solid identity foundation. However, modern Zero Trust security requires more than just knowing who a user is; you need to understand their context.

Standard user data, such as basic group membership, is often insufficient for today’s complex access requirements. This brings us to the third feature highlighted in the webinar: Custom Attributes.

Custom Attributes allow administrators to go beyond the default schema and define unique, highly specific tags for users. This rich context empowers you to build intelligent, granular, context-aware access policies that drive smarter security decisions.

A user's role in an organization is rarely defined by a single group membership. With Custom Attributes, you can define highly specific tags that align with your unique business structure. You can tag users based on their specific department, their cost center, their employee number, their job title, or even their security clearance level.

Because managing dozens of attributes can become visually overwhelming, Duo allows administrators to group these attributes logically within the Admin Panel (e.g., grouping all project-related tags under a "Special Projects" category). By enabling these custom attributes, you can create highly precise policies that grant or deny access to applications based on exact roles and characteristics, ensuring users only have access to the resources necessary for their specific responsibilities.

Not all applications are created equal. An application housing the company's cafeteria menu requires vastly different security controls than a database containing sensitive customer financial records or protected health information.

Custom Attributes allow you to tag users who handle highly sensitive data. For example, you can create a custom attribute labeled "PCI Data Access" or "HIPAA Compliant." Once these users are tagged, you can build stringent, targeted policies around them. You might require that any user with the "PCI Data Access" attribute must authenticate using a phishing-resistant MFA factor (like a biometric or FIDO2 security key) and must be logging in from a corporate-managed, trusted device before they are granted access. This allows you to apply maximum friction and security exactly where it is needed, without disrupting the workflow of users accessing low-risk applications.

User status is rarely static. Employees go on sabbatical, contractors are hired for 30-day sprints, and staff members are temporarily assigned to cross-functional teams. When a user's state changes, your security policies must adapt instantly.

Custom Attributes enable this agility. You can define attributes that reflect dynamic, temporary states. For instance, Reetam demonstrated creating a "Temporary Access" attribute in the webinar. You can build a policy that triggers when this attribute is applied, automatically limiting the user's access to a specific subset of applications for exactly 30 days.

Alternatively, you could create an "On Leave" attribute. If an employee goes on extended medical or parental leave, applying this attribute could automatically block all access to corporate resources until they return, preventing their dormant account from being compromised while they are away. This dynamic adaptability ensures your security posture evolves in real-time alongside your workforce.

Identity lifecycle management is a continuous process, not a one-time project. Three Duo features work together to automate it:

  • Duo Directory centralizes and brokers user identities across standalone, hybrid, and third-party scenarios.

  • Directory Sync automates onboarding and offboarding across Microsoft Entra ID, Active Directory, Google Workspace, OpenLDAP, and Okta.

  • Custom attributes enforce granular, context-aware access policies based on role, clearance, or status.

Together, these three features deliver automated user lifecycle management: the right users get the right access to the right resources under the right conditions, from their first day to their last.

Watch the Duo 3 in 30 webinar on identity lifecycle management, available on-demand on the Duo website. We walk through the live Admin Panel configurations, and you’ll see how easy it is to implement these solutions in your own environment.

Watch the 3 in 30 webinar
Start a free trial

]]>
<![CDATA[Cisco Systems Named a Customers’ Choice in Gartner Peer Insights™ 2026 Voice of the Customer for Access Management]]> sgrebe@duo.com (Scott Grebe) https://duo.com/blog/gartner-customers-choice-access-management-2026 https://duo.com/blog/gartner-customers-choice-access-management-2026 Industry News Wed, 13 May 2026 00:00:00 +0000

Cisco stands alone in the Customers’ Choice Quadrant for 2026 based on reviews of its Duo offering in the Access Management VOC

Cisco Systems was named a Customers’ Choice in the 2026 Gartner Peer Insights™ Access Management Voice of the Customer. The recognition follows Cisco’s inclusion in the 2026 Gartner Peer Insights™ Voice of the Customer User Authentication category. Cisco is the only vendor to be mentioned as a Customers’ Choice in both the 2026 VOC for Access Management and User Authentication based on reviews of its Cisco Duo offering.

Among the companies evaluated by customers within the 2026 Gartner Peer Insights™ Access Management Voice of the Customer, Cisco was the only vendor to appear in the Customers’ Choice quadrant. Placement in the quadrant reflects ratings and reviews that met or exceeded the market average for User Interest and Adoption (x-axis) and Overall Experience (y-axis).

Cisco, based on reviews for Duo, received an overall rating of 4.8 out of 5, reflecting that 98% of customers are willing to recommend Cisco for access management, the highest percentage among vendors in the category.

Placement in the Gartner Peer Insights™ 2026 Customers’ Choice quadrant is based on ratings and reviews submitted by anonymous customers that met or exceeded the market average for Overall Experience and User Interest and Adoption. Cisco’s ratings are reflective of 62 reviews by verified customers during an 18-month period ending February 28, 2026.

According to Gartner Peer Insights™, Access Management’s purpose is to give people (employees, consumers, and other users) and machines access to protected applications in a streamlined and consistent way that enhances the user experience. Duo delivers comprehensive access management capabilities and broad Identity and Access Management (IAM) value including:

  • Identity lifecycle management

  • User authentication including phishing-resistant, multi-factor authentication (MFA) and end-to-end passwordless login

  • Single sign-on (SSO) and session management

  • Identity directory

  • Authorization policy definition and enforcement

  • Adaptive, risk-based access

  • Session protection and monitoring

  • Identity context sharing across security tools

  • Consolidated identity provider (IdP) and directory management capabilities

Direct quotes from the Gartner Peer Insights™ Access Management Reviews include:

Passwordless Remote Access and Simple Management Achieved with Seamless Setup Process

"Easy to get started and set up; we installed the Duo authentication proxy and it took no longer than a day to get it up and into the testing phase. The dashboard is excellent and simple. Active Directory Integration was seamless and allows us to manage users and groups from a single place and the changes are reflected in the Duo dashboard.”

"Duo Provides Granular Security Policies and Easy Implementation for Organizations"

“The security features are very comprehensive for identity security. The ability to use the onboard "directory" for creating user accounts in combination with integrated identity platforms gives additional flexibility for tracking identities for casual or non-traditional users.”

Multi-Factor Star

“DUO has been an outstanding solution for us. It has helped us implement two-factor authentication for more applications than we ever imagined, with enough two-factor options to accommodate every user.”

“Cisco is constantly adding functionality to DUO, allowing us to grow with the product and adapt to an ever-changing security landscape.”

"Push Notification Passcode Feature Enhances Security Without Disrupting Workflows"

“This product strikes a good balance between security and usability... It is a very simple and quick authentication process. Push notification with verified passcode feature is very simple and provides strong security without interrupting everyday work.”

"Duo Delivers Reliable Performance with Strong Security and Seamless Integration Features"

"What I like most is the wide range of features Duo offers. It provides comprehensive security capabilities while remaining easy to manage and integrate with our systems.”

Explore related resources to learn more about the capabilities highlighted in this recognition:

Gartner and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

Gartner, Gartner Peer Insights Voice of the Customer for Access Management, Peer Contributors, April 24th, 2026.

Gartner, Gartner Peer Insights Voice of the Customer for User Authentication, Peer Contributors, January 22nd, 2026.

]]>
<![CDATA[How to build IdP failover with backup and split strategies]]> sandeag2@cisco.com (Sandeep Agarwal) https://duo.com/blog/idp-failover-backup https://duo.com/blog/idp-failover-backup Product & Engineering Mon, 27 Apr 2026 00:00:00 +0000

In a previous post, we explored why depending on a single Identity Provider (IdP) creates concentration risk that can affect availability, security, vendor leverage, and business continuity. Now we want to walk through the practical strategies for addressing that risk.

If your organization has assessed its IdP concentration risk and determined that a mitigation strategy is necessary, this post provides two proven approaches you can implement. For a comprehensive framework to evaluate identity providers and directory strategies, download the IAM Buyers Evaluation Guide.

We believe organizations operating critical infrastructure must implement a practical mitigation strategy for identity concentration risk. Two approaches have proven effective:

  • Backup IdP: Maintain a secondary IdP that you fail over to during disruptions to your primary provider.

  • Split IdP: Run two IdPs concurrently with your user base distributed across both providers.

Each approach has distinct advantages depending on your organization's size, complexity, and operational maturity. The following sections walk through both in detail.

This strategy involves failing over to a backup IdP to reduce the potential impact of an outage at your primary provider. The operating model works as follows:

  • During normal operations, users authenticate through Single Sign-On (SSO) with your primary IdP.

  • During an IdP outage, you change the SSO configuration of your applications to switch authentication to the backup IdP.

To execute this strategy successfully, follow these five principles.

Choose your backup IdP from a different vendor. Operational diversity is the foundation of this approach. If your backup IdP runs on the same vendor infrastructure as your primary IdP, a single vendor-level disruption can take down both providers simultaneously. Select a backup provider that operates on independent infrastructure.

Match the configuration of your primary IdP. When you create a backup IdP, replicate the configuration of your primary IdP as closely as possible. This includes Multi-Factor Authentication (MFA) policies, conditional access rules, group memberships, and attribute mappings. Configuration parity ensures that users experience consistent security enforcement regardless of which IdP handles authentication.

Hydrate the backup IdP with your current user base. Your backup IdP must contain an up-to-date copy of your primary IdP's user directory. This ensures that every user can authenticate and access the required applications and services when you activate the backup. Most organizations have moved from manual provisioning to automation that integrates Human Resources Management Systems (HRMS) with the IdP. Establishing this synchronization with a second IdP is usually a one-time setup using connectors provided by the new provider.

Prepare Security Assertion Markup Language (SAML) and OpenID Connect (OIDC) profiles in advance. Most systems and applications allow you to create multiple SAML and OIDC profiles, with each profile referring to a different IdP. To minimize the work required during a failover event, prepare these profiles before you need them:

  1. Create separate SAML and OIDC profiles for your primary IdP and your backup IdP

  2. Configure SSO to use only the primary IdP profile during normal operations

  3. When an outage occurs, modify the SSO configuration to use the backup IdP profile

This preparation reduces your failover from a complex reconfiguration exercise to a profile switch.

Prepare the backup IdP to handle production load. When you activate the backup IdP, it must handle all of the authentication requests that your primary IdP normally processes. When you size your backup deployment, account for two key factors:

  • The number of users in your organization who authenticate through SSO

  • The configured session length in your applications, which determines how frequently users are redirected to the IdP for reauthentication

For example, if your session length is between eight and 24 hours, authentication requests typically spike during morning hours when employees begin their workday. Size your backup IdP to handle these peak loads, not just average traffic.

You may not need to provision an entirely new IdP to serve as your backup. Many organizations still operate an on-premises IdP that could fill this role. For example, your organization might use Active Directory as its authoritative source for identities and Active Directory Federation Services (AD FS) for SSO. In this scenario, AD FS could serve as the backup IdP.

This reuse approach helps you limit both cost and maintenance overhead. Before committing to a new provider, audit your existing infrastructure for an IdP that already has access to your user directory and supports SAML or OIDC federation.

A backup IdP that has never been tested is not a reliable backup. To ensure your SSO failover process works when you need it, verify the process on a regular schedule:

  1. Select one or more applications and manually switch their SSO profile assignment to the backup IdP

  2. Verify that SSO with the backup IdP authenticates users as expected

  3. Confirm that signing certificates are current and valid

  4. Document the time required to complete the switchover

  5. Identify any steps that caused delays or confusion and refine the process

Treat failover testing the same way you treat disaster recovery testing for other critical systems. A documented, rehearsed process executes faster under pressure than one your team performs for the first time during an actual outage.

This strategy involves running two IdPs concurrently and distributing your user base across both providers. Unlike the backup approach, both IdPs are active during normal operations. The operating model works as follows:

  • One segment of your users authenticates through SSO with IdP 1

  • Another segment authenticates through a second SSO configuration with IdP 2

Choosing how to split your user base. Organizations can segment users across IdPs in several ways:

  • By user type: First-party users such as employees and interns authenticate through one IdP, while third-party users such as vendors and contractors authenticate through the other (as shown in the image above)

  • By business function: Critical business units use one IdP, and non-critical units use the other

  • By geographic location: Primary office locations use one IdP, and secondary locations use the other (this is our recommended approach as it provides the cleanest operational separation)

The split approach provides several operational benefits compared to maintaining a standby backup:

Avoids complete identity failure. Because both IdPs are always active, an outage at one provider only affects the user segment assigned to that provider. The other segment continues to authenticate normally. Your organization never experiences a total identity blackout.

Eliminates switchover complexity during outages. With a backup IdP strategy, your team must execute a failover procedure under pressure during an outage. With split IdPs, the SSO configurations for both providers are already active. The incremental effort during a disruption is limited to reassigning the SSO profile for the affected user segment to the functioning IdP.

To implement the split approach effectively:

  • Choose IdPs from different vendors to maintain operational diversity, just as with the backup approach

  • Hydrate all users to both IdPs so that either provider can authenticate any user when needed, not just the segment currently assigned to it

  • Assign the correct users and groups to the correct IdP in each of your applications

  • Have users set up their authentication credentials across both IdPs so they can authenticate through either provider without delays during a reassignment

Whether you choose the backup approach or the split approach, start with these three steps:

Audit your blast radius. If your primary IdP went offline for four hours, which mission-critical systems would remain accessible? Map every federated application to understand your full exposure.

Evaluate your N+1 options. Do you have an existing on-premises IdP or a secondary cloud provider that could serve as a failover? Assess what you already have before investing in new infrastructure.

Practice the switch. Ensure your team knows exactly how to execute a SAML profile switchover before a crisis forces them to learn on the fly. Document the procedure, assign roles, and rehearse it.

For a step-by-step framework to evaluate IdP providers and directory strategies as part of your resilience plan, download the IAM Buyers Evaluation Guide.

Identity controls access to every application, every dataset, and every workflow your organization depends on. We do not accept single points of failure in our power grids, our databases, or our networks. It is time we apply the same standard to our identity systems.

Ready to explore how Cisco Duo can strengthen your identity resilience strategy? Talk to a security expert.

]]>
<![CDATA[Agentic AI security: Three threats your team should know]]> sleung2@cisco.com (Steve Leung) https://duo.com/blog/agentic-ai-security-threats https://duo.com/blog/agentic-ai-security-threats AI Security Thu, 23 Apr 2026 00:00:00 +0000

AI agents are in your environment right now. They’re reading databases, sending messages on behalf of employees, and executing multi-step workflows across production systems. If you’re a security leader, you already know this introduces risk.

The hard part isn’t awareness. It’s the pressure to keep pace. Every week brings new agentic capabilities, new integrations, new competitive advantages your organization can’t afford to sit out. So you let adoption move forward and accept a certain level of risk, because falling behind feels worse.

That’s a reasonable trade-off. But most organizations are accepting risk they haven’t actually scoped. The agentic AI security challenge covers more ground than traditional security models account for, and without a way to think about it, it’s hard to know which exposures matter, which ones are already present, and where your existing controls fall short.

In our research at Cisco Duo into how AI agents interact with enterprise systems through protocols like MCP (Model Context Protocol), we keep seeing threats cluster into three categories. The point here isn’t to slow down adoption. It’s to give security teams a framework for reasoning about where the real exposure is, so you can keep moving forward with your eyes open.

The most common agentic threats aren’t attacks. They’re configuration mistakes and tooling limitations.

When organizations deploy agents, they connect them to enterprise tools and grant permissions. The urgency is part of it, but the bigger issue is tooling. The policy and configuration systems most organizations rely on were designed for human users. They don’t map cleanly to agents, which are non-human identities that need per-action scoping, tighter delegation boundaries, and identity models that most traditional tools simply don’t support. So teams do the best they can with what they have, and the result is permissions that are too broad, too persistent, and too loosely scoped. You don’t need an attacker to exploit these conditions. They’re exploitable by design.

Over-privileged agents are the simplest example. A developer wants a coding assistant to review pull requests and leave comments. They hand it their personal GitHub access token, the same one they use for CLI work. That token carries every permission the developer has: push code, merge branches, delete repositories, access private repos across the org. The agent was meant to read and comment. Now it can do everything the developer can, with no guardrails and no one in the loop.

Delegation scope drift is harder to spot. An agent starts with read-only Salesforce access. Over eight months, support tickets lead to adding write access, then export, then full API access. Each change makes sense at the time. Nobody reviews the cumulative result, which now far exceeds the original intent.

Cross-user boundary violations show up when agents can reach data belonging to someone other than the user who authorized them. An enterprise Slack integration grants agents access to “all channels the app is installed in” rather than “channels the delegating user belongs to.” One user’s agent can now read another user’s private channels and DMs.

Shared agent identities are an attribution problem. A platform team creates a single “team-devops-bot” identity shared by 20 engineers, connected to AWS, Kubernetes, and Terraform. When the agent runs a destructive terraform destroy, logs show “team-devops-bot.” Good luck figuring out which engineer triggered it.

None of these are edge cases. They’re the default outcome when you apply existing identity and access patterns to agents without rethinking the model. The fixes aren’t exotic: least-privilege scoping per agent, user-level isolation, individual identities with clear ownership, periodic review of accumulated permissions. Most teams just haven’t had the bandwidth to get there yet.

Perfect permissions don’t prevent all damage. Agents interpret instructions, make judgment calls, and sometimes get it wrong. No attacker required.

Dangerous tool sequences are where traditional access controls break down. An automation agent (1) reads database credentials from a secrets vault, (2) queries customer PII from a database, and (3) uploads a “backup” to an S3 bucket. Every individual action is allowed. Strung together, it’s data exfiltration. If your policy only evaluates actions one at a time, you’ll never catch this.

Runaway execution is the least sophisticated failure mode and potentially the most disruptive. In March 2026, a multi-agent research system’s Analysis and Verification agents entered an undetected recursive feedback loop. The Analysis Agent expanded content based on Verification feedback, which triggered new verification questions, which triggered more analysis. Every API call succeeded. Every response was well-formed. The loop ran for eleven days before anyone noticed. Cost: $47,000 (Dev|Journal, 2026). This pattern is endemic across AI coding tools: Cursor, Copilot, and Claude Code have all had documented infinite loop incidents, with individual cases racking up hundreds to thousands of dollars in minutes.

The thread connecting these is that access control alone won’t save you. You need behavioral monitoring: what does normal agent activity actually look like, and what deviates from that? You need to evaluate tool interactions as sequences, not individual calls in isolation.

The first two categories are self-inflicted. This one involves an adversary on the other end.

As agents become standard enterprise infrastructure, attackers are adapting. The attack surface is there, and they’ve already started working it.

The confused deputy is a classic attack pattern that gets significantly more dangerous with agents. In 2025, four critical-severity vulnerabilities (CVSS 9.3-9.4) hit Anthropic, Microsoft, ServiceNow, and Salesforce, all following the same pattern: an attacker injects hidden instructions into content the agent processes (an email, a web form, a Slack message), and the agent uses its legitimate permissions to exfiltrate data to the attacker. Microsoft’s EchoLeak vulnerability (CVE-2025-32711) was a zero-click attack: the victim never even opened the malicious email. Copilot’s retrieval engine ingested the payload alongside trusted SharePoint files and encoded sensitive data into an outbound URL. The agent isn’t over-privileged in any of these cases. These are identity-based attacks where the agent’s own credentials become the weapon, manipulated into misusing its legitimate access on behalf of someone who doesn’t have it.

Agent credential theft is scaling fast, and it’s a different problem than stolen passwords. When a human credential leaks, the attacker gets one person’s access, usually gated by multi-factor authentication (MFA), to a limited set of systems. Agent credentials are bearer tokens. There’s no second factor. Whoever has the key IS the agent. And because agents tend to accumulate access across multiple services (AWS, GitHub, Slack, databases), a single compromised credential can grant broad cross-system access at machine speed. Making it worse: research has found that 53% of MCP servers rely on long-lived static secrets, and only 8.5% use OAuth (ReversingLabs, 2025). These aren’t short-lived tokens that expire in an hour. They’re keys that sit valid for months. In February 2026, researchers discovered a misconfigured database on the AI agent platform Moltbook that exposed 1.5 million of these keys in plaintext (prplbx, 2026) (OpenAI, Anthropic, AWS, GitHub, Google Cloud). Any attacker with those keys could fully impersonate any agent on the platform. The broader trend is accelerating: 67% of compromised organizations experienced credential theft against cloud management consoles in 2025, and 61% of organizations now cite AI as their top data security concern (AICerts, 2026).

MCP server security is a genuinely new concern, and the numbers are sobering. The MCPTox benchmark found that 5.5% of MCP servers exhibit tool poisoning attacks, 43% are vulnerable to command injection, and a third allow unrestricted network access (MCPTox, 2026). In the first two months of 2026 alone, over 30 CVEs were filed against MCP servers, clients, and infrastructure (heyuan110, 2026). One of the most notable, CVE-2025-6514, was a CVSS 9.6 remote code execution flaw in mcp-remote (Amla Labs, 2025), an npm OAuth proxy package with over 437,000 downloads. On the supply chain side, open source MCP servers have been found with hidden reverse shells and single-line code updates that silently forward data to third-party servers (Docker, 2026).

Each category demands something different. Misconfigurations are a governance problem: better defaults, tighter guardrails, regular review. Non-deterministic execution and malicious attacks are both observability and detection problems, but different kinds: the first requires behavioral monitoring across sequences of actions, not just individual calls; the second layers on threat intelligence, credential hygiene, and infrastructure validation.

No single control covers all three. But AI agent security starts with a few things that help everywhere:

  • Least-privilege authorization at the tool-call level. Agents should get exactly the permissions they need for their specific task, evaluated per action, not granted in bulk.

  • User isolation by design. An agent acting on behalf of one user should never be able to touch another user’s data or sessions.

  • Infrastructure validation. The tools and servers agents connect to need verification. Governing the agents themselves isn’t enough if the infrastructure underneath them is compromised.

  • AI agent monitoring across sequences. A single tool call might look fine. The pattern across a session is where risk shows up.

The agentic threat landscape is growing fast, and it’s more specific than “agents might go rogue.” Keeping up with AI capability in your organization matters. So does keeping up with security practices in this space, and the two should move in lockstep, not six months apart.

At Duo, we’re actively researching these threat categories as part of our work on agentic identity and MCP security. To see how we’re applying least-privilege authorization, user isolation, and infrastructure validation to the agent ecosystem, visit our Agentic AI Security page or start a free trial.

]]>
<![CDATA[How MSPs secure client access with Duo and Meraki]]> jaho2@cisco.com (Janet Ho) https://duo.com/blog/msp-client-access-security https://duo.com/blog/msp-client-access-security Industry News Tue, 21 Apr 2026 00:00:00 +0000

Many MSPs are helping clients build a stronger security foundation. But getting there isn't always straightforward. It takes time, resources, and alignment across teams. Yours and theirs.

Meanwhile, threats aren't waiting.

Many of your clients still rely on passwords and legacy access controls that weren't designed for today's attacks that target logins, not systems. Some have MFA in place, but the challenge is coverage and effectiveness. Ensuring it's enforced at the right access points and resistant to modern phishing attacks.

According to Cisco Talos' 2025 Year in Review, VPNs are one of the top identity control points attackers target because VPNs authenticate users with credentials, and credentials get stolen. Without phishing-resistant MFA on the VPN, a stolen password is all an attacker needs to create a fully trusted session and move freely as a valid user. No forced entry. No alerts.

And they're not stopping at the VPN. Talos found that MFA itself is under direct attack: device compromise attacks where attackers fraudulently register their own device as a trusted MFA factor surged 178% in 2025.

That's not a technology failure. That's your clients' exposure.

According to Microsoft's 2025 Digital Defense Report, phishing-resistant MFA blocks over 99% of identity-based attacks, making it one of the most effective controls you can deploy across your client base.

At the same time, expectations are rising.

Your clients are being pushed to adopt stronger access controls as users, devices, and applications connect from everywhere. But in practice, rolling out these frameworks introduces friction. New policies to configure, identity and device signals to align, and controls to integrate across existing systems.

Managing multiple tenants, stitching together tools from different vendors, and maintaining consistent security policies across client environments increases operational overhead, drives up costs, and pulls focus away from what actually matters: reducing client risk.

This is the gap most MSPs are feeling: high client expectations. Limited capacity.

Ready to take the first step? The Service Creation Guide walks through how to package identity-led access security into a scalable, revenue-generating managed service. If you have clients to bring along, the at-a-glance gives them a quick summary they can act on today.

Cyber insurers are also raising the bar. They're no longer satisfied with checkbox compliance. They expect continuous validation that controls like MFA are actively enforced. Your clients need to demonstrate measurable identity security to maintain coverage and manage premiums. As their trusted security partner, MSPs are on the hook to help them prove it.

You don't need to overhaul everything. You need to focus on where attackers actually get in. Small steps starting with securing access can reduce client risk today while moving them toward a security model where only the right people get in, without introducing extra work for your team.

If you're looking for immediate traction across your client base, start with the access points attackers rely on most—VPN, Wi-Fi, and administrative systems. Critical access points like Remote Desktop Protocol (RDP) and server logins are often overlooked or inconsistently protected across client environments, especially in hybrid setups. Extending phishing-resistant MFA to these remote desktop and server logins closes another common gap and gives you another high-value control point to offer clients.

Cisco Duo verifies identity using phishing-resistant MFA and adaptive access policies. Meraki enforces access at the network layer.

Together, they secure VPN, Wi-Fi, and administrative access across your clients without adding complexity or slowing your team down.

Here’s what Cisco Duo and Meraki deliver:

Without Duo + Meraki

With Duo + Meraki

Shared credentials across client sites

Duo verifies identity and device trust before granting access

Siloed identity and network data

Correlated audit trails in one place

Complex multi-vendor rollouts

Fast deployment, up and running quickly

Reactive compliance evidence gathering

Exportable logs ready at renewal time

Duo and Meraki give your team clear audit trails, exportable compliance logs, and fast deployment across every client. And with Duo Essentials, you also get passwordless authentication and single sign-on (SSO) — so users get a smoother login experience while your team avoids managing multiple credentials across every client.

This doesn't have to be an all-or-nothing transformation. For your clients, meaningful progress starts with securing how they get in. Lock down access first. Everything else follows.

]]>