Dex
Cisco Duo logo
Security & Backup

Cisco Duo

Administer Cisco Duo MFA across your managed subaccounts - users, groups, phones, enrollment, bypass codes, and authentication logs.

Dex connects to Cisco Duo through the MSP Admin API so admins can run MFA administration conversationally - list and read users, groups, phones, and integrations inside a Duo subaccount, enroll users, generate bypass codes, associate phones and groups, send verification pushes, and read authentication and administrator logs. Available as an MSP global app: one parent Admin API integration (integration key, secret key, API hostname) is shared across the partner account, and each Dex tenant is confined to its own Duo subaccount by account_id. Subaccount create/delete and the customer roster stay on the MSP master connection. Dex Go is off, so end users never get the Duo tool, though a ticket-side skill can help a requester check their own Duo status.

What Dex does with Cisco Duo

Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.

A

For admins (Dex Pro)

  • List and read Duo users in a subaccount, including status, enrollment, phones, and groups
  • Create and modify users, and email 2FA enrollment links
  • Generate bypass codes for a user - with approval, since codes skip MFA
  • Associate a user with a group or attach a phone, and send a verification push to confirm device possession
  • List and read groups, phones, and integrations (applications) in the subaccount
  • Read authentication logs and administrator action logs for the subaccount
  • Manage the MSP subaccount roster from the master connection - list, create, and delete Duo subaccounts
  • Deploy as an MSP global app - one parent Admin API integration, each customer confined to its Duo subaccount by account_id

Just ask Dex

Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.

Admin prompts

  • >List the users in the Contoso Duo subaccount and show me who is not yet enrolled
  • >Email a Duo enrollment link to jdoe@example.com
  • >What is the Duo status for the user matching msmith@acme.com - are they active, disabled, or locked out?
  • >Show me the authentication logs for this subaccount over the last day
  • >Generate a set of bypass codes for the user asmith@contoso.com

Policy actions

Every action Dex can take on Cisco Duo is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.

ActionWhat it does
duo_list_accountsList the MSP's Duo subaccounts (master connection only)
duo_create_accountCreate a Duo subaccount (master connection only) - creates a new customer partition
duo_delete_accountDelete a Duo subaccount (master connection only) - irreversible
duo_list_usersList Duo users in the subaccount
duo_read_userRead a Duo user (status, enrollment, phones, groups)
duo_create_userCreate a Duo user in the subaccount
duo_update_userModify a Duo user (status, name, email, notes)
duo_delete_userPermanently delete a Duo user (not Trash; master-only on a scoped child)
duo_enroll_userEmail a Duo 2FA enrollment link to a user
duo_create_bypass_codesGenerate Duo bypass codes for a user - these are secrets that skip MFA
duo_associate_user_groupAdd a Duo user to a group - group membership drives Duo application policy
duo_associate_user_phoneAttach a phone to a Duo user - that device can then approve their MFA
duo_send_verification_pushSend a verification push to a Duo user's phone to confirm they hold it
duo_list_groupsList Duo groups in the subaccount
duo_read_groupRead a Duo group
duo_list_phonesList Duo phones in the subaccount
duo_read_phoneRead a Duo phone
duo_list_integrationsList Duo applications (integrations) in the subaccount
duo_read_authentication_logsRead Duo authentication logs for the subaccount
duo_read_admin_logsRead Duo administrator action logs for the subaccount
duo_read_infoRead Duo account info for the subaccount

How to configure Cisco Duo

Onboarding takes minutes. Dex validates your credentials before saving them.

Setup steps

  1. 1
    In the Duo Admin Panel, go to Applications > Application Catalog > Admin API and create an Admin API application (an Owner must create it).
  2. 2
    Grant the application the permissions Dex needs: Grant resource - Read/Write, Grant read log, and under Subaccount permissions Grant accounts - Read/Write plus Grant resource - Read/Write.
  3. 3
    Copy the Integration key (ikey), Secret key (skey), and API hostname (api-XXXXXXXX.duosecurity.com or api-XXXXXXXX.duofederal.com).
  4. 4
    In Dex, enable the Cisco Duo integration and paste the integration key, secret key, and API hostname. Leave account_id blank on the MSP-master connection.
  5. 5
    Dex validates the credentials with a live signed call before saving. For MSPs, discovery reads POST /accounts/v1/account/list on the master and saves each tenant's 20-character account_id on its own connection.

Credentials required

integration_key
Admin API integration key (ikey) from the Duo Admin API application (secret)
secret_key
Admin API secret key (skey) from the same application - treat like a password (secret)
api_hostname
API hostname, api-<id>.duosecurity.com or api-<id>.duofederal.com - paste the hostname only, not https://
account_id
This tenant's 20-character Duo subaccount id - leave blank on the MSP-master connection, set it on the tenant's own connection once discovered

Requirements

  • A Cisco Duo account with an Admin API application created by an Owner
  • For MSP use, the application needs Subaccount permissions (Grant accounts - Read/Write, Grant resource - Read/Write, Grant read log)
  • Subaccount create/delete and the customer roster (POST /accounts/v1/account/list) are master-connection-only; on a scoped child connection they are refused, along with DELETE of a user
  • Dex Go is off - end users never get the Duo tool, though a ticket-side skill can help a requester check their own Duo status
  • For MSPs, the integration deploys as a global app with per-tenant scoping by account_id

See Dex run Cisco Duo

Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.