Skip to content

Cisco Duo identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Cisco Duo, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cisco Duo connector needs.

Checks (11)

severity: high User Not Enrolled in MFA fix difficulty: easy #

Enroll the Duo user in a multi-factor authentication method

  1. Open the Duo Admin Panel > Users and select the user
  2. Send an enrollment email or add a Duo Mobile device / hardware token
  3. Confirm the user completes activation (push or mobile OTP capable)

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high User in MFA Bypass Status fix difficulty: easy #

Remove standing MFA bypass from the user account

  1. Open the Duo Admin Panel > Users and select the user
  2. Change status from Bypass to Active
  3. If temporary bypass is required, use time-limited bypass codes instead of bypass status

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium User Has Only SMS/Phone Factors fix difficulty: medium #

Replace SMS/phone-call factors with Duo Push or a security key

  1. Ask the user to install Duo Mobile and activate push
  2. Optionally enforce a policy disallowing SMS/phone-call authenticators

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Dormant User fix difficulty: easy #

Disable or remove Duo accounts inactive for 90+ days

  1. Open the Duo Admin Panel > Users, sort by last login
  2. Disable or delete accounts no longer in use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low Disabled User Still Has Factors fix difficulty: easy #

Remove enrolled factors from disabled user accounts

  1. Open the Duo Admin Panel > Users and select the disabled user
  2. Remove associated phones and hardware tokens, or delete the account

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low Locked Out User fix difficulty: easy #

Review locked-out user accounts for brute-force or abandonment

  1. Open the Duo Admin Panel > Users and filter by Locked Out status
  2. Investigate the cause and either unlock, re-enroll, or remove the account

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: medium Dormant Administrator fix difficulty: easy #

Remove administrators inactive for 90+ days

  1. Open the Duo Admin Panel > Administrators, review last login
  2. Remove or deactivate inactive admin accounts

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low Orphan Phone Device fix difficulty: easy #

Remove phones not associated with any user

  1. Open the Duo Admin Panel > 2FA Devices > Phones
  2. Delete devices with no associated users

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: low Landline Phone Factor fix difficulty: medium #

Replace landline phone factors with Duo Push or a security key

  1. Open the Duo Admin Panel > 2FA Devices > Phones
  2. Identify landline devices and migrate the user to a stronger factor

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: low Unactivated Phone Device fix difficulty: easy #

Complete or remove phones that never finished Duo Mobile activation

  1. Open the Duo Admin Panel > 2FA Devices > Phones
  2. Re-send activation or delete devices that never activated

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: low Orphan Hardware/OTP Token fix difficulty: easy #

Remove hardware/OTP tokens not assigned to any user

  1. Open the Duo Admin Panel > 2FA Devices > Tokens
  2. Delete tokens with no associated users

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More Cisco Duo checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial