We utilize Duo Security to mitigate phishing and other similar attack vectors in general.
Cisco Duo - Essentials Edition
Cisco Systems, Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Saves us time, establishes trust, and prevents phishing
What is our primary use case?
How has it helped my organization?
Our phishing attacks have significantly decreased. The number of compromises is almost nonexistent due to the implementation of Duo Security.
Duo Security's self-service portal has definitely helped us save a couple of hours per month.
Duo Security's ability for establishing trust is great.
What is most valuable?
The anti-phishing feature is the most valuable.
What needs improvement?
Previously, we encountered an issue with utilizing the passcode as part of the second factor; however, that has now been transformed into a feature.
I would appreciate it if Duo Security could improve its integrations with Windows Hello.
For how long have I used the solution?
I have been using Duo Security for five years.
What do I think about the stability of the solution?
Duo Security is stable.
What do I think about the scalability of the solution?
After Cisco purchased Duo Security, I was uncertain about its scalability. However, it appears that Cisco has granted them the freedom to pursue their own initiatives and has provided the necessary resources for them to achieve their goals.
How are customer service and support?
The technical support is excellent.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment took place five years ago, but during that time, we experienced some growing pains before reaching a satisfactory point.
What about the implementation team?
I was not involved in the implementation, but we did seek external assistance, which proved beneficial.
What was our ROI?
We have observed a return on investment with Duo Security in terms of anti-phishing and breach prevention.
What other advice do I have?
I rate Duo Security a ten out of ten.
We do not use Duo Security for end-to-end detection and remediation of threats.
Duo Security may not be the only solution available, but it is a fantastic choice.
Helps reduce the risk of breaches
What is our primary use case?
We use Duo Security for multi-factor authentication for our VPN.
How has it helped my organization?
We didn't have any MFA previously. Adding that extra layer of security helps.
Duo Security has been pretty good for securing our infrastructure from end to end so that you can detect and remediate threats. We've seen several of our employees leave the country, and we see their connections trying to go through and so forth. We can either add them to allow them access or keep denying that access, and we get alerted to that.
It is pretty good in terms of user authentication and device verification for helping to prevent identity-based attacks. Your device is preauthorized. If somebody steals your device, they still need to know your password. That works out pretty well.
Duo Security helps reduce the risk of breaches. If I had known about it sooner, I'd have got it sooner.
The Self-Service Portal has helped free up our IT staff. Our guys spend a little time, and they can go in and look at how to do things and how to set things up. It makes things a little easier.
Duo Security establishes trust for every access request, no matter where it comes from. We really limit where we cannot be accessed from. It helps to make sure whoever we're letting in is who they're supposed to be.
Duo Security considers all resources to be external. If you treat everything as a threat, you're safer that way.
It has helped our organization improve its cybersecurity resilience.
What is most valuable?
It's a lot easier for our end users to connect to our network. You don't have to type in a code. You get push notifications, that's probably the best thing about it. The fewer clicks they have to do to be online, the better it is. They can easily get into the network and do remote work.
What needs improvement?
I'd like to see it integrated into other applications. I know there are some integrations, but I haven't been able to explore that any further.
For how long have I used the solution?
I've been using Duo Security for about the last 18 months.
What do I think about the stability of the solution?
It has been awesome. It's been a ten out of ten.
What do I think about the scalability of the solution?
I haven't had a deal with that.
How are customer service and support?
That's pretty good, but we didn't have to use them for this product. In general, Cisco support has been excellent. I'd rate them a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't have MFA. This was our first one. We were using open-source VPN software and decided that we needed to add MFA. We didn't want to patch a bunch of different things together. Cisco AnyConnect and MFA together worked out very well. We also had a Cisco Firepower firewall, and we decided that one vendor for all of it would make it much easier. Its price was also very reasonable. It made it easy for us to make that decision.
How was the initial setup?
It was straightforward. For most things that I've dealt with from Cisco, I've had to do a lot of research to find things, but with Duo Security, everything was right there for us.
What about the implementation team?
We did it in-house. It was easy.
What was our ROI?
Less time is spent trying to figure things out with a bunch of different software. By having one vendor, there's not a lot of extra work that our guys have to do to keep maintaining that.
What's my experience with pricing, setup cost, and licensing?
Pricing was very reasonable.
What other advice do I have?
To someone researching this solution who wants to improve cybersecurity in their organization, I'd say that definitely give it a look. It's easy to set up. It was very easy for us to set up. We even had our Cisco team call us and make sure we had everything going. It was almost no effort, so it's worth a try.
I'd rate Duo Security a ten out of ten.
Provides security and flexibility, and comes with great support and at-par licensing
What is our primary use case?
We use Duo Security for multi-factor authentication.
How has it helped my organization?
Duo Security helps with multi-factor authentication. It gives another level of security for authentication and logging devices. It's just more secure.
It does a very good job of securing our infrastructure. It enables us to be more secure and provides another level for our users and admins.
It definitely increases security in our work environment. I've also used it at school for logging into my system there. It's good for both scenarios. It's very user-friendly.
It's very good for user authentication and device verification for helping to prevent identity-based attacks. The only thing would be if you lose your phone or something like that, then it breaks the whole setup, so it has been very successful in that.
Now that it has been implemented, it has freed up our IT staff's time. It has mostly been set up and go. We then forget about it till we have to update it.
It's very good for establishing trust for every access request, no matter where it comes from.
Duo Security considers all resources to be external which is an important aspect because of the way our network is set up. We've remote sites, and everyone at those sites also has the requirement to use Duo Security.
It's another level of the security level mechanism that we have. At this point, the way cybersecurity is going, adding more options that are not very heavy lifting for a user is very important.
What is most valuable?
The flexibility is the most valuable feature. We use it for the app on the phone. When we're at different locations, the phone is usually there, so we can use that. It has just been a very flexible option.
What needs improvement?
For upgrades, there should be a better notification of when they're coming out. We always have a testing phase, so we need to be ahead of it. It takes us longer before we can upgrade to the newest version.
For how long have I used the solution?
I've known Duo Security for four years.
How are customer service and support?
Their support is great. We use them a lot. It depends on what issues we're having, but we always get any service, so I'd rate them a ten out of ten. They're very responsive and very knowledgeable. They're more eager at points to get things figured out than we're ready to, which is good, but we have to step back.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't use any other solution before. Its integration with the rest of our products probably made us go for it.
How was the initial setup?
Its deployment is easy, but getting users bought in and starting to use it could be a bit difficult. That comes with any big change.
What was our ROI?
Our organization has definitely got a good return on investment on it.
What's my experience with pricing, setup cost, and licensing?
I haven't seen it in a while, but it's at par with everything else licensing-wise.
What other advice do I have?
Overall, I'd rate Duo Security a ten out of ten.
Establishes trust for every access request, no matter where it comes from
What is our primary use case?
We use it for multi-factor authentication. That's the only use case we have now. We're not using it to its maximum capabilities but we'll use it for more functions moving forward.
How has it helped my organization?
Duo Security has improved our cybersecurity resilience. Multi-factor authentication gives us another layer of protection. Having another layer of security is very important for us.
Duo Security establishes trust for every access request, no matter where it comes from. This is something that's absolutely needed.
What is most valuable?
It's easy to deploy. It's easy to manage. It's easy to integrate with other applications.
We also use it for single sign-on with Meraki and VPN access for non-Cisco firewalls, but we're now migrating to Cisco firewalls. It's easy to deploy, and it works.
What needs improvement?
I'm not using it as much as I could. So far, it has everything I need. I don't have any requirements or improvements. Everything is working smoothly, and we're happy with it.
For how long have I used the solution?
We have been using Duo Security for about two years.
What do I think about the stability of the solution?
Its stability is great.
What do I think about the scalability of the solution?
We have 1,500 users that use Duo Security. We're planning to use Duo Security for more applications, but the number of users won't increase anymore, so in terms of scalability, I don't think we'll have any issues.
How are customer service and support?
We have opened some cases with Cisco for questions and things at all, and they were very helpful. They're very good. They answer questions quickly, and the people who work there are knowledgeable, so I can't complain. I'd rate them a ten out of ten because I got prompt responses and knowledgeable people.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were using Microsoft Authenticator before, but we had a lot of problems with that, so we had to move away from that. Initially, we didn't have any multi-factor authentication, so having a multi-factor authentication for multiple applications and services that we provide helps us in making our network more secure.
How was the initial setup?
You synchronize your AD with Duo Security and create all the groups for access. You send the emails to do the deployment, and you load the cell phone numbers. That's for the end-user side, and for the firewall, we have the proxies. We're using a proxy for one of the products. Our firewall sends RADIUS requests to the proxy, and the proxy communicates to Duo Cloud. The virtual machine deployment for the process was very easy. The configuration takes a few steps, but it's easy.
We've both on-premise and cloud deployments. We're using the tool on the cloud, but we don't have any infrastructure on the cloud.
What about the implementation team?
We did the deployment ourselves.
What was our ROI?
We have seen an ROI. The cost of not having it means you're vulnerable to hacking and other things. Nowadays, multi-factor authentication is required for insurance. It's a must now.
What's my experience with pricing, setup cost, and licensing?
It's very simple. Its price is fair. We use the hardware tokens as well. You get what you pay for.
In terms of licensing, Cisco has very complicated products, but Duo Security was surprisingly easy. The licensing model is easy. The license is based on the intent. You can see how many licenses you have. It's one of the easiest solutions I have deployed, so I'm very happy about it. Every other Cisco product—such as switches, APs, wireless, and controllers—has a very complicated license model. The new smart license model doesn't always work. It's very complicated. The vendors will put your license somewhere else. You need to talk to vendors. It's complicated, but Duo Security licensing is simple.
Which other solutions did I evaluate?
We evaluated RSA, Microsoft, and Duo Security. We evaluated these three, and we realized that Duo Security had better reviews, and it was easier to deploy and cost-effective, so it made sense to use it.
What other advice do I have?
Overall, I'd rate Duo Security a ten out of ten.
An easy-to-use and easy-to-deploy product that enhances security and gives insight into policy violations
What is our primary use case?
We use Duo Security for 2FA during logins.
What is most valuable?
We needed 2FA for compliance. We already used Cisco across the board, so it made sense to use the product. We benefit from using the solution. We were unaware that some users were sharing logins and doing some things that went against policies. Once we had Duo Security in place, we realized that codes were not going where they needed to, and we could sort that out. The solution is easy to use.
What needs improvement?
We have some users that don't prefer to use the app. The product could be more intuitive on the app. We have users that are a little dated in their technology adoption. Telling some of our non-intuitive users to use the app was a little struggle.
For how long have I used the solution?
We implemented the solution about a year ago.
What do I think about the stability of the solution?
We haven't had any issues with the solution’s stability at all. We've had no issues with it not being compatible anywhere.
What do I think about the scalability of the solution?
We're a pretty small shop. We have less than 100 employees, so scalability is not a huge concern because there's not a lot of growth right now. However, bundling and provisioning the tool with any device is pretty easy.
How are customer service and support?
Support is good. We've had a couple of issues with the tool, and anytime we needed anything answered, we've got it resolved. Everything's been quick and reasonable. We generally expect to get answers the same day we have the problem, although it is not possible.
How would you rate customer service and support?
Positive
How was the initial setup?
To my knowledge, we didn't have any issues in the rollout. We tried to phase it out over the course of a few weeks. Once we got a few of them tested, we went to the next phase. Then, we decided to go 100% with it because we saw no problems doing a stack of implementation. It was pretty good.
What was our ROI?
My organization sees an ROI on the product. If there's any attempt at a breach, then we're confident that it will be stopped.
What other advice do I have?
The solution is deployed on the cloud. We're pretty sure it's on our end with the telephone system. We have set up automated phone calls to the desk phones, and sometimes they don't go through or are delayed. However, we've been looking through it and are pretty sure it’s on our telephone system.
I rate the product a seven out of ten in securing our infrastructure from end to end. It's pretty straightforward for people that have done 2FA before, but we have a lot of users that haven't. We have to do a little convincing to get them to do the additional step.
We have saved time by using the tool so that we can dedicate our time to other valuable projects. The tool’s Self-Service Portal helped us with uptime. The solution is good at establishing trust for every access request, no matter where it comes from.
We have policies for our machines and for our phones. The solution really opened our eyes to what people needed to do on their phones and what they were actually bringing to the building.
Duo Security absolutely helped our organization improve its cybersecurity resilience. Our employee and guest network are separated. However, people were bringing their personal devices and doing work-related things on them that we weren't aware of. The solution allowed us to see a little bit more of what was going on at the user level.
Duo Security was the first implementation in our organization. We did not use similar solutions before. Choosing the solution was a pretty quick process. Duo Security was the first one that we demoed. We didn't have any issues, so we went right with it. We chose it because of its ease of use and implementation. We were able to roll it out fairly quickly, so there was no reason to look elsewhere.
We had some partner companies and sister companies that were starting to have breaches. They told us that if we had 2FA, it wouldn't have been a problem.
Overall, I rate the solution a ten out of ten.
A multi-factor authentication offering a good dashboard while being reasonably priced
What is our primary use case?
Our general use cases are for multi-factor authentication for our networking and data center environment devices. We also do some SAML for our network monitoring tools with our different partners in our environment. With SAML, we use it for RADIUS and TACACS authentication.
How has it helped my organization?
The solution has definitely made our administrative access and privileged access to our data center architecture more secure by using multi-factor authentication. It's no longer just a password. You need to have Duo Push. It also helps the security team keep track of when people log in a lot easier, and you can just go to Duo Security to do that. The multi-factor aspect for us was the big reason why we chose Duo. We are Cisco, and it's integrated with Duo Security.
What is most valuable?
The administrator tool in the dashboard is the most valuable feature. It's really easy to quickly see if users are locked out from their device, firmware code, or just all the little dashboards and reports I can run to give the security for monthly reports. The dashboard's really good.
What needs improvement?
The pain point for us at one point was the Duo Authentication Proxy since we're on-premises and not in the cloud. We had to have a proxy machine that's in our DMZ to talk to Duo for us. The configuration of that was a little complicated.
For how long have I used the solution?
I have been using Duo Security in my organization's environment for eighteen months.
What do I think about the stability of the solution?
I never faced any stability issues.
What do I think about the scalability of the solution?
I never faced any scalability issues.
How are customer service and support?
The solution's technical support has been great. The only times I've ever had to call them was when I had to deal with Duo Authentication Proxy, and they were very helpful. They would go through your config and help you figure out any little pain points you're dealing with as far as integrating those different protocols, but they were fine every time I had a call. I rate the support a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
Regarding implementation, it was a really quick project. I think we did PoC to the final rollout in six weeks. Duo Security is very integrated with other security and Cisco products, it took us around six weeks, and we had the solution up and running along with multi-factor authentication for all privileged access users in our environment. Previously, we just had a username and password. It was a big win for us.
What's my experience with pricing, setup cost, and licensing?
Price-wise, the solution has been very, very reasonable, especially since I like that you can scale, and they work really well if you need to expand quickly or retract. We haven't had any problems. Licensing is the last thing I think about regarding Duo Security because it's so easy, and I had no problems with it.
Which other solutions did I evaluate?
During our evaluation phase, we looked at Okta. For privileged access and for our authentication protocols like RADIUS and TACACS, Okta didn't have that functionality. They did SAML, so you could secure web apps or SaaS platforms or anything like that, but not our internal data center networking infrastructure. Duo Security was the only one that really had that capability. It was a really quick process. It's been great ever since.
What other advice do I have?
It is a very powerful tool when it comes to securing infrastructure from end to end. It makes authentications seamless for the users, and it's very well integrated with, like, Cisco ISE. It's not hard to maintain, and that was the biggest bonus. You don't want pain points for your users. Integration and the solution's seamlessness were the two big points.
Regarding my impressions of Duo Security's ability to help reduce risks and breaches, I would say that it is very high. The biggest pushing risk for us is insider threats, so mitigation requiring multi-factor authentication for privileged access reduces that threat surface. Duo Security was a really quick and really easy way to get a really quick win on that.
Duo Security's user authentication and device verification for helping to prevent and identify attacks is pretty good, especially for profiling the devices and for devices that have Duo's app in them. It helps us to understand the users of Duo about which firmware is running and whether they're possibly running firmware that could have some vulnerabilities. It's all in the dashboard. It's very easy to make reports and see them. It really helps people who use Duo, and they have their endpoint in there. It really helps us see a lot about their device.
It helps us save money and time, especially for identify privileged access users who are having problems logging into devices. We get it to automatically alert us, so we can be proactive about finding out what the issue is because if you see a lot of repeated attempts to log in to something, then you see that in Duo, it will email us, and then we can go to just investigate and remediate the issue. It's usually somebody with a bad password, trying to put it in many times, but you never can be sure. So it really helps us be proactive in the aforementioned situations.
Regarding my assessment of Duo Security for establishing trust for every access request, no matter where it comes from, I would say that it does pretty well. So, I don't know if I can talk more about this because we really only have certain avenues into privileged access devices, so I really can't say if it is from anywhere.
It is very important for me that Duo Security considers all resources to be external, especially from a principal security standpoint. It's a great posture to have, and I think that having that kind of posture is good for your security just inside your own network if you treat everything as external. They speak the same language security-wise that we look for in our organization.
Duo Security has helped improve my company's cybersecurity resilience, considering that in our limited scope of where we use it, we are more resilient because of those formation things where we learn about issues proactively, and then we can actually mitigate them, and the report shows trends. So if we see trends, we can see what we mitigated, and we can look at those trends and see if there's a more focused approach than maybe a more long-term thing we need to look at or a bigger change we need to look at. I would say it's helpful from that point.
I would tell those planning to use the solution that Duo Security is a seamless and really transparent solution for its users, and it's very integrated into one's existing systems. Ease of implementation is for somebody who has to engineer a solution and implement it. The ease of implementation is one of the top five things. It's the ease of implementation and it's the integration in your existing systems that really sells Due Security for me.
I rate the overall product a ten out of ten.
Provides a single log in place for all SaaS applications and helps in RADIUS authentication
What is our primary use case?
We use Duo Security for authentication for all of our SaaS applications. We also use it for RADIUS authentication.
How has it helped my organization?
Duo Security makes logging into all our applications easy with one stop for all our activity there. We use Cisco across the board for networking, and we love Cisco.
What is most valuable?
Since Duo Security provides a single place to log in for our SaaS applications, we don't have to manage user accounts and remember passwords for each specific application.
What needs improvement?
Duo Security should better organize its tile feature to organize applications better.
For how long have I used the solution?
We have been using Duo Security for about three years.
What do I think about the stability of the solution?
Duo Security's stability is good, and we haven't had any issues.
What do I think about the scalability of the solution?
Duo Security's scalability is good. We are a fairly large organization but haven't had any scalability issues.
How are customer service and support?
Duo Security's technical support is great. They do a better job on the Duo side than on the networking side for support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've used Okta in the past. Okta has a really good auto-login feature. Duo Security can do the same thing, but Okta might do it a little bit better. It just automatically logs in if it's part of your profile.
We switched to Duo Security because of our relationship with our account reps.
What was our ROI?
We have seen a return on investment using Duo Security because it saves time.
What's my experience with pricing, setup cost, and licensing?
Duo Security's pricing is good, fair, and very comparable to today's market.
What other advice do I have?
Duo Security Self-Service Portal has significantly helped free up our IT staff for other projects. Instead of managing thousands of accounts across hundreds of SaaS applications, it's all in one spot now. Duo Security has probably saved us four or five hours at least.
I think Duo Security does a great job of establishing trust for every access request, no matter where it comes from.
It is very important for our organization that the solution considers all resources to be external because it frames the activity as zero trust, and that's how we run our network to zero trust across the board. So when you treat all resources as external, we want to lock them down every time and not just have random passwords floating everywhere.
Duo Security will significantly simplify the life of someone who wants to improve cybersecurity in their organization, and they should definitely try it.
Overall, I rate Duo Security ten out of ten.
Keeps us secure, allows us to be remote, and is simple to deal with
What is our primary use case?
We use it for multifactor authentication for getting in with cell phones and PCs.
How has it helped my organization?
Duo Security allows us to be remote, and it keeps us secure. It has been very good for securing our infrastructure from end to end. We haven't had any issues.
It has helped free up our IT staff, but I don't have the metrics on how much time it has actually saved. We don't worry about it. It just works.
It has been good for establishing trust for every access request, no matter where it comes from.
What is most valuable?
We're working remotely. It helps us keep people more safe. Its adoption has been fine. I like the fact that you can bypass it if you need to because there are situations where the internet doesn't work, etc.
Its ability to help reduce the risk of breaches is pretty good. I like its ability for user authentication and device verification.
What needs improvement?
We use Yubikey for pushing it to the phones. Yubikeys can get expensive because people tend to lose those for some reason. Fifty dollars a device is pretty high.
For how long have I used the solution?
I've been using this solution for a couple of years.
How are customer service and support?
I don't deal directly with their tech support myself. I've got some other folks that do that for me, but I don't hear any complaints, so I'd rate them really high.
Which solution did I use previously and why did I switch?
We did use another solution. I can't remember the name of it, but it had a lot of flaws and a lot of issues. It did not connect to the equipment that we had to use. It would break down, so we had to find something else.
We didn't consider another solution. While researching, Duo Security came out to be the best. The last one was terrible, and this one ranked a lot higher.
How was the initial setup?
We have a hybrid deployment. It was very easy to implement it.
It integrates well with other systems. We have Cisco Umbrella and Cisco routing and switching. We had Cisco firewalls, but I wouldn't recommend them.
What was our ROI?
We've seen an ROI in using this product. There is stability and ease of use. It isn't a problem to handle. It's simple to deal with.
What's my experience with pricing, setup cost, and licensing?
It falls in line with everything else.
What other advice do I have?
To someone researching this solution who wants to improve cybersecurity in their organization, I'd say that it has been very beneficial.
Overall, I'd rate Duo Security a ten out of ten.
Provides heightened security and has a helpful customer support team
What is our primary use case?
We use Duo Security to level up security and access to internal systems.
How has it helped my organization?
Duo Security has provided us with heightened security. That's the biggest benefit because, nowadays, security risks are big due to hacking. This solution narrows down a lot of things that we have to go through.
What is most valuable?
If you have to log in to something, you must go to Duo Security to confirm that you're who you are on your phone. From there, you go back to the app, and it allows you access.
What needs improvement?
When you come to the push in Duo Security, there are some integrations where you have to use the code instead of the push functionality. Sometimes, you have to go and push from the app, go to Duo Security, and then go back over after you've accepted the push. It would be good if a seamless web comes down, you press the button at the top, and it goes away while you're still in the app.
For how long have I used the solution?
I have been using Duo Security for about two years.
What do I think about the stability of the solution?
Duo Security is a pretty stable solution.
What do I think about the scalability of the solution?
Duo Security is a scalable solution. You can easily download the app, log in, and you have access. Scaling is not an issue with Duo Security.
How are customer service and support?
Duo Security's customer support is very helpful, going above and beyond what they normally need to do to get things fixed and resolved. I can always reach out to my reps, who try to figure out what's going on to help me.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Since I changed companies, I can't remember the old solution, but it was probably some Microsoft solution. It did almost the same thing as Duo Security, except that Duo Security has the push. So instead of going back and finding the code, it can easily just push to the app, allowing you access. So it's a little bit faster to access your systems than having to find these different apps.
What was our ROI?
We have seen a return on investment with Duo Security because getting hacked once would cost us millions. So investing in a solution like Duo Security saves us all that money.
What other advice do I have?
Most solutions do what we're trying to use Duo Security for. It ensures a person has different access to the system via a different device like a YubiKey.
Duo Security has helped to improve our organization's security posture through reassurance in giving out access. Having something like Duo Security on the back end can help pinpoint who's logging in and ensure there is no random bot.
I highly recommend Duo Security because it's still seamless from my standpoint. I don't know how it would be on the back end, but it'd be a great application for any organization wanting to heighten its security on user access.
Overall, I rate Duo Security ten out of ten.