Cisco Duo operates at the identity and access layer and serves as a frontline defense against credential-based attacks. If suspicious authentication events, unauthorized enrollments, or MFA policy changes are not addressed promptly, attackers can bypass access controls, escalate privileges, or establish persistent footholds. Rapid detection and response at the identity layer is therefore critical.
By integrating Cisco Duo with ManageEngine Log360 Cloud, security teams can not only detect and correlate identity-based threats centrally but also execute automated SOAR actions directly from incident workflows, enabling immediate containment and controlled remediation without switching consoles.
Use cases

Pre-requisites
- Before creating a connection for a pre-defined service, ensure that the corresponding integration/extension is installed in Log360 Cloud.
- Only after installing the extension will the service appear in the Connections page for connection setup.
Audited events
Release Notes
Version 2
Seamlessly integrated with Log360 Cloud SOAR workflows which ensures quick responses to identity threats by managing authentication and revoking sessions.
Version 1
Collect and analyze Cisco Duo logs to gain deeper insights into authentication and access activities.
By leveraging event patterns, you can enhance identity security, detect risky login behaviors, and respond to threats proactively.


