Cisco Duo for Log360 Cloud

Cisco Duo is a multi-factor authentication (MFA) and zero-trust security platform that protects access to applications by verifying user identities and the health of their devices. It supports a wide range of authentication methods including push notifications, hardware tokens, nSMS passcodes, and biometrics, enabling organizations to enforce strong access controls across cloud, on-premises, and hybrid environments.

Cisco Duo operates at the identity and access layer and serves as a frontline defense against credential-based attacks. If suspicious authentication events, unauthorized enrollments, or MFA policy changes are not addressed promptly, attackers can bypass access controls, escalate privileges, or establish persistent footholds. Rapid detection and response at the identity layer is therefore critical.

By integrating Cisco Duo with ManageEngine Log360 Cloud, security teams can not only detect and correlate identity-based threats centrally but also execute automated SOAR actions directly from incident workflows, enabling immediate containment and controlled remediation without switching consoles.

Use cases

1) Prevent account takeover attempts

When Log360 Cloud detects suspicious authentication activity-such as excessive failed logins, repeated MFA push requests, or logins from unusual geolocations-it can automatically trigger user management actions in Cisco Duo.
This enables immediate containment measures, such as disabling a compromised user account or placing it in Bypass status for investigation. Instead of waiting for manual analyst intervention, the response is executed as part of a predefined playbook, reducing dwell time and limiting the blast radius.
For example: If MFA fatigue is detected-where an attacker floods a user with push requests-Log360 Cloud can automatically modify the user’s status to Disabled while simultaneously recording analyst notes for audit tracking.
Similarly, you can automate actions such as:

  • Enroll or re-enroll users using ciscoduo_enrollUser to restore MFA protection for accounts that have had authenticators removed.
  • Retrieve and revoke bypass codes using ciscoduo_retrieveBypassCodesByUserId and ciscoduo_deleteBypassCode to eliminate persistent access loopholes.

2) Ensure only legitimate users enroll in Cisco Duo

Unauthorized enrollments can allow attackers to register their own devices and bypass MFA protections entirely. By monitoring new enrollment events and correlating them with existing identity data in Log360 Cloud, security teams can flag and investigate unexpected enrollments before they are exploited.
Automated playbooks can use ciscoduo_deleteUser or ciscoduo_modifyUser to disable or remove fraudulently enrolled accounts immediately upon detection.

3) Prevent unauthorized MFA policy changes

Attackers with administrative access may attempt to weaken MFA protections by modifying policies-for example, adding bypass exceptions or disabling secondary authentication for privileged accounts. Log360 Cloud can monitor and flag such high-risk admin actions in real time.
Automated SOAR responses can use ciscoduo_updatePolicy or ciscoduo_updateGroup to revert unauthorized changes, and ciscoduo_modifyAdministrators to revoke elevated privileges from compromised admin accounts.

Pre-requisites

  • Before creating a connection for a pre-defined service, ensure that the corresponding integration/extension is installed in Log360 Cloud.
  • Only after installing the extension will the service appear in the Connections page for connection setup.

Audited events

Authentication events

  • Fraudulent authentications
  • Success and failure authentications
  • User enrollments

Administrator events

    • User management
    • Admin management
    • Group management
    • Policy management
    • Directory sync events
    • External directory management
    • Application management
    • Hard token management

Telephony events

Telephony credits used

Release Notes

Version 2

Seamlessly integrated with Log360 Cloud SOAR workflows which ensures quick responses to identity threats by managing authentication and revoking sessions.

Version 1

Collect and analyze Cisco Duo logs to gain deeper insights into authentication and access activities.
By leveraging event patterns, you can enhance identity security, detect risky login behaviors, and respond to threats proactively.

Resources