What Neo can do with Duo
- Clear an MFA lockout: find the user, read why Duo locked them out, verify the caller with a Duo Push to their phone, and set the user active again.
- Onboard a new starter: create the Duo user, put them in the right group, add their phone and have Duo send the enrollment email or the Duo Mobile activation SMS.
- Offboard a leaver: disable or remove the Duo user and remove their phones, tokens and bypass codes.
- Explain a denied sign-in from the authentication log, and which policy applies to a user and an application.
- Manage groups, devices, policies, applications and administrators when you allow it.
How Neo verifies a caller
Before Neo or a technician changes a locked-out user, the agent can send a verification Duo Push to a phone on the user’s Duo account and read whether the user approved or denied it. Duo keeps the answer for 120 seconds; a push with no answer by then has timed out. The push shows a confirmation code, and the agent gets the same code, so a technician on the phone can ask the caller to read it back. Verifying a caller needs a phone that is activated for Duo Push. A user who has lost their phone cannot approve a push, so verify them another way before you approve a change.Your subaccounts are mapped to clients
Neo matches each Duo client subaccount to a client in your PSA and keeps the mapping on the Duo card’s Organization Mapping tab, refreshed on each PSA metadata sync. With the mapping, an agent works in the right client’s subaccount for each ticket. When the Admin API application lacks Grant accounts - Read under Subaccount permissions, or your Duo account has no subaccounts, Neo cannot read a subaccount list and maps nothing new. Mappings from an earlier sync stay on the tab as they were. Matching starts with the name: exact, then after stripping a legal-form suffix (Ltd, Inc, LLC). Last comes an AI match for the long tail. A name match, or one you confirm, is handed straight to your agents. An AI match is not handed to your agents automatically. It shows on the Organization Mapping tab, where you can confirm or correct it. Anything Neo could not match stays unmapped and visible on the same tab, where you can set the right client by hand. A mapping you set by hand survives every later sync.Next steps
Connect Duo
Create an Admin API application in the Duo Admin Panel and save its keys in Neo.
