1. Create an Admin API application for Neo
1
Add the application
Log in to the Duo Admin Panel and open Applications > Application Catalog. Find Admin API and click + Add.With a Duo MSP account, do this in your own (parent) account. One application there reaches every client subaccount, so you do not create one in each subaccount.
2
Copy the keys and the hostname
On the application’s page, copy the Integration key, the Secret key and the API hostname (for example
api-1a2b3c4d.duosecurity.com). Treat the secret key like a password.3
Tick the permissions
Tick the permissions for what you want Neo to do. The first three cover the lockout and onboarding work:
Tick Grant set Admin API permissions only if you want Neo to grant Admin API permissions to another Duo application. Neo asks a technician before every such grant. Leave it unticked otherwise.
4
As an MSP, tick the subaccount permissions
Under Subaccount permissions, tick Grant accounts - Read, so Neo can list your client subaccounts, and the same permissions you ticked above. Without them, Neo sees only your own account and none of your clients.Tick Grant accounts - Write only if you want Neo to create subaccounts and set a subaccount’s edition and telephony credits, and Grant user limits - Read and - Write for a subaccount’s user limit.
5
Optionally restrict the networks
Networks for API Access limits where the application can be used from. Leave it empty to allow any network, or add Neo’s IP addresses. If you restrict it and leave out one of Neo’s addresses, Duo refuses some of Neo’s requests.
6
Save the application
Scroll to the bottom of the page and click Save.
2. Add the keys in Neo
1
Open Integrations
In the Neo Dashboard, open Integrations → Duo, under Security.
2
Save the keys and the hostname
Paste the API hostname, the integration key and the secret key, and click Save settings. Neo signs a request to Duo with them before saving, so a mistyped key or hostname is rejected straight away. The check reads one user, so it also rejects keys of another application type and an Admin API application without Grant resource - Read. Any other missing permission is not caught here: Duo refuses that call later, when an agent makes it.
3. Turn Duo on per agent
1
Open the agent
In the Neo Dashboard, open the agent and its Integrations tab.
2
Choose an access profile
Under Duo, choose a profile, or set each permission group by hand.
3
Tell the agent what to do
Add a line to the agent’s instructions, for example: “When a user is locked out of Duo, verify the caller with a Duo Push, then set the user active again and note what you did on the ticket.”
Under every profile, a technician approves setting a user or group to bypass, adding a user to a group, creating bypass codes, deleting a phone, hardware token, security key or desktop authenticator, detaching a phone or token from a user, every policy, account setting and administrator change, creating or deleting an application, resetting its secret key or granting it Admin API permissions, and changing a subaccount’s edition, telephony credits or user limit. The Duo API page lists the permission groups and what Neo never sends.
