Skip to main content
Neo connects to Duo through an Admin API application. Duo includes the Admin API in the Duo Essentials, Advantage and Premier plans, and only a Duo administrator with the Owner role can create the application.

1. Create an Admin API application for Neo

1

Add the application

Log in to the Duo Admin Panel and open Applications > Application Catalog. Find Admin API and click + Add.With a Duo MSP account, do this in your own (parent) account. One application there reaches every client subaccount, so you do not create one in each subaccount.
2

Copy the keys and the hostname

On the application’s page, copy the Integration key, the Secret key and the API hostname (for example api-1a2b3c4d.duosecurity.com). Treat the secret key like a password.
3

Tick the permissions

Tick the permissions for what you want Neo to do. The first three cover the lockout and onboarding work:Tick Grant set Admin API permissions only if you want Neo to grant Admin API permissions to another Duo application. Neo asks a technician before every such grant. Leave it unticked otherwise.
4

As an MSP, tick the subaccount permissions

Under Subaccount permissions, tick Grant accounts - Read, so Neo can list your client subaccounts, and the same permissions you ticked above. Without them, Neo sees only your own account and none of your clients.Tick Grant accounts - Write only if you want Neo to create subaccounts and set a subaccount’s edition and telephony credits, and Grant user limits - Read and - Write for a subaccount’s user limit.
5

Optionally restrict the networks

Networks for API Access limits where the application can be used from. Leave it empty to allow any network, or add Neo’s IP addresses. If you restrict it and leave out one of Neo’s addresses, Duo refuses some of Neo’s requests.
6

Save the application

Scroll to the bottom of the page and click Save.

2. Add the keys in Neo

1

Open Integrations

In the Neo Dashboard, open Integrations → Duo, under Security.
2

Save the keys and the hostname

Paste the API hostname, the integration key and the secret key, and click Save settings. Neo signs a request to Duo with them before saving, so a mistyped key or hostname is rejected straight away. The check reads one user, so it also rejects keys of another application type and an Admin API application without Grant resource - Read. Any other missing permission is not caught here: Duo refuses that call later, when an agent makes it.

3. Turn Duo on per agent

1

Open the agent

In the Neo Dashboard, open the agent and its Integrations tab.
2

Choose an access profile

Under Duo, choose a profile, or set each permission group by hand.
3

Tell the agent what to do

Add a line to the agent’s instructions, for example: “When a user is locked out of Duo, verify the caller with a Duo Push, then set the user active again and note what you did on the ticket.”
Under every profile, a technician approves setting a user or group to bypass, adding a user to a group, creating bypass codes, deleting a phone, hardware token, security key or desktop authenticator, detaching a phone or token from a user, every policy, account setting and administrator change, creating or deleting an application, resetting its secret key or granting it Admin API permissions, and changing a subaccount’s edition, telephony credits or user limit. The Duo API page lists the permission groups and what Neo never sends.

Client subaccounts

Neo finds each client’s subaccount by its account id and sends the call to that subaccount’s own API hostname. Each subaccount is mapped to a client in your PSA on the Duo card’s Organization Mapping tab; see Duo overview. With Grant accounts - Read ticked, an agent on a ticket reaches only the subaccount mapped to the ticket’s client, and never your own account when the client has no mapped subaccount, so map every client you want agents to work on. Without it, Neo may not know your subaccounts, and a ticket call without an account id can then reach your own account.