Duo Security
By Cisco
Duo Security is a cloud-based access security platform, owned by Cisco, best known for its multi-factor authentication (MFA) product that verifies user identity before granting access to applications and networks.
Definition
Duo Security is a cloud-based access security platform, owned by Cisco, best known for its multi-factor authentication (MFA) product that verifies user identity before granting access to applications and networks.
Overview
Duo Security started as a standalone two-factor authentication vendor and was acquired by Cisco in 2018, after which it became a core part of Cisco's zero-trust security portfolio. Its flagship product adds a second verification step — typically a push notification to a mobile app, a one-time passcode, or a hardware token like a Yubikey — on top of a username and password. Beyond basic Multi-Factor Authentication (MFA), Duo evaluates the trustworthiness of the device requesting access, checking factors such as operating system patch level, disk encryption status, and whether the device is managed by the organization. This device-trust layer lets administrators block logins from out-of-date or unmanaged devices even if the correct password and MFA code are supplied, which is a foundational building block of a Zero Trust access model. Duo integrates with a broad range of systems — VPNs, cloud applications, on-premises servers, and custom applications via APIs and SDKs — so organizations can apply consistent authentication policies everywhere rather than only at a single entry point. It is frequently deployed alongside Single Sign-On (SSO) providers, acting as the step-up verification layer at login. Because it is easy to deploy and has a strong reputation for reliability and low user friction, Duo remains one of the most widely used MFA products in both small businesses and large enterprises, and is often one of the first security controls organizations adopt when hardening their identity posture.
Key Features
- Push-notification, SMS, phone-call, and hardware-token based multi-factor authentication
- Device trust checks including OS version, patch status, and encryption state
- Adaptive access policies based on user, device, location, and risk signals
- Broad integration ecosystem covering VPNs, SSO providers, and custom applications
- Self-service enrollment portal that reduces IT helpdesk burden
- Detailed authentication logs for auditing and compliance
- Part of Cisco's broader zero-trust and secure access portfolio
Use Cases
Frequently Asked Questions
From the Blog
Zero Trust Security Explained
Zero Trust means never trust, always verify. Learn how this model replaces the old network perimeter and secures modern cloud and remote work setups.
Read More Cloud & CybersecurityDevSecOps: Building Security Into Your Pipeline
DevSecOps builds security into every stage of software delivery instead of bolting it on at the end. Learn the practices, tools, and culture that make it work.
Read More Cloud & CybersecurityCommon Web Security Vulnerabilities (OWASP Top 10)
The OWASP Top 10 ranks the most critical web application security risks. Learn what each one is, how attackers exploit it, and how to defend against it.
Read More Cloud & CybersecurityWhat Is Zero Trust Security?
Zero Trust security assumes no user or device is trusted by default. Learn its core principles, how it replaces the old perimeter model, and how to adopt it.
Read More