Cisco Duo access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Cisco Duo, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cisco Duo connector needs.
Checks (4)
severity: high Admin With Privileged Role and No Admin-Unit Restriction fix difficulty: medium #
Scope Owner/Administrator admins with Administrative Units or reduce their role
- Open the Duo Admin Panel > Administrators and select the admin
- Assign an Administrative Unit restriction, or downgrade to Help Desk/User Manager
- Confirm the remaining unrestricted owners are intentional break-glass accounts
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: low Owner-Role Administrator fix difficulty: easy #
Review every Owner-role administrator for least privilege
- Open the Duo Admin Panel > Administrators and list Owner-role admins
- Downgrade any account that does not require full ownership
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: medium Admin API Integration With Write Permission fix difficulty: easy #
Remove write/admin Admin-API permissions from integrations that only need read
- Open the Duo Admin Panel > Applications and select the Admin API application
- Set permission to "Grant read information" / "Grant read resource" only, unless write is required
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: high Admin API Integration Can Manage Admins fix difficulty: easy #
Remove the manage-administrators Admin-API permission unless explicitly required
- Open the Duo Admin Panel > Applications and select the Admin API application
- Disable "Grant administrators" permission unless administrator management via API is required
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3