Cisco Duo configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Cisco Duo, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cisco Duo connector needs.
Checks (8)
severity: high Admin API Integration Without IP Restriction fix difficulty: medium #
Restrict Admin API integrations to known networks/IPs
- Open the Duo Admin Panel > Applications and select the Admin API application
- Set Networks for API access (or an IP whitelist) to your egress ranges
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Integration Without Enforced Enrollment Policy fix difficulty: medium #
Configure an enforced enrollment policy on the integration
- Open the Duo Admin Panel > Applications and select the integration
- Set the New User Policy to require enrollment rather than allow access
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Inactive User Expiration Not Configured fix difficulty: easy #
Enable automatic expiration of inactive users
- Open the Duo Admin Panel > Settings > Inactive Users
- Set an inactivity expiration period (e.g. 90 days)
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium No Lockout For Unenrolled Users fix difficulty: easy #
Lock out users who never complete enrollment
- Open the Duo Admin Panel > Settings > Lockout and Fraud
- Set an unenrolled-user lockout threshold
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Weak Password Complexity fix difficulty: easy #
Require upper, lower, numeric, and special characters in passwords
- Open the Duo Admin Panel > Settings > Password
- Enable all four character-class requirements
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Short Minimum Password Length fix difficulty: easy #
Increase the minimum password length to at least 12 characters
- Open the Duo Admin Panel > Settings > Password
- Set the minimum password length to 12 or more
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Fraud Notification Email Disabled fix difficulty: easy #
Enable fraud-notification emails for suspicious authentications
- Open the Duo Admin Panel > Settings > Lockout and Fraud
- Enable fraud notification email and set a recipient address
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium No Authentication Lockout Threshold fix difficulty: easy #
Configure an automatic lockout threshold for failed authentications
- Open the Duo Admin Panel > Settings > Lockout and Fraud
- Set a lockout threshold (e.g. 10 failed attempts)
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10