Cisco Duo identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Cisco Duo, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cisco Duo connector needs.
Checks (11)
severity: high User Not Enrolled in MFA fix difficulty: easy #
Enroll the Duo user in a multi-factor authentication method
- Open the Duo Admin Panel > Users and select the user
- Send an enrollment email or add a Duo Mobile device / hardware token
- Confirm the user completes activation (push or mobile OTP capable)
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high User in MFA Bypass Status fix difficulty: easy #
Remove standing MFA bypass from the user account
- Open the Duo Admin Panel > Users and select the user
- Change status from Bypass to Active
- If temporary bypass is required, use time-limited bypass codes instead of bypass status
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium User Has Only SMS/Phone Factors fix difficulty: medium #
Replace SMS/phone-call factors with Duo Push or a security key
- Ask the user to install Duo Mobile and activate push
- Optionally enforce a policy disallowing SMS/phone-call authenticators
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Dormant User fix difficulty: easy #
Disable or remove Duo accounts inactive for 90+ days
- Open the Duo Admin Panel > Users, sort by last login
- Disable or delete accounts no longer in use
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Disabled User Still Has Factors fix difficulty: easy #
Remove enrolled factors from disabled user accounts
- Open the Duo Admin Panel > Users and select the disabled user
- Remove associated phones and hardware tokens, or delete the account
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Locked Out User fix difficulty: easy #
Review locked-out user accounts for brute-force or abandonment
- Open the Duo Admin Panel > Users and filter by Locked Out status
- Investigate the cause and either unlock, re-enroll, or remove the account
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Dormant Administrator fix difficulty: easy #
Remove administrators inactive for 90+ days
- Open the Duo Admin Panel > Administrators, review last login
- Remove or deactivate inactive admin accounts
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Orphan Phone Device fix difficulty: easy #
Remove phones not associated with any user
- Open the Duo Admin Panel > 2FA Devices > Phones
- Delete devices with no associated users
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: low Landline Phone Factor fix difficulty: medium #
Replace landline phone factors with Duo Push or a security key
- Open the Duo Admin Panel > 2FA Devices > Phones
- Identify landline devices and migrate the user to a stronger factor
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: low Unactivated Phone Device fix difficulty: easy #
Complete or remove phones that never finished Duo Mobile activation
- Open the Duo Admin Panel > 2FA Devices > Phones
- Re-send activation or delete devices that never activated
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: low Orphan Hardware/OTP Token fix difficulty: easy #
Remove hardware/OTP tokens not assigned to any user
- Open the Duo Admin Panel > 2FA Devices > Tokens
- Delete tokens with no associated users
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4