↳ GitHub sourceConnector

Cisco Duo Authentication

Description

The Cisco Duo connector ingests authentication log data from the Cisco Duo Admin API into Microsoft Sentinel. Supports HMAC-based API Key authentication (Integration Key and Secret Key). For more information, visit [Cisco Duo Admin API Docs](https://duo.com/docs/adminapi#overview).
Declared author / publisher
Cisco Systems, Inc.

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions are required.
Workspace
Workspace
Cisco Duo API Key
A Cisco Duo Integration Key and Secret Key are required. These are obtained by creating an Admin API application in the Duo Admin Panel. [See documentation](https://duo.com/docs/adminapi#overview).

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Step 1 - Obtain Cisco Duo Admin API credentials
1. Log in to the [Cisco Duo Admin Panel](https://admin.duosecurity.com). 2. Navigate to **Applications** and click **Protect an Application**. 3. Search for **Admin API** and click **Protect**. 4. Copy the **API Hostname**, **Integration Key**, and **Secret Key**. 5. Ensure the application has **Grant read log** permission enabled.
Step 2 - Connect Cisco Duo to Microsoft Sentinel
Enter your Cisco Duo Admin API credentials below to begin ingesting authentication logs.
API Base URL
Integration Key (Username)
Secret Key (Password)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CiscoDuoAuthConnectorDefinition
Additional source files 2Solutions/CiscoDuoSecurity/Data Connectors/CiscoDuoAuth_CCF/CiscoDuoAuth_ConnectorDefinition.jsonsource ↗Solutions/CiscoDuoSecurity/Data/Solution_CiscoDuoSecurity.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.