M ManySignal
MS
DU
Integration

Duo Security Integration

MFA event telemetry for detecting push fatigue and bypass attempts.

What this integration does

Duo Security meets agentic SOC

Duo Security (now Cisco Duo) is the leading enterprise MFA and zero-trust access platform. ManySignal ingests Duo authentication logs, administrator events, and telephony logs to detect MFA fatigue attacks (repeated push floods), unusual authentication patterns, and administrator account abuse.

Authentication log ingestion via Duo Admin API

MFA push flood (fatigue attack) pattern detection

Denied push request rate analysis per user

Data collected

  • Authentication events (result, factor, device, location)
  • Administrator audit log events
  • Telephony log events
  • Bypass code creation and use events

Actions supported

  • Disable Duo user
  • Send Duo push approval to verify user identity
  • Create Duo bypass code (for lockout recovery under analyst control)
  • Set user to require Duo on next login

Getting started

Set up in minutes

  1. 1

    Create a Duo Admin API application

  2. 2

    Grant required permissions

  3. 3

    Configure in ManySignal

Duo Security Integration: frequently asked questions

Can ManySignal detect Duo MFA fatigue in real time?

Yes. Duo logs push notifications within seconds of the event. ManySignal's MFA fatigue detection fires when a user receives more than a configurable number of push requests in a short window — default is 3 pushes in 5 minutes.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.