Automatically enabled when you configure Duo permissions in your agent workflow.
What It Does
- Find a user by username or email, and read their status, lockout reason, phones, tokens, groups and last sign-in
- Send a verification Duo Push to the user’s phone and read whether they approved it
- Set a locked-out user active again, or set a user to bypass or disabled
- Create and enroll a new starter, add a phone, and have Duo send the Duo Mobile activation SMS or the enrollment email
- Disable or remove a leaver, and remove their phones, tokens, security keys and bypass codes
- Read the authentication, administrator and telephony logs, and which policy applies to a user and an application
- Manage groups, blocked devices, policies, applications, administrators and account settings when you allow it
Client subaccounts
With a Duo MSP account, the agent works in a client’s subaccount by passing its account id (account_id) on the call. Neo looks up that subaccount’s own API hostname and sends the call there. Without an account id, the call goes to your own account. Each subaccount is mapped to a client in your PSA, so the agent knows which account id belongs to the ticket’s client: see Duo overview.
On a ticket, Neo checks the account id against that mapping before it sends the call. Neo knows your subaccounts from the subaccount list, so this check needs Grant accounts - Read on the Duo application. With it, the agent can reach only the subaccount mapped to the ticket’s client; Neo refuses any other account id. When the ticket’s client has a subaccount, Neo also refuses a call without an account id, because that call would reach your own account. When the ticket’s client has no mapped subaccount, the agent can reach no subaccount on that ticket, and on a Duo MSP account it cannot reach your own account either, because your own users are your staff: map the client on the Duo card’s Organization Mapping tab. Without Grant accounts - Read, Neo may not know your subaccounts, and a ticket call without an account id can then reach your own account. Listing or creating subaccounts is refused on a ticket, because the list names every client. A mapping counts once it is a name match or one you confirmed. Runs with no ticket, such as a chat or a scheduled agent with no ticket, are not limited to one client.
Permission Groups
Each group is Disabled, Read Only or Read / Write. Logs and Reports is Disabled or Read Only, because Duo has no write there.
Access Profiles
Under every profile, a technician approves setting a user or group to bypass, adding a user to a group, creating bypass codes, deleting a phone, hardware token, security key or desktop authenticator, detaching a phone or token from a user, every policy, account setting and administrator change, creating or deleting an application, resetting its secret key or granting it Admin API permissions, and changing a subaccount’s edition, telephony credits or user limit.
Safety Controls
How to Configure
1
Connect Duo
Save your Admin API application’s integration key, secret key and API hostname in the Neo Dashboard under the Security integrations category. See Connecting Duo to Neo.
2
Configure permissions
In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
