Skip to content

The 23 Cisco Duo security checks Black Cat runs

Black Cat SSPM evaluates 23 security policies against your Cisco Duo configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.

configuration

highAdmin API Integration Without IP Restriction

Restrict Admin API integrations to known networks/IPs

mediumIntegration Without Enforced Enrollment Policy

Configure an enforced enrollment policy on the integration

mediumInactive User Expiration Not Configured

Enable automatic expiration of inactive users

mediumNo Lockout For Unenrolled Users

Lock out users who never complete enrollment

lowWeak Password Complexity

Require upper, lower, numeric, and special characters in passwords

lowShort Minimum Password Length

Increase the minimum password length to at least 12 characters

lowFraud Notification Email Disabled

Enable fraud-notification emails for suspicious authentications

mediumNo Authentication Lockout Threshold

Configure an automatic lockout threshold for failed authentications

factor

mediumUser Has Only SMS/Phone Factors

Replace SMS/phone-call factors with Duo Push or a security key

lowOrphan Phone Device

Remove phones not associated with any user

lowLandline Phone Factor

Replace landline phone factors with Duo Push or a security key

lowUnactivated Phone Device

Complete or remove phones that never finished Duo Mobile activation

lowOrphan Hardware/OTP Token

Remove hardware/OTP tokens not assigned to any user

identity

mediumDormant User

Disable or remove Duo accounts inactive for 90+ days

lowDisabled User Still Has Factors

Remove enrolled factors from disabled user accounts

lowLocked Out User

Review locked-out user accounts for brute-force or abandonment

mediumDormant Administrator

Remove administrators inactive for 90+ days

mfa

highUser Not Enrolled in MFA

Enroll the Duo user in a multi-factor authentication method

highUser in MFA Bypass Status

Remove standing MFA bypass from the user account

privilege

highAdmin With Privileged Role and No Admin-Unit Restriction

Scope Owner/Administrator admins with Administrative Units or reduce their role

lowOwner-Role Administrator

Review every Owner-role administrator for least privilege

mediumAdmin API Integration With Write Permission

Remove write/admin Admin-API permissions from integrations that only need read

highAdmin API Integration Can Manage Admins

Remove the manage-administrators Admin-API permission unless explicitly required

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial