> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Duo API

> Work Duo MFA tickets: find the user, verify the caller with a Duo Push, clear a lockout, enroll a new starter, offboard a leaver, and read the authentication log

The Duo API tool gives Neo agents access to the Duo Admin API, in your own Duo account or in a client's subaccount. The common use is a ticket from a user locked out of Duo: the agent finds the user, reads why they are locked out, verifies the caller with a Duo Push, and sets the user active again.

<Info>
  Automatically enabled when you configure Duo permissions in your agent workflow.
</Info>

## What It Does

* Find a user by username or email, and read their status, lockout reason, phones, tokens, groups and last sign-in
* Send a verification Duo Push to the user's phone and read whether they approved it
* Set a locked-out user active again, or set a user to bypass or disabled
* Create and enroll a new starter, add a phone, and have Duo send the Duo Mobile activation SMS or the enrollment email
* Disable or remove a leaver, and remove their phones, tokens, security keys and bypass codes
* Read the authentication, administrator and telephony logs, and which policy applies to a user and an application
* Manage groups, blocked devices, policies, applications, administrators and account settings when you allow it

## Client subaccounts

With a Duo MSP account, the agent works in a client's subaccount by passing its account id (`account_id`) on the call. Neo looks up that subaccount's own API hostname and sends the call there. Without an account id, the call goes to your own account. Each subaccount is mapped to a client in your PSA, so the agent knows which account id belongs to the ticket's client: see [Duo overview](/integrations/duo/overview#your-subaccounts-are-mapped-to-clients).

On a ticket, Neo checks the account id against that mapping before it sends the call. Neo knows your subaccounts from the subaccount list, so this check needs **Grant accounts - Read** on the Duo application. With it, the agent can reach only the subaccount mapped to the ticket's client; Neo refuses any other account id. When the ticket's client has a subaccount, Neo also refuses a call without an account id, because that call would reach your own account. When the ticket's client has no mapped subaccount, the agent can reach no subaccount on that ticket, and on a Duo MSP account it cannot reach your own account either, because your own users are your staff: map the client on the Duo card's **Organization Mapping** tab. Without **Grant accounts - Read**, Neo may not know your subaccounts, and a ticket call without an account id can then reach your own account. Listing or creating subaccounts is refused on a ticket, because the list names every client. A mapping counts once it is a name match or one you confirmed. Runs with no ticket, such as a chat or a scheduled agent with no ticket, are not limited to one client.

## Permission Groups

| Group | Covers |
| - | - |
| Users | Find, create, enroll, change status (active, bypass, disabled; read a lockout and clear it by setting active), send to Trash and restore, delete, and group membership |
| Caller Verification | The verification Duo Push and its answer, and Duo identity verification |
| Phones and Authenticators | Phones, hardware tokens, security keys and Duo Desktop authenticators: add, attach to a user, re-send the Duo Mobile activation by SMS, resync, remove |
| Bypass Codes | List bypass codes, create new codes for a user, delete. Duo never returns an existing code |
| Groups | Create, rename, change status, delete, and list members |
| Endpoints and Devices | Endpoints Duo has seen and Duo Desktop registered devices: read, remove, block and unblock |
| Policies | The global policy and custom policies, which policy applies to a user and application, create, copy, change, delete |
| Applications | The applications Duo protects: read, create, change, delete |
| Administrators | Duo administrators, roles and administrative units: read, create, change, reset a lockout, delete |
| Account Settings | Global account settings, branding, custom messaging and Duo Passport |
| Logs and Reports | Authentication, activity, administrator, telephony and offline enrollment logs, Trust Monitor events, and account summary and usage. Read only |
| Subaccounts and Billing | List and create client subaccounts, and read or set a subaccount's edition, telephony credits and user limit |

Each group is Disabled, Read Only or Read / Write. Logs and Reports is Disabled or Read Only, because Duo has no write there.

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read, and the verification Duo Push | Changes to users, phones, bypass codes and groups. Every other area is read only |
| **IT Admin** | Changes to users, phones and groups, and the verification Duo Push | Changes to bypass codes, devices, applications and subaccounts, plus the changes that always ask |
| **Full Automation** | Every change except the ones below that always ask | The changes that always ask |

Under every profile, a technician approves setting a user or group to bypass, adding a user to a group, creating bypass codes, deleting a phone, hardware token, security key or desktop authenticator, detaching a phone or token from a user, every policy, account setting and administrator change, creating or deleting an application, resetting its secret key or granting it Admin API permissions, and changing a subaccount's edition, telephony credits or user limit.

## Safety Controls

| Control | Behavior |
| - | - |
| **Bypass codes and the bypass status** | Creating bypass codes always asks a technician, under every profile, because a code passes MFA as the user. So does a user or group change that sets the status to bypass, which turns off MFA, the bulk user create included. A change Neo cannot read counts as one that sets bypass. Adding a user to a group always asks too, because the call names only the group, and a group set to bypass turns off the user's MFA |
| **Authenticators** | Deleting a phone, a hardware token, a security key or a desktop authenticator, or detaching a phone or token from a user, always asks a technician, because the user loses that second factor |
| **Policies and account settings** | Every policy change and every account setting change always asks a technician, because a policy can turn off MFA for the users it covers, and a setting can widen who may let users skip MFA |
| **Administrators** | Every change to an administrator, a role, an administrative unit or an activation link always asks a technician |
| **Applications** | Creating or deleting a Duo-protected application, resetting its secret key, or granting an application an Admin API permission always asks a technician, because that permission widens what the application's key may do in your Duo account |
| **Billing** | Changing a subaccount's edition, telephony credits or user limit always asks a technician, because it costs you money |
| **Client scope** | On a ticket, a call reaches only the subaccount mapped to the ticket's client, when the Duo application has **Grant accounts - Read**. See [Client subaccounts](#client-subaccounts) |
| **Neo's own application** | Neo does not change, delete or reset the secret key of the Admin API application it is connected with, because that would break its connection to Duo |
| **Secrets in answers** | Neo removes an application's secret key and an OAuth or OIDC client secret from every answer, the answer to creating an application included, so the agent and the run log never see them |
| **Activation links and enrollment codes** | Neo removes a pending administrator's activation link and the enrollment code of a new user from what the agent reads. Duo emails them to the person instead |
| **Refused** | Neo does not delete a subaccount, send Duo's bulk call, read an application's secret key or an OAuth or OIDC client secret, create a phone's Duo Mobile activation link or an administrator's activation link, or download the account logo. The agent has Duo send the activation SMS or email instead |

## How to Configure

<Steps>
  <Step title="Connect Duo">
    Save your Admin API application's integration key, secret key and API hostname in the Neo Dashboard under the **Security** integrations category. See [Connecting Duo to Neo](/integrations/duo/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or set each permission group by hand.
  </Step>
</Steps>

<Tip>
  For lockout tickets, **Helpdesk** fits: the agent verifies the caller on its own, and a technician approves the change to the user.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.