Cisco Duo
Administer Cisco Duo MFA across your managed subaccounts - users, groups, phones, enrollment, bypass codes, and authentication logs.
Dex connects to Cisco Duo through the MSP Admin API so admins can run MFA administration conversationally - list and read users, groups, phones, and integrations inside a Duo subaccount, enroll users, generate bypass codes, associate phones and groups, send verification pushes, and read authentication and administrator logs. Available as an MSP global app: one parent Admin API integration (integration key, secret key, API hostname) is shared across the partner account, and each Dex tenant is confined to its own Duo subaccount by account_id. Subaccount create/delete and the customer roster stay on the MSP master connection. Dex Go is off, so end users never get the Duo tool, though a ticket-side skill can help a requester check their own Duo status.
What Dex does with Cisco Duo
Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.
For admins (Dex Pro)
- List and read Duo users in a subaccount, including status, enrollment, phones, and groups
- Create and modify users, and email 2FA enrollment links
- Generate bypass codes for a user - with approval, since codes skip MFA
- Associate a user with a group or attach a phone, and send a verification push to confirm device possession
- List and read groups, phones, and integrations (applications) in the subaccount
- Read authentication logs and administrator action logs for the subaccount
- Manage the MSP subaccount roster from the master connection - list, create, and delete Duo subaccounts
- Deploy as an MSP global app - one parent Admin API integration, each customer confined to its Duo subaccount by account_id
Just ask Dex
Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.
Admin prompts
- >List the users in the Contoso Duo subaccount and show me who is not yet enrolled
- >Email a Duo enrollment link to jdoe@example.com
- >What is the Duo status for the user matching msmith@acme.com - are they active, disabled, or locked out?
- >Show me the authentication logs for this subaccount over the last day
- >Generate a set of bypass codes for the user asmith@contoso.com
Policy actions
Every action Dex can take on Cisco Duo is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.
| Action | What it does |
|---|---|
duo_list_accounts | List the MSP's Duo subaccounts (master connection only) |
duo_create_account | Create a Duo subaccount (master connection only) - creates a new customer partition |
duo_delete_account | Delete a Duo subaccount (master connection only) - irreversible |
duo_list_users | List Duo users in the subaccount |
duo_read_user | Read a Duo user (status, enrollment, phones, groups) |
duo_create_user | Create a Duo user in the subaccount |
duo_update_user | Modify a Duo user (status, name, email, notes) |
duo_delete_user | Permanently delete a Duo user (not Trash; master-only on a scoped child) |
duo_enroll_user | Email a Duo 2FA enrollment link to a user |
duo_create_bypass_codes | Generate Duo bypass codes for a user - these are secrets that skip MFA |
duo_associate_user_group | Add a Duo user to a group - group membership drives Duo application policy |
duo_associate_user_phone | Attach a phone to a Duo user - that device can then approve their MFA |
duo_send_verification_push | Send a verification push to a Duo user's phone to confirm they hold it |
duo_list_groups | List Duo groups in the subaccount |
duo_read_group | Read a Duo group |
duo_list_phones | List Duo phones in the subaccount |
duo_read_phone | Read a Duo phone |
duo_list_integrations | List Duo applications (integrations) in the subaccount |
duo_read_authentication_logs | Read Duo authentication logs for the subaccount |
duo_read_admin_logs | Read Duo administrator action logs for the subaccount |
duo_read_info | Read Duo account info for the subaccount |
How to configure Cisco Duo
Onboarding takes minutes. Dex validates your credentials before saving them.
Setup steps
- 1In the Duo Admin Panel, go to Applications > Application Catalog > Admin API and create an Admin API application (an Owner must create it).
- 2Grant the application the permissions Dex needs: Grant resource - Read/Write, Grant read log, and under Subaccount permissions Grant accounts - Read/Write plus Grant resource - Read/Write.
- 3Copy the Integration key (ikey), Secret key (skey), and API hostname (api-XXXXXXXX.duosecurity.com or api-XXXXXXXX.duofederal.com).
- 4In Dex, enable the Cisco Duo integration and paste the integration key, secret key, and API hostname. Leave account_id blank on the MSP-master connection.
- 5Dex validates the credentials with a live signed call before saving. For MSPs, discovery reads POST /accounts/v1/account/list on the master and saves each tenant's 20-character account_id on its own connection.
Credentials required
- integration_key
- Admin API integration key (ikey) from the Duo Admin API application (secret)
- secret_key
- Admin API secret key (skey) from the same application - treat like a password (secret)
- api_hostname
- API hostname, api-<id>.duosecurity.com or api-<id>.duofederal.com - paste the hostname only, not https://
- account_id
- This tenant's 20-character Duo subaccount id - leave blank on the MSP-master connection, set it on the tenant's own connection once discovered
Requirements
- •A Cisco Duo account with an Admin API application created by an Owner
- •For MSP use, the application needs Subaccount permissions (Grant accounts - Read/Write, Grant resource - Read/Write, Grant read log)
- •Subaccount create/delete and the customer roster (POST /accounts/v1/account/list) are master-connection-only; on a scoped child connection they are refused, along with DELETE of a user
- •Dex Go is off - end users never get the Duo tool, though a ticket-side skill can help a requester check their own Duo status
- •For MSPs, the integration deploys as a global app with per-tenant scoping by account_id
Related integrations
- Directory & Identity
Microsoft Entra ID
Manage Entra ID users, groups, licenses, and sign-in risk through Microsoft Graph.
Learn more → - Directory & Identity
Okta
Run Okta user, group, and app-assignment operations in natural language.
Learn more → - Security & Backup
CrowdStrike Falcon
Triage Falcon detections and respond to hosts conversationally - inventory sensors, isolate compromised machines, and run Real Time Response.
Learn more →
See Dex run Cisco Duo
Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.