Description
The Cisco Duo Telephony Logs connector ingests SMS and phone-call authentication event data from the Cisco Duo Admin API into Microsoft Sentinel.
Telephony logs record every instance where Duo sends an SMS passcode or places a phone callback during an authentication, enrollment, or administrator bypass workflow. Each event includes the phone number, channel used (sms or phone), context, and number of telephony credits consumed.
Supports HMAC-based API Key authentication (Integration Key and Secret Key).
For more information, visit [Cisco Duo Admin API Docs](https://duo.com/docs/adminapi#telephony-log).
- Declared author / publisher
- Cisco Systems, Inc.
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions are required.
Workspace
Workspace
Cisco Duo API Key
A Cisco Duo Integration Key and Secret Key are required. These are obtained by creating an Admin API application in the Duo Admin Panel with 'Grant read log' permission. [See documentation](https://duo.com/docs/adminapi#telephony-log).
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect Cisco Duo Telephony Logs to Microsoft Sentinel
To enable the Cisco Duo Telephony Logs connector, provide your Duo Admin API credentials below.
1. Log in to the [Duo Admin Panel](https://admin.duosecurity.com).
2. Navigate to **Applications > Protect an Application**.
3. Find **Admin API** and click **Protect**.
4. Ensure the application has **Grant read log** permission enabled.
5. Copy the **Integration Key**, **Secret Key**, and **API Hostname** and enter them below.
Integration Key (ikey)
Secret Key (skey)
API Base URL
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
CiscoDuoTelephonyConnectorDefinition
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC