Skip to content

Cisco Duo access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Cisco Duo, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cisco Duo connector needs.

Checks (4)

severity: high Admin With Privileged Role and No Admin-Unit Restriction fix difficulty: medium #

Scope Owner/Administrator admins with Administrative Units or reduce their role

  1. Open the Duo Admin Panel > Administrators and select the admin
  2. Assign an Administrative Unit restriction, or downgrade to Help Desk/User Manager
  3. Confirm the remaining unrestricted owners are intentional break-glass accounts

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: low Owner-Role Administrator fix difficulty: easy #

Review every Owner-role administrator for least privilege

  1. Open the Duo Admin Panel > Administrators and list Owner-role admins
  2. Downgrade any account that does not require full ownership

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: medium Admin API Integration With Write Permission fix difficulty: easy #

Remove write/admin Admin-API permissions from integrations that only need read

  1. Open the Duo Admin Panel > Applications and select the Admin API application
  2. Set permission to "Grant read information" / "Grant read resource" only, unless write is required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: high Admin API Integration Can Manage Admins fix difficulty: easy #

Remove the manage-administrators Admin-API permission unless explicitly required

  1. Open the Duo Admin Panel > Applications and select the Admin API application
  2. Disable "Grant administrators" permission unless administrator management via API is required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

More Cisco Duo checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial