Skip to content
Duo logo

Duo integration

Unify MFA device lifecycle and authentication intelligence to enforce zero-trust access controls and security incident response.

What it connects

  • User accounts with MFA enrollment status, enrolled devices, and credential types.
  • Administrator audit logs showing user provisioning, group changes, and access control modifications.
  • Authentication attempt logs with success/failure results, authentication methods, and device context.
  • MFA device inventory including phones, hardware tokens, and their assignment to users.

What it automates

  • Create and update Duo user accounts with group assignment for automated onboarding and offboarding.
  • Generate one-time bypass codes for locked-out users and provision hardware tokens for new hires.
  • Remove MFA devices when employees depart or swap authentication methods.
  • Monitor and resync hardware tokens to maintain zero-trust compliance.

In practice

A new hire ticket triggers user creation in Duo, assignment to security groups based on role, and enrollment of both push authentication and hardware token backup.
During offboarding. STLabs removes the departing user's phone and tokens from Duo, revokes bypass codes, and updates group membership to block access.
Helpdesk tickets requesting MFA resets are validated for approval, then STLabs generates bypass codes and sends SMS activation links to restore user access within audit controls.
Authentication logs are correlated with incidents: 15+ failed Duo pushes in 10 minutes triggers a security ticket with the attacker IP, user, and time window for investigation.

See how it connects.Every tool, one live map.

All integrations