Offering safe entry and a frictionless consumer expertise are usually competing initiatives, however they don’t should be! Learn on to study why.
In our world at this time, context modifications shortly. We earn a living from home, espresso outlets and the workplace. We use a number of gadgets to do work. And on the flip facet, attackers have gotten more and more savvy, getting round safety controls, corresponding to multi-factor authentication (MFA), to realize unauthorized entry.
To cite Wendy Nather, Cisco’s head of Advisory CISOs, “Belief is neither binary nor everlasting.” Due to this fact, safety controls should continuously consider for change in belief, however with out including pointless friction for end-users.
It’s no shock that the lately printed Cybersecurity Readiness Index, a survey of 6,700 cybersecurity leaders from throughout the globe, revealed that extra progress is required to guard identification, networks and functions.
To deal with these challenges and to make zero belief entry for the workforce simple and frictionless, Cisco Duo introduced the final availability of Danger-Based mostly Authentication and enhancements to our enterprise prepared Single Signal-On resolution at Cisco Reside EMEA 2023 earlier this week.
Danger-Based mostly Authentication

Danger-Based mostly Authentication fulfills the zero belief philosophy of steady belief verification by assessing the chance stage for every entry try in a fashion that’s frictionless to customers. A better stage of authentication is required solely when there is a rise in assessed danger. Duo dynamically detects danger and robotically steps up authentication with two key insurance policies:
1. Danger-Based mostly Issue Choice
The Danger-Based mostly Issue Choice coverage detects and analyzes authentication requests and adaptively enforces essentially the most safe elements. It highlights danger and adapts its understanding of regular consumer habits. It does this by in search of recognized assault patterns and anomalies after which permitting solely the safer authentication strategies to realize entry.
For instance, Duo can detect if a corporation or worker is being focused for a push bombing assault or if the authentication machine and entry machine are in two completely different international locations, and Duo responds by robotically elevating the authentication request to a safer issue corresponding to phishing resistant FIDO2 safety keys or Verified Duo Push.

2. Danger-Based mostly Remembered Gadgets
The Danger-Based mostly Remembered Gadgets coverage establishes a trusted machine session (like “bear in mind this laptop” verify field), robotically with out asking the consumer the verify a field, throughout a profitable authentication. As soon as the session is established, Duo seems to be for anomalous IP addresses or modifications to a tool all through the lifetime of the trusted session and requires re-authentication provided that it observes a change from historic baselines.
The coverage additionally incorporates a Wi-Fi Fingerprint offered by Duo Gadget Well being app to make sure that IP deal with modifications mirror precise modifications in location and never regular utilization situations corresponding to a consumer establishing an organizational VPN (Digital Non-public Community) session.

Duo makes use of anonymized Wi-Fi Fingerprint to reliably detect whether or not the entry machine is in the identical location because it was for earlier authentications by evaluating the Wi-Fi networks which might be “seen” to the entry machine. Additional, Duo preserves consumer privateness and doesn’t monitor consumer location or acquire any non-public info. Wi-Fi Fingerprint solely lets Duo know if a consumer has modified location.
Single Signal-On
A typical group makes use of over 250 functions. Single sign-on (SSO) options assist staff entry a number of functions with a single set of credentials and permit directors to implement granular insurance policies for software entry from a single console. Built-in with MFA or passwordless authentication, SSO serves as a important entry administration software for organizations that wish to implement zero belief entry to company functions.

Duo SSO is already well-liked amongst Duo’s prospects. Now, we’re including two new capabilities that cater to trendy enterprises:
1. Help for OpenID Join (OIDC)
An growing variety of functions use OIDC for authentication. It’s a trendy authentication protocol that lets software and web site builders authenticate customers with out storing and managing different folks’s passwords, which is each troublesome and dangerous. So far, Duo SSO has supported SAML net functions. Supporting OIDC permits us to guard extra of the functions that our prospects are adopting as all of us transfer in the direction of a mobile-first world and combine stronger and trendy authentication strategies.
2. On-Demand Password Resets
Password resets are costly for organizations. It’s estimated that 20-50% of IT helpdesk tickets are for password resets. And in response to a report by Ponemon Institute, massive enterprises expertise an common lack of $5.2 million a 12 months in consumer productiveness because of password resets.
When logging into browser-based functions, Duo SSO already permits customers to reset passwords once they have expired in the identical login workflow. And we heard from our prospects that customers need the choice to proactively reset passwords. Now, Duo SSO presents the comfort to reset their Energetic Instantly passwords earlier than they expire. This functionality additional will increase consumer productiveness and reduces IT helpdesk tickets.

Danger-Based mostly Authentication and enhancements to Duo SSO can be found now to all paying prospects based mostly on their Duo Version. If you’re not but a Duo buyer, join a free 30-day trial and check out these new capabilities at this time!
We’d love to listen to what you assume. Ask a Query, Remark Under, and Keep Related with Cisco Safe on social!
Cisco Safe Social Channels
Share:

