Connecting to DUO

AJ Suurhoff
AJ Suurhoff
  • Updated

The Duo integration syncs users from Duo into ControlMap and runs compliance checks for user ownership and multi-factor authentication (MFA).

Prerequisites

Who can use this feature?
A ControlMap user with Super Admin or Compliance Manager permission.

What you’ll need:

  • A Duo account with the Owner role. Duo Owner access is required to add the Admin API application.

  • Access to a ControlMap tenant.

Note: This article captures third-party steps and/or an interface that may have since been updated.

Create the Admin API application in Duo

Use the Duo Admin API application to provide ControlMap with access to the Duo data required for the integration. Do not use a generic single sign-on (SSO) application.

  1. Sign in to the Duo Admin Panel with an account that has the Owner role.

  2. In the left-hand menu, go to Applications > Application Catalog.

  3. Search for Admin API.

  4. Select the Admin API application with the description “Provide programmatic access to the administrative functionality of Duo’s platform.”

  5. Click Add to create the application.

For more details about Duo’s administrative API, see Duo Admin API.

Configure the Admin API permissions

Configure the following permissions in the Admin API application:

  1. In the Admin API application, go to Settings > Permissions.

  2. Enable the following permission groups:

    • Grant administrators — Read and Write

      • Grant resource — Read and Write

      • Grant set Admin API permissions

  3. Save the application.

Copy the Duo credentials

From the same Admin API application, copy the following values and store them securely:

  • Integration key

  • Secret key

  • API hostname

Use all three values from the same Admin API application. If you generate or use credentials from different applications, ControlMap might not be able to authenticate the connection.

Connect Duo in ControlMap

  1. In your ControlMap tenant, go to Integrations > Identity Providers > Duo.

  2. Click Connect.

  3. Enter the Integration key, Secret key, and API hostname copied from Duo.

  4. Confirm the compliance checks you want to run.

  5. Add any required watchers.

  6. Confirm the sync schedule.

  7. Save the integration.

Compliance checks

The Duo integration can run the following compliance checks:

  • All user accounts are assigned to an employee or owner.

  • All users have MFA enabled.

  • All admins have MFA enabled.

Any questions?

Reach out to the ControlMap support team by submitting a support ticket.

Was this article helpful?

Yes! No