Skip to content

Cisco Duo configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Cisco Duo, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cisco Duo connector needs.

Checks (8)

severity: high Admin API Integration Without IP Restriction fix difficulty: medium #

Restrict Admin API integrations to known networks/IPs

  1. Open the Duo Admin Panel > Applications and select the Admin API application
  2. Set Networks for API access (or an IP whitelist) to your egress ranges

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Integration Without Enforced Enrollment Policy fix difficulty: medium #

Configure an enforced enrollment policy on the integration

  1. Open the Duo Admin Panel > Applications and select the integration
  2. Set the New User Policy to require enrollment rather than allow access

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Inactive User Expiration Not Configured fix difficulty: easy #

Enable automatic expiration of inactive users

  1. Open the Duo Admin Panel > Settings > Inactive Users
  2. Set an inactivity expiration period (e.g. 90 days)

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium No Lockout For Unenrolled Users fix difficulty: easy #

Lock out users who never complete enrollment

  1. Open the Duo Admin Panel > Settings > Lockout and Fraud
  2. Set an unenrolled-user lockout threshold

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Weak Password Complexity fix difficulty: easy #

Require upper, lower, numeric, and special characters in passwords

  1. Open the Duo Admin Panel > Settings > Password
  2. Enable all four character-class requirements

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Short Minimum Password Length fix difficulty: easy #

Increase the minimum password length to at least 12 characters

  1. Open the Duo Admin Panel > Settings > Password
  2. Set the minimum password length to 12 or more

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Fraud Notification Email Disabled fix difficulty: easy #

Enable fraud-notification emails for suspicious authentications

  1. Open the Duo Admin Panel > Settings > Lockout and Fraud
  2. Enable fraud notification email and set a recipient address

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium No Authentication Lockout Threshold fix difficulty: easy #

Configure an automatic lockout threshold for failed authentications

  1. Open the Duo Admin Panel > Settings > Lockout and Fraud
  2. Set a lockout threshold (e.g. 10 failed attempts)

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Cisco Duo checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial