Cisco Duo Authentication

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID CiscoDuoAuthConnectorDefinition
Publisher Cisco Systems, Inc.
Used in Solutions CiscoDuoSecurity
Collection Method CCF
Connector Definition Files CiscoDuoAuth_ConnectorDefinition.json
DCR Definition Files CiscoDuoAuth_DCR.json
CCF Configuration CiscoDuoAuth_PollingConfig.json
CCF Capabilities CiscoDuo, Paging

The Cisco Duo connector ingests authentication log data from the Cisco Duo Admin API into Microsoft Sentinel.

Supports HMAC-based API Key authentication (Integration Key and Secret Key).

For more information, visit Cisco Duo Admin API Docs.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
DuoAuthentication_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Step 1 - Obtain Cisco Duo Admin API credentials

  1. Log in to the Cisco Duo Admin Panel.
  2. Navigate to Applications and click Protect an Application.
  3. Search for Admin API and click Protect.
  4. Copy the API Hostname, Integration Key, and Secret Key.
  5. Ensure the application has Grant read log permission enabled.

2. Step 2 - Connect Cisco Duo to Microsoft Sentinel

Enter your Cisco Duo Admin API credentials below to begin ingesting authentication logs.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index