Integration Guide: Cisco Duo Users
Learn How to Connect the Cisco Duo Users Integration
Published Date: June 26, 2026 | Last Updated: August 28, 2026
Overview
Tello IAM offers two separate Cisco Duo integrations. Cisco Duo Users connects to the Duo Admin API to manage and monitor end user accounts. Cisco Duo Admin connects to the Duo Admin API to manage administrator accounts. These are distinct integrations with separate credentials and permissions — each must be connected independently.
This article covers the Cisco Duo Users integration.
Before connecting
The Administrator completing this setup must have access to the Duo Admin Panel and permission to create Admin API applications. The Admin API application must be granted the following permissions for Tello IAM to connect:
- Grant administrators — Read and Write
- Grant read information
- Grant resource — Read and Write
- Grant identity verification — Read and Write
The following grants are not required: Grant applications, Grant settings, Grant read log, and Grant set Admin API permissions.
Step 1: Create an Admin API application in Duo
- Sign in to the Duo Admin Panel.
- Navigate to Applications → Protect an Application.
- Search for Admin API and select Protect.
- Under Permissions, enable Grant administrators (Read and Write), Grant read information, Grant resource (Read and Write), and Grant identity verification (Read and Write). Leave the remaining grants disabled.
- Save the application. Duo displays the API Hostname, Integration Key, and Secret Key for the application.
- Copy all three values.
Important: Copy the Secret Key before leaving this page. It will not be shown again. If lost, a new Admin API application must be created.
Step 2: Connect Cisco Duo Users in Tello IAM
- Navigate to Integrations in the left navigation.
- Select + Add Integration.
- Search for Cisco Duo Users and select Add.
- Enter the API Hostname (for example,
api-XXXXXXXX.duosecurity.com). - Enter the Integration Key.
- Enter the Secret Key.
- Select Test Connection to verify all values are valid. A Connection successful confirmation will appear if accepted.
- Select Connect. The integration appears on the Integrations page and an initial sync begins automatically.
Verify the connection
After the initial sync completes, confirm the following on the Integrations page:
- The Cisco Duo Users integration displays a status of
Active - A sync timestamp is present and reflects the completed sync
- User records on the Users page display detected Duo user permissions in the Access column
Reauthorizing the connection
If the integration loses authorization, it will display an error on the Integrations page. To reauthorize, locate the existing Admin API application in the Duo Admin Panel or create a new one, then select the integration row in Tello IAM, select Configure, and enter the updated credentials.
Related articles
- Cisco Duo Admin — connect the Duo Admin API to manage administrator accounts
- Configuring Integrations — manage sync schedules, drift detection, and integration settings
- Understanding Errors — resolve integration errors and authorization failures
Seasoft Security Solutions LLC | Tello IAM