No more typing reviews! Try our Samantha, our new voice AI agent.
Researcher at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Mar 12, 2026
Log analysis has strengthened threat detection and builds customer confidence
Pros and Cons
  • "The best feature Cisco Duo offers is its simplicity."
  • "Cisco Duo could be improved with more interesting rules or correlation rules between all the data sources such as Windows and Azure."

What is our primary use case?

My main use case for Cisco Duo is to detect network-based threats.

There is one situation where malware is downloaded via a link, and Cisco Duo has blocked this URL, demonstrating how I use Cisco Duo as a detector for network-based threats.

We can correlate Cisco Duo with other data sources such as cloud and Azure, which represents another interesting scenario about how I use Cisco Duo.

What is most valuable?

The best feature Cisco Duo offers is its simplicity.

The interface is what makes Cisco Duo simple for me.

Cisco Duo has positively impacted my organization as we can analyze the logs to detect threats.

Analyzing logs and detecting threats with Cisco Duo helps customers gain confidence in our company, showing the positive effects it has had on my organization.

What needs improvement?

Cisco Duo could be improved with more interesting rules or correlation rules between all the data sources such as Windows and Azure.

For how long have I used the solution?

I have been using Cisco Duo for six months.

Buyer's Guide
Cisco Duo
August 2026
Learn what your peers think about Cisco Duo. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.

What other advice do I have?

I have not yet implemented Cisco Duo's end-to-end phishing resistance with capabilities such as proximity verification to strengthen my organization's ability to defend against modern phishing and identity-based attacks.

There are no other improvements needed with Cisco Duo that we have not discussed. I would rate this product an 8.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 12, 2026
Flag as inappropriate
PeerSpot user
RyanDeppe - PeerSpot reviewer
Solutions Architect at Winslow Technology Group
Real User
Jun 21, 2023
Helps reduce the risk of a breach and is easy to deploy and onboard
Pros and Cons
  • "The ease of deploying Cisco Duo Security and onboarding has greatly benefited our customers."
  • "Cisco can further enhance the integrations, as they possess exceptional integrations with various providers' products and feature sets."

What is our primary use case?

We have been using Duo Security for authentication in our in-house sales operations technologies. Therefore, as a Cisco partner, we regularly recommend Cisco Duo Security to our customers to help secure their VPN environments or connectivity to business-critical systems.

How has it helped my organization?

For our customers, Duo Security is a significant advantage because it provides them with a straightforward method to implement MFA across their entire environment. Moreover, once we delve into the more advanced features of Duo Security, it enables us as a partner to engage in ongoing discussions regarding security strategies with our customers. Initially, we may only introduce them to MFA during the onboarding process. However, as their security strategy evolves, we can leverage Duo to perform additional tasks such as risk-based assessments and deployments, thereby assisting in the development of their security measures.

Duo Security helps secure our infrastructure. It serves as our gateway layer of protection, allowing us to understand who is logging in and why. We conduct risk-based assessments on each user to determine whether their actions are appropriate or not. Duo Security is not a comprehensive security solution, but it is undoubtedly a crucial component, a critical layer of security. This aspect resonates with our customers consistently.

Their ability to reduce the risk of a breach is of utmost importance. It serves as the primary line of defense. Currently, credential gathering and leaks are widespread in the market. By implementing an MFA solution like Duo Security, we can effectively prevent these issues. When we put a stop to credential harvesting, it becomes much harder for attackers to infiltrate and navigate our network. Therefore, Duo Security acts as an excellent first line of defense.

User authentication and device verification are the methods through which we envision our customers navigating in order to prevent identity-based attacks. Initially, when we employ Duo Security, it is a straightforward implementation of multi-factor authentication. As we progress, we enhance security measures by incorporating device risk assessment and potentially even regional assessment. This includes considerations such as whether the login is being attempted from a specific IP address. These gradual enhancements contribute to the establishment of an additional layer of protection. Thus, it is not necessary to implement a completely disruptive strategy right from the start. Instead, it is possible to gradually adopt and integrate this approach, following a crawl, walk, or run methodology.

The Duo Security self-service portal helps free up our customers' IT staff time, allowing them to focus on other projects. As a Cisco partner, we have received feedback from our customers that the portal is highly interactive, enabling them to easily navigate and resolve issues. After setting up their Duo environment, we rarely receive callbacks for assistance, as the portal is intuitive and empowers users to handle everything they need on their own.

The appealing aspect of Duo Security is its ability to establish trust for every access request, regardless of its origin. It is a cloud-based solution with excellent API integrations. It doesn't matter where or how a user logs in; Duo will be there to protect the user, whether it's through MFA, risk assessment, or similar methods. 

It is extremely beneficial to our customers that Duo Security considers all resources as external. Our customers frequently inquire about a zero-trust model, and this is a key component of it. Unfortunately, I would love to say that there is a simple solution for zero trust where we can just deploy this solution and be done with it. But that's not the case. It requires a layered approach, and that's what we convey to our customers. Duo Security is definitely a part of that.

Duo Security has helped improve our customers' cybersecurity resilience. Internally, it protects our users from accessing sales operations-based environments. Additionally, our customers use it regularly to protect business-critical applications.

What is most valuable?

The ease of deploying Cisco Duo Security and onboarding has greatly benefited our customers. When they have the need or requirement to implement an MFA solution, being able to swiftly set up Cisco Duo Security is perhaps the fastest and simplest feature available.

What needs improvement?

There is always room for improvement. Duo Security is a great product in its current state. However, Cisco can further enhance the integrations, as they possess exceptional integrations with various providers' products and feature sets. They should continue to improve and expand these integrations to include more products. The more integrations they offer, the more advantageous it becomes for us as a Cisco partner to promote and sell their product.

For how long have I used the solution?

I have been using Duo Security for one and a half years.

What do I think about the stability of the solution?

The stability has been excellent. I haven't heard of any issues, either internally or from our customers, regarding any problems with the Cisco Duo platform, the authentication VM, or anything of that nature.

What do I think about the scalability of the solution?

Scalability is excellent. Being cloud-driven, our customers are not concerned. They can simply purchase licenses as they need them, and scale up or down as required. Typically, scaling up and scaling out is the norm. The flexible licensing model and cloud-based delivery enable this process.

How are customer service and support?

Cisco support has consistently been exceptional, and Duo is no different. Although we seldom encounter issues, when we do, they usually relate to product integration or similar matters. However, these problems are never troublesome. The support documentation provided by Duo is superb, possibly even top-notch opinion. Therefore, even if we do experience an issue, more often than not, we can locate a solution within the existing documentation.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have always used Duo Security internally. We have observed some of our customers replacing Microsoft Azure MFA with Duo Security due to its superior capabilities. Duo Security offers better compatibility and works seamlessly with various other vendors. Therefore, we have witnessed cases where customers replace their Azure MFA with Duo Security. In other instances, customers have chosen to complement Azure MFA with Duo Security. Some customers have investments in Microsoft that they do not want to lose, which is understandable. We acknowledge that fact. However, Duo Security is a highly complementary technology they may utilize for high-profile business applications or even VPN authentication. This is because it integrates well with their hardware or software.

The flexibility offered by Duo Security, its ease of operation, and the overall advantage of having the Cisco name behind it is significant. Knowing that Cisco is a global leader in security and backed by Cisco Talos is one of the primary reasons organizations make the switch. Consequently, it is straightforward to discuss with customers the benefits that Cisco brings to the table and how Duo Security can provide flexibility in their security strategies.

How was the initial setup?

Deploying Duo Security is extremely easy. As a cloud-based solution, we can have services up and running within a day.

What was our ROI?

What we have observed from some of our customers is that having an MFA solution like Cisco Duo Security in place actually reduces their premiums for cybersecurity insurance. This means that investing in MFA provides an immediate return on investment, as they are guaranteed to recoup the money. Many cyber insurance companies now mandate the inclusion of MFA features. If we do not have MFA, we either have to pay higher premiums or risk not having coverage at all. Therefore, deploying Cisco Duo quickly and effortlessly offers an instant ROI for many of our customers, allowing them to obtain the necessary coverage from their cyber insurance carrier.

If we meet not only MFA solutions but also other criteria within the cybersecurity insurance industry, savings could be upwards of fifty percent on our premium. This is because, as we deploy more security solutions, our level of risk decreases, as observed by cybersecurity insurance companies. Consequently, we become a lower-risk customer, leading to reduced premiums. However, if we don't have some of these solutions in place, there are two significant risks: firstly, we may not be covered at all, which is a considerable risk; and secondly, if we are covered, our premiums will be exorbitantly high.

What's my experience with pricing, setup cost, and licensing?

I believe the licensing model is excellent as it offers flexibility to our customers, allowing them to adopt a crawl, walk, or run approach. We don't have to sell the highest licensing feature set right from the beginning because they may not require it. Therefore, starting with the MFA license can be sufficient for them, as it helps onboard them and allows them to become comfortable with the solution. As they develop their strategy, we can gradually introduce them to different layers of Duo Security. This approach has been a successful business model for us.

What other advice do I have?

I give Duo Security a nine out of ten.

For those who want to enhance their cybersecurity, Duo Security is an excellent initial step. It enables individuals to eliminate easily exploitable vulnerabilities and embark on their security strategy journey. This journey cannot be completed in a single day, but Duo will assist in taking that crucial first step.

For those currently evaluating Duo Security, I encourage them to take advantage of the free trial. They can sign up at little or no cost and try the product to assess its feature sets and availability. Utilize this opportunity to thoroughly test and explore the product and make use of the available documentation. It's an excellent method to gauge the capabilities of Duo Security.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Cisco Duo
August 2026
Learn what your peers think about Cisco Duo. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.
Ata Alemoush - PeerSpot reviewer
Sr Modern Workplace Specialist at a logistics company with 10,001+ employees
Real User
Aug 1, 2022
A straightforward solution with an excellent GUI, easy setup, and outstanding support
Pros and Cons
  • "The integration with Azure Active Directory and the AWS cloud is amazing, as most products nowadays require the creation of a customized integration. With Duo Security, it was more like native integration, and it took me five minutes to register."
  • "Compared with other products, Duo Security is excellent; I'm very impressed, and so are my colleagues."
  • "Integration with a product such as Microsoft Sentinel would be great. As the product continually improves, I'm unsure if this feature is available."

What is our primary use case?

A colleague and I conducted some market research, where we found the solution and implemented it according to our needs. We installed the agents in our server, which communicate with Duo Security and send a prompt to our mobiles which is very convenient. We can also use the authenticator with other products and integrate it with a password reset disk. The product covers all of our needs.

How has it helped my organization?

The solution allows us to cover significant organizations and audit organizations with very high-security demands. At that level, security is non-negotiable, and Duo Security provides a second layer multi-factor server authentication, easy implementation, and Microsoft integration. 

What is most valuable?

The integration with Azure Active Directory and the AWS cloud is amazing, as most products nowadays require the creation of a customized integration. With Duo Security, it was more like native integration, and it took me five minutes to register.

The solution is straightforward, requiring minimal training and expertise to operate; IT staff have no problem understanding it.

The GUI is excellent, and the solution has valuable features, including policies and easy integration. It's a fantastic product.

Cisco owns Duo Security, and they are trusted everywhere, so establishing trust for access requests is never an issue. This is a major factor because when it comes to security, the solution must come from a trusted organization. We don't want to place our security in the hands of unknown third-party organizations; data leaks are a genuine concern. 

I can't give specific details of my organization's security risks, but I can say that Duo Security has eliminated trust from my organization's network architecture. 

I'm amazed by the product, especially by the ease of implementation. One of our major clients was equally impressed with the product. We use this solution to secure our network, which meets all our needs.   

Compared with other products, Duo Security is excellent; I'm very impressed, and so are my colleagues. I can't speak highly enough of this solution. The support of hybrid work is vital nowadays, as many organizations are moving from on-premises to cloud and hybrid environments, so it's important for the product to be compatible with both environments.

In the enterprise segment, we require many solutions to defend against different threats, with each system responsible for its own security function. Duo Security remediates the specific threats we need and has all the necessary features. 

I would rate the solution a 10 out of 10 in this area. 

What needs improvement?

Integration with a product such as Microsoft Sentinel would be great. As the product continually improves, I'm unsure if this feature is available.

For how long have I used the solution?

We have been using the solution for two years. 

What do I think about the stability of the solution?

The solution is 100% stable.

I work with many products, and I've realized that the ones based in America run SMS and phone call communications through Twilio. As we are outside America, Twilio isn't correctly integrated with our local ISPs, so it has some issues with our IPs. This can impede our communications and is an issue I've faced multiple times because of Twilio.

What do I think about the scalability of the solution?

The platform is highly scalable, and Duo Security is constantly improving its product; I receive weekly emails about new features and improvements they have made.

How are customer service and support?

The support staff are fantastic, they're very impressive and I would rate them a 10 out of 10. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We use the native Microsoft Authenticator and implement Duo Security as an additional layer of protection.

How was the initial setup?

The initial setup is straightforward; Duo Security provides excellent documentation and support compared to other companies. This solution can be deployed in a day.

What about the implementation team?

I deployed the solution myself using the provided documentation and sometimes reached out to support. I never had an issue, and implementation took just two days.

What was our ROI?

We definitely received an ROI; the solution improved our security by perhaps 70%, and this particular landing zone requires significant protection.

What's my experience with pricing, setup cost, and licensing?

I only need the solution for IT staff, which makes it relatively cheap. If I deployed it for the whole company, it would be costly, so it depends on the number of users. Duo Security is affordable compared to other products in the segment.

Which other solutions did I evaluate?

I don't exactly remember which other solutions we considered, but we used G2's platform's reports to evaluate them.

What other advice do I have?

I would rate this solution a nine out of ten. 

The maintenance of network connectivity depends on the complexity of the organization. It is easy to implement for our company and our architecture, but it wouldn't be as easy for a more complex network structure like a bank. We use the SaaS version of the product, so it's straightforward to implement and maintain. 

Our staff weren't used to using MFA, so it was initially frustrating for them, but this is a security requirement for us, and they adapted to it.

I would advise leaders looking to build resilience in their organization to implement another MFA product like Duo Security. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2175198 - PeerSpot reviewer
reviewer2175198Works at a computer software company with 10,001+ employees
Real User

Hi Ata! It looks like you can integrate with Sentinel using the Cisco Duo Security Data Connection for Sentinel: https://help.duo.com/s/article...

Senior Information Security Engineer at DAAC System Integrator
Reseller
Top 10
Jan 15, 2025
Security measures and seamless updates improve organization
Pros and Cons
  • "All features of the solution are effective, particularly those involved in identifying vulnerabilities and updates."
  • "My overall rating for the solution is ten out of ten."
  • "All features of the solution are effective, Duo supports BYOD policies by allowing users to authenticate securely from their personal devices."
  • "There was an issue related to integration with third parties."
  • "The customer service is okay. However, the response time could be faster."

What is our primary use case?

At this point, the primary use case of Cisco Duo is to secure access to systems, applications, and data through multi-factor authentication (MFA), and we use Cisco Duo, which we also provide to other clients. We implemented it and use it ourselves. The IT and finance departments should be involved in the process.

How has it helped my organization?

Simplified Access Management with a centralized admin control, security remote access even with their BYOD etc.

What is most valuable?

All features of the solution are effective, Duo supports BYOD policies by allowing users to authenticate securely from their personal devices. This flexibility allows employees to work from anywhere while ensuring that only secure devices can access corporate data. This has been very effective for our organization, and we have not encountered any issues. We use Cisco Duo and provide it to our clients as well. We implemented it and also use it internally. The IT and finance departments should be involved.

What needs improvement?

I found some issues yet do not remember them specifically. There was an project requirement related to facial recognition integration imbedded in duo.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

The stability of the solution is okay. We have not found any issues.

What do I think about the scalability of the solution?

Until now, we did not find issues related to scalability as we did not implement the solution at a large scale.

How are customer service and support?

The customer service is okay. However, the response time could be faster.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup consists mostly of demos, so it is not very hard to implement. 

Additionally, there is also online support available. The setup took around a week, depending on how big the infrastructure is.

What's my experience with pricing, setup cost, and licensing?

The setup cost is reasonable, estimated at around six euros per month.

What other advice do I have?

We did not find any issues. The clients who want to acquire this product need to change something in the security infrastructure by implementing MFA security authentication, like Duo, and so on. My overall rating for the solution is ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Security Specialist at zeezsecops.com.ng
Real User
Jan 4, 2024
Effectively safeguards against unauthorized access attempts or server breaches
Pros and Cons
  • "They are users who, as mentioned before, utilize RDPAP and MDPAP. It includes functionalities related to finance, specifically in single sign-on."
  • "I believe there are two new features. I am interested in adding auto-admin services and incorporating icons for easier navigation. This could contribute to a new business idea platform. I have seen the features, and they make things easier, resolving issues from before. The platform has been updated, and there's now another link in my platform for media access. When it comes to improvements, the UI can be more user-friendly, and there is room for easier navigation. Perhaps there could be enhancements in customization. I haven't faced issues in storage or backup, but I am open to improvements in customization functionality. It's not my environment, but I see possibilities for improvement in the deployment of funds. The addition of new features is appreciated, and for customization, it could provide more freedom for users."

What is our primary use case?

On my end, Cisco Duo suits my account needs well. The application remains in place. We generally apply Cisco Duo across various use cases. Many customers, including banks and private organizations, use it for enhanced security, particularly in financial and general security tasks.

What needs improvement?

I am interested in adding auto-admin services and incorporating icons for easier navigation. This could contribute to a new business idea platform. I have seen the features, and they make things easier, resolving issues from before. The platform has been updated, and there's now another link in my platform for media access.

When it comes to improvements, the UI can be more user-friendly, and there is room for easier navigation. 

There could be enhancements in customization. I haven't had issues with storage or backup, but I am open to improvements in customization functionality. It's not my environment, but I see possibilities for improvement in the deployment of funds.

For how long have I used the solution?

I have been using Cisco Duo for the past year. Customers request server protection using various servers, and it can integrate with applications. It is an MFA solution, designed for server access and data security.

What do I think about the stability of the solution?

Typically, I manage things directly from the GUI, and I handle whatever comes up. So far, stability has been an issue, but I am not the creator of the solution, so I cannot predict future occurrences. 

Generally, it has been fine without any notable issues, but the future is uncertain. I would rate it 8 out of 10. 

What do I think about the scalability of the solution?

It is scalable and I would rate it 8 out of 10. Regarding the size of your customers, they are mostly large enterprises.

How are customer service and support?

We haven't encountered any significant issues so far. The only time we need to contact support is when something arises, and they promptly address it. Everything else has been running smoothly.

How would you rate customer service and support?

Neutral

How was the initial setup?

I would rate it seven because it comes with numerous features that require continuous upgrades. I have observed the need for consistent updates in the inventory. It is beneficial for newcomers to the platform, as data is continuously added, and automation has reduced the effort required to find information. It roughly takes 12 hours to be deployed.

What's my experience with pricing, setup cost, and licensing?

I am not aware of the pricing. There are two departments, and I don't have any information about them.

What other advice do I have?

Cisco Duo effectively safeguards against customer factors, such as unauthorized access attempts or server breaches. It provides a high level of protection, ensuring only authorized individuals have access to the environment. I am confident in its security features.

I would rate it 8 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Telecom Engineer at a university with 1,001-5,000 employees
Video Review
Real User
Aug 8, 2023
The easy remote access is the biggest benefit
Pros and Cons
  • "At the moment, the ease of use is what is the best feature for me. Once it has been set up and the security can hoc to my mobile device, it's very simple to use my single sign-on, get prompted for a Duo Security, push, go to my phone, accept the push, and I'm done. It's a very simple process."
  • "The only thing I can think of to improve for tech support is to have a dedicated engineer but then I would get an engineer that has priorities in one area or another and maybe not the scope I need."

What is our primary use case?

I work in an institution with about 6,000 people. I'm a telecommunications engineer. I use Duo Security as my access point when working remotely. Because I'm a telecommunications engineer, I have to have access to my systems remotely, and our VPN client requires that we go through second-level verification, for which we use Duo Security

Ours is on-prem. We have on-prem Duo Security. We do not use cloud at this time. 

How has it helped my organization?

The benefit of Duo Security, for me, is the very easy remote access. I don't have to go through repeated steps to log in to my platform, and it's the same process every time. It works quickly, and it's just that simple.

When it comes to securing our infrastructure from end to end, I wish I could speak more in-depth about that. I do know that Duo Security does identify me as a user, and the folks that need to track who's using it, when, and why. I know that there are very detailed and well-designed reports to let them do that. I am not on that side of Duo Security. Again, as a user, the best part is the ease of use. 

What is most valuable?

At the moment, the ease of use is what is the best feature for me. Once it has been set up and the security can hoc to my mobile device, it's very simple to use my single sign-on, get prompted for a Duo Security, push, go to my phone, accept the push, and I'm done. It's a very simple process. 

What needs improvement?

The only thing I can think of to improve for tech support is to have a dedicated engineer but then I would get an engineer that has priorities in one area or another and maybe not the scope I need.

I like the fact that when I open a ticket, I'm not getting the same caller calling back. I like the variety of support that Cisco offers.

Opening a technical assistant's request is a little challenging at times. I wish that the Cisco website could understand who I am from the chart and just let me in rather than forcing me to pick out my contract number, my address, or something like that. They should make it streamlined, make it simple.

For how long have I used the solution?

I have been in this current position with Duo Security for two and a half years.

What do I think about the stability of the solution?

To my knowledge, we are relatively stable. I know there are times when in-house we may have difficulty with servers, connectivity, or databases, but it only happens sporadically. I think in my experience, we've had Duo not work maybe once or twice in the last two and a half years. It usually results in rebooting a server.

What do I think about the scalability of the solution?

When we speak of clients on which Duo Security is deployed, every user in my environment typically has a cell phone and a laptop and we use mobile push. I believe we do use PIN capabilities, as well, but primarily we use mobile push. I suspect that it's on a PC mobile platform.  

How are customer service and support?

On average, Cisco's technical support is very good. There are times that I need to go through escalation processes, but once I escalate it, I know that I'm going to get the service I need. The more challenging part for me is defining the problems so that the technical solution reps can help me solve them. 

My rating for Cisco technical support would vary depending on what they are supporting for me. I would say they've never dropped below, say, a 7.5, but pretty consistently range in a nine out of ten category.

I think Cisco support works very hard to satisfy my needs as a customer rather than frustrating me.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I believe that they did use a different solution. I actually believe that we did not have multi-level verification on our VPN login when we started out. As a result of COVID, it became necessary to have multi-level verification. That was when Duo Security was introduced. I also understand, this was prior to my employment, that Duo Security was enacted in less than seven days. 

What was our ROI?

As a case for return on investment, I would stretch my exposure and say that the return has been remarkable because we went from full-time, on-premise workers, to full-time remote for everyone for several months. Subsequently, many of our staff now work a hybrid schedule, and Duo Security makes it entirely possible. 

What's my experience with pricing, setup cost, and licensing?

When it comes to pricing, the only thing I can say is that working in education, when you buy a product, it has to have value. My assumption is that Duo Security has a great deal of value for its cost. 

What other advice do I have?

To advise somebody about Duo Security, I would say it works. It works. 

I have not experienced another security program like Duo Security. I don't have a way of rating it other than to say, I'm happy with how it works, and it makes my job easier. 

I'll give it a 9.25 out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2212659 - PeerSpot reviewer
Network Administrator Team Lead at a construction company with 5,001-10,000 employees
Real User
Jun 25, 2023
Establishes trust for every access request, no matter where it comes from
Pros and Cons
  • "It's easy to deploy. It's easy to manage. It's easy to integrate with other applications."
  • "The new smart license model doesn't always work. It's very complicated."

What is our primary use case?

We use it for multi-factor authentication. That's the only use case we have now. We're not using it to its maximum capabilities but we'll use it for more functions moving forward.

How has it helped my organization?

Duo Security has improved our cybersecurity resilience. Multi-factor authentication gives us another layer of protection. Having another layer of security is very important for us.

Duo Security establishes trust for every access request, no matter where it comes from. This is something that's absolutely needed.

What is most valuable?

It's easy to deploy. It's easy to manage. It's easy to integrate with other applications. 

We also use it for single sign-on with Meraki and VPN access for non-Cisco firewalls, but we're now migrating to Cisco firewalls. It's easy to deploy, and it works.

What needs improvement?

I'm not using it as much as I could. So far, it has everything I need. I don't have any requirements or improvements. Everything is working smoothly, and we're happy with it.

For how long have I used the solution?

We have been using Duo Security for about two years.

What do I think about the stability of the solution?

Its stability is great.

What do I think about the scalability of the solution?

We have 1,500 users that use Duo Security. We're planning to use Duo Security for more applications, but the number of users won't increase anymore, so in terms of scalability, I don't think we'll have any issues.

How are customer service and support?

We have opened some cases with Cisco for questions and things at all, and they were very helpful. They're very good. They answer questions quickly, and the people who work there are knowledgeable, so I can't complain. I'd rate them a ten out of ten because I got prompt responses and knowledgeable people.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using Microsoft Authenticator before, but we had a lot of problems with that, so we had to move away from that. Initially, we didn't have any multi-factor authentication, so having a multi-factor authentication for multiple applications and services that we provide helps us in making our network more secure.

How was the initial setup?

You synchronize your AD with Duo Security and create all the groups for access.  You send the emails to do the deployment, and you load the cell phone numbers. That's for the end-user side, and for the firewall, we have the proxies. We're using a proxy for one of the products. Our firewall sends RADIUS requests to the proxy, and the proxy communicates to Duo Cloud. The virtual machine deployment for the process was very easy. The configuration takes a few steps, but it's easy.

We've both on-premise and cloud deployments. We're using the tool on the cloud, but we don't have any infrastructure on the cloud.

What about the implementation team?

We did the deployment ourselves.

What was our ROI?

We have seen an ROI. The cost of not having it means you're vulnerable to hacking and other things. Nowadays, multi-factor authentication is required for insurance. It's a must now.

What's my experience with pricing, setup cost, and licensing?

It's very simple. Its price is fair. We use the hardware tokens as well. You get what you pay for.

In terms of licensing, Cisco has very complicated products, but Duo Security was surprisingly easy. The licensing model is easy. The license is based on the intent. You can see how many licenses you have. It's one of the easiest solutions I have deployed, so I'm very happy about it. Every other Cisco product—such as switches, APs, wireless, and controllers—has a very complicated license model. The new smart license model doesn't always work. It's very complicated. The vendors will put your license somewhere else. You need to talk to vendors. It's complicated, but Duo Security licensing is simple.

Which other solutions did I evaluate?

We evaluated RSA, Microsoft, and Duo Security. We evaluated these three, and we realized that Duo Security had better reviews, and it was easier to deploy and cost-effective, so it made sense to use it.

What other advice do I have?

Overall, I'd rate Duo Security a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kevin OShields - PeerSpot reviewer
Network Administrator at a energy/utilities company with 5,001-10,000 employees
Real User
Jun 22, 2023
A multi-factor authentication offering a good dashboard while being reasonably priced
Pros and Cons
  • "The administrator tool in the dashboard is the most valuable feature. It's really easy to quickly see if users are locked out from their device, firmware code, or just all the little dashboards and reports I can run to give the security for monthly reports. The dashboard's really good."
  • "The pain point for us at one point was the Duo Authentication Proxy since we're on-premises and not in the cloud. We had to have a proxy machine that's in our DMZ to talk to Duo for us. The configuration of that was a little complicated."

What is our primary use case?

Our general use cases are for multi-factor authentication for our networking and data center environment devices. We also do some SAML for our network monitoring tools with our different partners in our environment. With SAML, we use it for RADIUS and TACACS authentication.

How has it helped my organization?

The solution has definitely made our administrative access and privileged access to our data center architecture more secure by using multi-factor authentication. It's no longer just a password. You need to have Duo Push. It also helps the security team keep track of when people log in a lot easier, and you can just go to Duo Security to do that. The multi-factor aspect for us was the big reason why we chose Duo. We are Cisco, and it's integrated with Duo Security.

What is most valuable?

The administrator tool in the dashboard is the most valuable feature. It's really easy to quickly see if users are locked out from their device, firmware code, or just all the little dashboards and reports I can run to give the security for monthly reports. The dashboard's really good.

What needs improvement?

The pain point for us at one point was the Duo Authentication Proxy since we're on-premises and not in the cloud. We had to have a proxy machine that's in our DMZ to talk to Duo for us. The configuration of that was a little complicated.

For how long have I used the solution?

I have been using Duo Security in my organization's environment for eighteen months.

What do I think about the stability of the solution?

I never faced any stability issues.

What do I think about the scalability of the solution?

I never faced any scalability issues.

How are customer service and support?

The solution's technical support has been great. The only times I've ever had to call them was when I had to deal with Duo Authentication Proxy, and they were very helpful. They would go through your config and help you figure out any little pain points you're dealing with as far as integrating those different protocols, but they were fine every time I had a call. I rate the support a nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

Regarding implementation, it was a really quick project. I think we did PoC to the final rollout in six weeks. Duo Security is very integrated with other security and Cisco products, it took us around six weeks, and we had the solution up and running along with multi-factor authentication for all privileged access users in our environment. Previously, we just had a username and password. It was a big win for us.

What's my experience with pricing, setup cost, and licensing?

Price-wise, the solution has been very, very reasonable, especially since I like that you can scale, and they work really well if you need to expand quickly or retract. We haven't had any problems. Licensing is the last thing I think about regarding Duo Security because it's so easy, and I had no problems with it.

Which other solutions did I evaluate?

During our evaluation phase, we looked at Okta. For privileged access and for our authentication protocols like RADIUS and TACACS, Okta didn't have that functionality. They did SAML, so you could secure web apps or SaaS platforms or anything like that, but not our internal data center networking infrastructure. Duo Security was the only one that really had that capability. It was a really quick process. It's been great ever since.

What other advice do I have?

It is a very powerful tool when it comes to securing infrastructure from end to end. It makes authentications seamless for the users, and it's very well integrated with, like, Cisco ISE. It's not hard to maintain, and that was the biggest bonus. You don't want pain points for your users. Integration and the solution's seamlessness were the two big points.

Regarding my impressions of Duo Security's ability to help reduce risks and breaches, I would say that it is very high. The biggest pushing risk for us is insider threats, so mitigation requiring multi-factor authentication for privileged access reduces that threat surface. Duo Security was a really quick and really easy way to get a really quick win on that.

Duo Security's user authentication and device verification for helping to prevent and identify attacks is pretty good, especially for profiling the devices and for devices that have Duo's app in them. It helps us to understand the users of Duo about which firmware is running and whether they're possibly running firmware that could have some vulnerabilities. It's all in the dashboard. It's very easy to make reports and see them. It really helps people who use Duo, and they have their endpoint in there. It really helps us see a lot about their device.

It helps us save money and time, especially for identify privileged access users who are having problems logging into devices. We get it to automatically alert us, so we can be proactive about finding out what the issue is because if you see a lot of repeated attempts to log in to something, then you see that in Duo, it will email us, and then we can go to just investigate and remediate the issue. It's usually somebody with a bad password, trying to put it in many times, but you never can be sure. So it really helps us be proactive in the aforementioned situations.

Regarding my assessment of Duo Security for establishing trust for every access request, no matter where it comes from, I would say that it does pretty well. So, I don't know if I can talk more about this because we really only have certain avenues into privileged access devices, so I really can't say if it is from anywhere.

It is very important for me that Duo Security considers all resources to be external, especially from a principal security standpoint. It's a great posture to have, and I think that having that kind of posture is good for your security just inside your own network if you treat everything as external. They speak the same language security-wise that we look for in our organization. 

Duo Security has helped improve my company's cybersecurity resilience, considering that in our limited scope of where we use it, we are more resilient because of those formation things where we learn about issues proactively, and then we can actually mitigate them, and the report shows trends. So if we see trends, we can see what we mitigated, and we can look at those trends and see if there's a more focused approach than maybe a more long-term thing we need to look at or a bigger change we need to look at. I would say it's helpful from that point.

I would tell those planning to use the solution that Duo Security is a seamless and really transparent solution for its users, and it's very integrated into one's existing systems. Ease of implementation is for somebody who has to engineer a solution and implement it. The ease of implementation is one of the top five things. It's the ease of implementation and it's the integration in your existing systems that really sells Due Security for me. 

I rate the overall product a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Paul Mhiripiri - PeerSpot reviewer
Networks And Infrastructure Manager at a financial services firm with 11-50 employees
Real User
Top 20
Aug 24, 2022
Easy to integrate, good VPN capabilities, and technical support is quick to assist with problems
Pros and Cons
  • "The most valuable feature is the ability for users to connect securely to the office using the VPN."
  • "With respect to our users feeling safe, secure, supported, and included, Duo Security is among the best solutions that we have ever used."
  • "We have had instances where Duo Security stops working on a user's device, which we have fixed by uninstalling and then reinstalling it."

What is our primary use case?

We began using Duo Security just after the pandemic began. We set up the VPN for our users so that they could connect from home and use the business applications. It is a security feature that is used on your mobile device, rather than something that is fixed in the office. You can use it at any given moment, as long as you have your mobile device with you.

Prior to implementing it, they were using just a username and password. That was not secure enough, so there had to be the second level of authentication. As it is now, it is integrated with the firewall. You put in your password and it is followed by a six-digit code that needs to be entered.

We operate in the financial sector so this product is crucial for our business.

The security codes are not generated locally, or on-premises. Rather, they are generated and sent from the cloud.

It is integrated with our Check Point firewall, which is used across different departments. People can connect from anywhere, including from home, and then utilize the business applications in different departments. All of them authenticate using the same firewall.

Importantly, it's not limited to one vendor or one firewall. You can use it to connect through a primary DC and a secondary DC, even if they are different vendors.

How has it helped my organization?

Using this product has improved our organization, primarily with respect to security. Even the system administrator, in charge of setting up the users, would not be able to use another person's ID to connect. This is because they would then need to use Duo Security, which resides on the user's device. This is something that other people cannot do because they can't generate the six-digit codes.

In terms of securing access to the applications on our network, this solution is very reliable.

With respect to our users feeling safe, secure, supported, and included, Duo Security is among the best solutions that we have ever used. We have not fully utilized all of the features. However, we're looking at using Duo to authenticate internet banking solutions. Providing a second level of authentication in these situations, perhaps in mobile banking, would be valuable.

Our regulatory requirements necessitate creating a very secure connection for financial services, which is what we get from this product.

Having a single solution for multifactor authentication makes it comfortable for the users. They only need to train on one product.

Maintaining network connectivity is not difficult. We are integrated with Fortinet and Check Point solutions. The Check Point solution is in a different data center than Fortinet, and Duo Security integrates with both of them, despite being from different vendors.

Overall, this product has helped us to remediate threats more quickly. There is no way that others can generate the security code, such as by using another server. They will not be able to connect or authenticate themselves another way.

The resilience that Duo Security provides is valuable in terms of meeting our audit requirements. This is important to us because it helps us to meet our regulatory requirements, which are set by the central bank and enforced by our cybersecurity team.

What is most valuable?

The most valuable feature is the ability for users to connect securely to the office using the VPN. There's no way to breach security using Duo. No user can connect from a different device, which guarantees access on a per-user basis. The only way somebody else can connect is if the user shares their VPN password, as well as the six-digit code. This is a well-accepted, business solution.

It is very easy to set up, configure, and integrate this product. It is also easy, from the user's side of things.

The interface is such that all of the management can be done from a single pane of glass. You can integrate as many applications as you want, and it's up to the enterprise that dictates that. Overall, it's easy to manage and administer. There are not too many moving pieces, which would make things more difficult to administer and troubleshoot when there are problems.

From our employees' perspective, they are confident that they are the only people that can connect to their accounts. Access to their own accounts remains under their control, and they are the only ones that can connect. 

What needs improvement?

The reporting feature is somewhat limited. All that you get is the list of times that the user connected. Given that it's only a secondary authentication, it may not be possible to enhance the reporting.

We have had instances where Duo Security stops working on a user's device, which we have fixed by uninstalling and then reinstalling it.

For how long have I used the solution?

I am in my third year of using Duo Security.

What do I think about the stability of the solution?

Due Security is a very stable product. We have never had issues in that regard.

What do I think about the scalability of the solution?

This is a very scalable solution. It's not limited to specific applications and we can use it across multiple ones.

We have 175 end-users.

How are customer service and support?

If we need to reach out to them, they would quickly assist us. At any given time, you can get support from Duo Security. This is not a free product and the technical support team is very reliable.

I would rate the technical support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to implementing Duo Security, our users were not using multifactor authentication. They were simply authenticating with a username and password. That was not secure enough, which is why we implemented the second level of authentication.

How was the initial setup?

The initial setup is easy and straightforward. It is very quick to integrate and manage. As it is very easy to integrate, it works well to secure our infrastructure from end to end, helping us to detect and remediate threats.

You just download the application and within a minute or so, you have an admin panel. After that, it is integrated with the firewall and the users can then quickly connect.

The integration is easy because Duo gives you a list of steps that vary based on the application and vendor that you want to integrate with. For example, if you want to integrate with a Check Point product then you have one set of instructions, whereas if you want to integrate with a Fortinet product, there is an alternate set for that.

In total, the deployment took less than two hours to complete.

What was our ROI?

Our ROI is mainly from the security side. Because of the regulator's requirement, it's worth the procurement. That said, on our end, we're not fully utilizing the product because you can integrate it with different applications. At this point, we are just using the basic feature, which is to connect to the VPN.

The administration is comfortable knowing that no user can connect to the system without using Duo authentication.

What's my experience with pricing, setup cost, and licensing?

From a business perspective, it is a little bit costly. The licensing is on a per-user basis. However, it's worth the cost.

We began with a free trial of the product that lasted for one month. After that, we paid for the license to use it.

Which other solutions did I evaluate?

We had an option to use Google Authenticator. It is also a secure solution but we chose Duo Security because it was recommended to us, and it has been acquired by Cisco.

What other advice do I have?

We do not utilize all of the features that are offered by Duo Security.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Patryk Rurek - PeerSpot reviewer
Dynatrace Architect at a hospitality company with 10,001+ employees
Real User
Aug 15, 2022
A robust solution with impeccable stability and good functionality, it fits well in a layered defense strategy
Pros and Cons
  • "The app has greater stability than rival solutions such as Google Authenticator, and Duo Push authentication is a valuable feature."
  • "Duo Security simplified establishing trusted connections, making it easier to implement distributed network solutions."
  • "I would like to see some features simplified, such as securing, configuring, and implementing Microsoft Remote Desktop. Other than that, the solution was rock solid throughout my time administering it."

What is our primary use case?

Our primary use case is for two-factor authentication. We also use the solution to secure Microsoft Remote Desktop, VPN, and SSH connections.

We deployed the product primarily to address security concerns, for example, implementing a more secure security posture using Duo Security.

My initial deployment of the product at a previous employer was across multiple environments and business units. We were primarily an active directory shop using Windows servers and desktops and Wise desktops, all of which utilized Duo Security as their two-factor solution.

In my current environment, the tool is implemented in different forms, on-premise and in the cloud. We deploy it everywhere.

How has it helped my organization?

Duo Security has been utilized in multiple organizations I've worked for, and it simplifies connecting securely via VPN, Microsoft Remote Desktop, and SSH.

What is most valuable?

The app has greater stability than rival solutions such as Google Authenticator, and Duo Push authentication is a valuable feature. 

The product worked to establish trust for as long as I've used it. It's a more functional solution than some competitors, which I discovered during the POC process. I think that Duo Security considering all resources to be external is one of the reasons why they are at the top of their field. 

Duo Security simplified establishing trusted connections, making it easier to implement distributed network solutions. I've always found it to be a good part of a layered defense strategy. 

Most of the end users when I was responsible for implementation, didn't quite understand the value of the solution until it was demonstrated. 

The tool does provide single-pane-of-glass management in my experience. I haven't implemented the solution for years, but I'm a user in my personal and professional life. Therefore, I can say that feature is essential in making Duo Security one of the critical steps in a defense-in-depth strategy. 

I never had any problems maintaining network connectivity, and it always performs well.  

Based on the logging I have seen Duo Security use, I would say their solution does help with threat remediation. It is an integral part of the defense strategy. 

A robust two-factor authentication solution is a massive part of a proper defense strategy, and having Duo makes it easier to implement and manage that two-factor solution. 

What needs improvement?

I would like to see some features simplified, such as securing, configuring, and implementing Microsoft Remote Desktop. Other than that, the solution was rock solid throughout my time administering it. 

For how long have I used the solution?

I have been using the solution for six years.

What do I think about the stability of the solution?

The solution is very stable, I've never seen it go down.

What do I think about the scalability of the solution?

The product is incredibly scalable.

How are customer service and support?

I had to contact technical support on a few occasions, and my problem was always resolved, but it took some time and work to reach a workable solution. My experience with them is primarily positive, but there is room for improvement.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

At the job in which I carried out the POC for the solution, we used physical RSA tokens, and I have been at locations that use HID tokens. In my opinion, the soft token solution is far better; it's more user-friendly, and staff can utilize the strategy more efficiently, effectively, and, unfortunately for RSA, more securely than the physical tokens offer.

How was the initial setup?

The basic deployment is very straightforward, though some Microsoft Remote Desktop support elements were a little more complicated. Primarily in getting the correct values and additional resources required for the deployment.

I wasn't involved in the deployment at my current company. At my previous employer, I did the POC and the initial training for our help desk groups.

What about the implementation team?

I carried out the implementation myself; I was responsible for maintaining all of the integration points and training the help desk team members to support the product.

What was our ROI?

It's hard to precisely measure an ROI for security solutions, but I would say it provides a return.

What's my experience with pricing, setup cost, and licensing?

I haven't seen any information on the pricing in four years, so I can't comment on that. 

Which other solutions did I evaluate?

We tested a SecureAuth solution that didn't meet our security standards. We wanted to try RSA Authentication Manager, but that was more complex for users, so we decided to go with Duo Security.

What other advice do I have?

I would rate this solution an eight out of ten.

When I carried out the POC for Duo Security at my former employer, I pitched it to them because it simplifies the login process and has excellent notifications. Physical tokens can be hard to read, especially for admins and staff trying to remediate problems late at night. We wanted a solution that was easy to set up and configure, and that is what we got; being a cloud-based solution, Duo Security is much easier to manage. We don't need to worry about managing, upgrading, and configuring much on our side; that's all handled in the cloud.   

The first company I mentioned working for was based in Ann Arbor, and Duo Security is or was based there too. I had personal relationships with several team members and recognized their product's value.

The solution improved trust models within our organization, significantly changing how people view connecting to the network. I don't think that it has had an impact on employee morale.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Duo Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Cisco Duo Report and get advice and tips from experienced pros sharing their opinions.