Duo: who is protected by multi-factor, and who is not
Duo is the multi-factor layer in front of your partners' logins. This connector reads three things out of it: who is actually protected, who is not, and what is happening at the sign-in prompt. The number an owner cares about is not how many licences they bought; it is how many of their people can still sign in with a password alone. That number is usually a handful, it is usually a surprise, and it is the reason this connector exists. Everything hangs off the matching Current company, so it feeds your business reviews and the company alert band. Current reads Duo and can never change anything in it.
What Current syncs
| Data set | What Current stores | Where it lands |
|---|---|---|
| Accounts | Each Duo account this credential reaches — your subaccounts if you manage them, or the single account if you do not — by identifier and name, with Duo's own user, administrator and application counts | The mapping panel on the Duo card, and the People section of a company record |
| People | Per person: Duo username, display name, email, account status, whether they are enrolled, when they last signed in, and how many phones, hardware tokens and security keys they carry | The People section, the at-risk list on the company card, and the MFA dashboard metrics |
| Authenticator devices | Per enrolled phone or tablet: platform, model, operating system and app version, when Duo last saw it, and the screen lock, encryption and tamper state Duo reports | The device hygiene numbers on the company card, each shown with its own denominator |
| Sign-in activity | Per account per day: how many authentications were granted, how many were denied, how many were reported as fraud, and a small count of the reasons Duo gave for denials | The denied-sign-ins trend on the company card and in a business review |
Create the Admin API application in Duo
- 11 · Sign in to the Duo Admin Panel as an ownerOnly an administrator with the Owner role can create an Admin API application. If you do not have that role, this is the point to ask whoever does — no other step below will work without it. The Admin API itself is available on the Essentials, Advantage and Premier plans and on Advantage and Premier trials; a free Duo account has no Admin API at all.
- 22 · Add the Admin API applicationGo to Applications, then Application Catalog, find Admin API, and add it. Duo creates the application and shows its page.
- 33 · Tick three permissions, and leave every write permission offOn that application's page, tick Grant read information, Grant resource - Read, and Grant read log. Those three cover the account summary, the people and their devices, and the sign-in activity. If you manage partners as Duo subaccounts, tick the subaccount read permission in the subaccount section as well, or the credential cannot see your partners. Leave every other box unticked, including all four write permissions and Grant set Admin API permissions. That way the credential itself has no way to change anything in Duo, which is a stronger guarantee than any promise Current can make about its own code.
- 44 · Copy the three valuesThe application page shows an integration key, a secret key, and an API hostname. The hostname looks like api-XXXXXXXX.duosecurity.com. Copy it exactly as Duo shows it, including for a data-residency account where it may look different — Current takes it as given and never rewrites it.
- 55 · Paste all three into Current and testIntegrations → Duo → Connect. Paste the API hostname, the integration key and the secret key, then press Test connection. Current makes one read against Duo to confirm the credentials work and can see your directory, then stores them server-side only; they are never shown again and never reach your browser. The secret key never travels to Duo at all — Current uses it to sign each request rather than sending it.
Map Duo accounts to your companies
If you manage partners as Duo subaccounts, each subaccount is one end-customer and Current lists all of them. If your credential covers a single Duo account, Current writes exactly one entry so the mapping panel works the same way. Either way, Current links each account to a Current company by normalized name — lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped — and only when exactly one company matches. Two companies that both fit stay unmapped for you to decide.
- 1Let the auto-matcher run firstEvery sync links each Duo account to the one Current company whose normalized name matches. Most map themselves; only the ambiguous ones need a hand.
- 2Open the mapping panelIntegrations → Duo → Manage → Customer mapping. It opens on the Unmapped tab, which lists every Duo account the matcher could not place.
- 3Map an account to its companyOn an unmapped row press Map, type a few letters of the Current company, and pick it. That account's people and devices attach to the company right away, rather than waiting for the next six-hour sync.
- 4Ignore internal or test accountsFor an account that should never map to a partner — your own staff, a lab, a demo — press Ignore. It moves to the Ignored tab and stops counting against the card's unmapped badge.
- 5Fix a wrong match laterThe Mapped tab lists every linked account; Unmap corrects a bad auto-match, and the Ignored tab's Un-ignore brings a dismissed one back. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.
Where the data shows up
- +The People section of a company record: how many people are enrolled out of the total, how many are at risk broken out as in bypass, not enrolled and locked out, and the authenticator mix across push, SMS, hardware tokens and security keys.
- +The at-risk list itself, naming the people when there are few enough to do something about today.
- +Device hygiene: how many enrolled phones have no screen lock or no encryption, each shown as n of m reported, so a device Duo did not report on never counts as a pass.
- +Stale accounts: people who are still enabled and have not signed in for ninety days, which is both a licence being paid for and a way in nobody is watching.
- +The denied sign-ins trend, which is the proof that the control is catching things rather than just sitting there.
- +The Security posture chapter of a Strategic Business Review, beside your other security feeds.
- +The company alert band, which raises an entry when somebody at that company can sign in without a second factor.
When something looks wrong
| What you see | What it means |
|---|---|
| "Duo rejected these credentials" | All three values are signed into every request, so any one of them being wrong reads the same way. Check the integration key, the secret key and the API hostname against the Admin API application page. The most common cause is the hostname: it is the api- address on that page, not the address you sign in at. |
| "Duo accepted these credentials but refused the user list" | A permissions gap, not a wrong key, and regenerating the key will not help. Go back to the Admin API application and confirm Grant read information, Grant resource - Read and Grant read log are ticked. If they are, check the integration key came from an Admin API application rather than an Auth API one — the two look alike, Duo answers the same way for both, and telling them apart by the key alone is not possible. |
| "Couldn't reach Duo" | A network or firewall problem between Current and your Duo API hostname, not a credential problem. Current retries on its own at the next scheduled sync. |
| "Duo is rate-limiting the request" | Duo publishes no read limit for this API, so Current paces itself well under any plausible one and backs off the moment Duo says to. Nothing is wrong with the credentials; wait and press Test again. |
| Connected, but no people listed | The credential authenticates and then reads nothing, which is the fingerprint of an under-permissioned application. Grant resource - Read is the box that covers people and their devices. |
| Connected, but no partners listed | If you manage subaccounts, the credential is missing the subaccount read permission, so Current sees the parent account only. Add it in the subaccount permission section of the Admin API application. If you do not manage subaccounts, one entry is correct — that entry is the whole account. |
| A company shows no Duo data | Its Duo account is not mapped yet. Check the Unmapped tab on the card. |
| Device hygiene shows fewer devices than you expect | The count only includes devices Duo actually reported a value for. The denominator beside it is the number reported, and the gap between that and the fleet is devices Duo said nothing about. |
| Somebody shows as at risk who looks fine in Duo | Look at their status. Bypass is the usual answer, and it is easy to miss in Duo because the account otherwise looks healthy. Disabled and locked out also count, as does anyone who never finished enrolling. |
| The denied sign-ins trend has a gap | Duo's sign-in log reaches back one hundred and eighty days at most and lags a couple of minutes behind live, and Current reads a bounded recent window on each run. A day Current has not covered stays blank rather than showing zero. |
