Duo
Multi-factor authentication and device trust that make zero trust practical.
Cisco Duo delivers multi-factor authentication, device trust, and adaptive access policy that verify every user and device before granting access to any application. Simple for users and fast to deploy, Duo protects against credential theft and phishing at the front door of every app — cloud or on-premises. Faltrox deploys, configures policy, and operates it as the access-control foundation of a zero-trust programme.
Overview
What Duo is
Compromised credentials are behind a large share of breaches, and multi-factor authentication is the single most effective control against them. Cisco Duo makes strong authentication practical — verifying user identity with a range of factors (push, passkeys/FIDO2, biometrics, tokens) and checking the health and trust of the device before it connects to an application.
Beyond MFA, Duo enforces adaptive access policies based on user, device posture, location, and risk, provides single sign-on, and gives visibility into every device accessing corporate applications. It protects cloud and on-premises apps, VPNs, and remote access alike, and integrates across the Cisco security stack and third-party identity providers. Faltrox deploys Duo, designs the access policy, and operates it as the identity-verification layer of a zero-trust architecture.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Every User
Multi-factor authentication verifies user identity at the front door of every application.
Every Device
Device trust checks the health and posture of the device before granting access.
Cloud & On-Prem Apps
Protects SaaS, on-premises applications, VPNs, and remote access consistently.
Credential Theft & Phishing
Phishing-resistant factors and MFA stop credential-based and phishing attacks.
Adaptive Access
Policy adapts to user, device posture, location, and risk for each access attempt.
Device Visibility
Surfaces every device accessing corporate applications, managed or not.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Authenticate
A user signs in and Duo verifies identity with a strong second factor — push, passkey/FIDO2, biometric, or token.
- 02
Check the Device
Device trust assesses the health and posture of the device — OS, patch level, security agents — before allowing access.
- 03
Apply Policy
Adaptive access policy weighs user, device, location, and risk to allow, step up, or deny the access attempt.
- 04
Grant
Verified users on trusted devices gain single sign-on access to the application without friction.
- 05
Operate
Faltrox designs the policy, rolls out phishing-resistant factors, and monitors access as part of zero trust.
Capabilities
Key capabilities
Multi-Factor Authentication
Verifies identity with push, passkeys/FIDO2, biometrics, and tokens for strong, usable MFA.
Phishing-Resistant Factors
FIDO2 passkeys and Verified Push resist the phishing and MFA-fatigue attacks that defeat weaker factors.
Device Trust
Checks device health and posture — managed or unmanaged — before granting access.
Adaptive Access Policy
Policies weigh user, device posture, location, and risk to make each access decision.
Single Sign-On
Integrated SSO gives verified users frictionless access across their applications.
Device Visibility
Inventories every device accessing corporate apps, surfacing risky and unmanaged devices.
Broad App Coverage
Protects cloud and on-premises apps, VPNs, and remote access with a large integration library.
Fast Deployment
Cloud-delivered and quick to roll out, with a user experience designed for adoption.
Works with
Part of the platform
Cisco products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Cisco Duo for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why is MFA so important?
Compromised credentials are behind a large share of breaches, and MFA is the single most effective control against them. Duo verifies a second factor at the front door of every application, so a stolen password alone is not enough to gain access.
02How does Duo resist phishing and MFA fatigue?
Through phishing-resistant factors like FIDO2 passkeys and Verified Push, which defeat the credential-phishing and push-bombing attacks that bypass weaker MFA. Faltrox rolls these out as part of hardening the access layer.
03What is device trust?
Before granting access, Duo checks the health and posture of the device — operating system, patch level, security agents — so access decisions consider not just who the user is but whether the device is trustworthy, which is core to zero trust.
04Does it work with on-premises apps and VPNs, not just SaaS?
Yes — Duo protects cloud SaaS, on-premises applications, VPNs, and remote access with a large integration library, so you can apply consistent MFA and device trust across the whole application estate.
05How does Faltrox operate it?
We deploy Duo, design the adaptive access and device-trust policy, roll out phishing-resistant factors, and monitor access — delivering it as the identity-verification foundation of the zero-trust architecture we build with you.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us