The 23 Cisco Duo security checks Black Cat runs
Black Cat SSPM evaluates 23 security policies against your Cisco Duo configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
configuration
Restrict Admin API integrations to known networks/IPs
Configure an enforced enrollment policy on the integration
Enable automatic expiration of inactive users
Lock out users who never complete enrollment
Require upper, lower, numeric, and special characters in passwords
Increase the minimum password length to at least 12 characters
Enable fraud-notification emails for suspicious authentications
Configure an automatic lockout threshold for failed authentications
factor
Replace SMS/phone-call factors with Duo Push or a security key
Remove phones not associated with any user
Replace landline phone factors with Duo Push or a security key
Complete or remove phones that never finished Duo Mobile activation
Remove hardware/OTP tokens not assigned to any user
identity
Disable or remove Duo accounts inactive for 90+ days
Remove enrolled factors from disabled user accounts
Review locked-out user accounts for brute-force or abandonment
Remove administrators inactive for 90+ days
mfa
Enroll the Duo user in a multi-factor authentication method
Remove standing MFA bypass from the user account
privilege
Scope Owner/Administrator admins with Administrative Units or reduce their role
Review every Owner-role administrator for least privilege
Remove write/admin Admin-API permissions from integrations that only need read
Remove the manage-administrators Admin-API permission unless explicitly required