What is our primary use case?
We mostly use it for multi-factor authentication with email platforms like Office 365 as well as other apps.
How has it helped my organization?
We were looking to deal with email phishing attacks and brute force attacks, and the like, and Duo has helped a lot. We're more secure with multi-factor and have seen the number of phishing attacks and brute force attacks go down.
Logging in with Duo is baked into anything that we log into, including any applications, email, and web apps. We integrate it with a product called Jump Cloud, which is our cloud-based identity management system. We have also integrated it into WebEx and Box. Duo runs all of our security and MFA, and it's worked out well.
It's helped a lot of our customers with multi-factor in their identity management systems, on-prem and in the cloud. That way, when users log in, they get the MFAs to be able to log in to any resource on the network.
And because everybody is working remotely now, Duo checks all the boxes for hybrid work.
When it comes to remediating threats, it has helped us do so quickly. We don't even see a lot of the threats anymore because it's working behind the scenes. It has definitely decreased the number of threats in the last year compared to what we used to see.
What is most valuable?
The ease of use and the ease of management of all the users have been key for us. The setting up of devices in Duo has been really easy as well. It's better than all the other ones I've worked with.
Another important feature is that Duo considers all resources to be external because even the internal ones look like external ones, and people click on stuff and get caught. It's very important to be more cautious than ever.
Also, the single pane of glass management works very well. That feature is very important because we have a lot of admins who have to manage Duo, and it's much easier when it's a single pane of glass. That single pane is also great because it's easy to enroll new devices.
What needs improvement?
One area that might be improved is that setting up SMS texting is not as easy as using the app, even though it does support it.
Also, a faster management user interface would help. It tends to lag a little bit.
For how long have I used the solution?
I've been using Duo Security for three or four years.
What do I think about the stability of the solution?
It has been stable. We haven't really had many issues with it. It maintains network connectivity across all workplaces and works great. I don't have any complaints.
What do I think about the scalability of the solution?
It can scale to as many employees as you have. It can go from five employees to 1,000 employees. I don't see any issues with the scalability.
How are customer service and support?
Their technical support is great.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
The initial deployment was pretty straightforward. We had a small number of challenges, but nothing we couldn't get by. It was pretty smooth, overall. Setting it up and enrolling new devices into the environment was a breeze. That was the easiest thing.
What about the implementation team?
What was our ROI?
We see ROI in that users feel more secure and their morale goes up. You get to keep those employees a lot longer if they feel better working for an organization that's investing in security. A big benefit is keeping your employees.
Everybody loves it. They feel a sense of security when they get that prompt to send them a text, or an email. It makes them feel like they're working for a company that is really taking the time to secure the environment. It gives them a good feeling when they get a second form of authorization.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty competitive. It's pretty cheap. Anybody can adopt it. We don't have customers that haven't used it because of the price.
Which other solutions did I evaluate?
We evaluated Microsoft Authenticator and Google Authenticator. With those solutions, you don't have the granularity of management of the MFA environment that Duo offers.
What other advice do I have?
Our Duo is all cloud-based, there's nothing on-prem. We typically integrate it with our cloud apps.
Resilience in cyber security is a game-changer. We have the same challenges that every organization goes through with security: phishing attacks, ransomware attacks, et cetera. I wouldn't say it has eliminated 100 percent of them, but it definitely cuts a lot of that stuff out. Every organization should have something like Duo, or MFA in general. But if they're going to do it, they should do it with Duo just because it's so easy to manage and it is resilient.
For management that wants to build more resilience within their organization, they have to implement multi-factor authentication across that organization for everything. It shouldn't just be for email but everything internally as well.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.