Duo Security

Pull users and admin role assignments from Duo Security via HMAC-signed Admin API.

Source connector

Source connector — pulls identity and access data from Duo Security into ComplianceScout where it is scored against your compliance frameworks and violation rules.

What ComplianceScout collects

After a successful sync, the following data is available in your ComplianceScout dashboard for violation detection and reporting.

  • All Duo users with email, username, status, and enrolled status
  • MFA device types enrolled per user (phone, hardware token, push, bypass code)
  • Admin accounts and admin roles
  • Group memberships and policies applied per group

Required credentials

These fields are collected when you add the connector in the ComplianceScout dashboard. Secrets are encrypted at rest using AES-256-GCM and are never logged.

FieldTypeRequiredNotes
Integration key (ikey)TextRequiredAdmin API integration key from Duo Admin Panel → Applications → Protect an Application → Admin API.
Secret key (skey)SecretRequiredAdmin API secret key. Keep this confidential.
API hostnameTextRequiredAPI hostname from the Admin API application, e.g. api-XXXXXXXX.duosecurity.com.

How to set up this connector

Follow these steps to gather the credentials above and connect Duo Security to ComplianceScout.

  1. Log in to the Duo Admin Panel and go to Applications → Protect an Application → search for Admin API.

  2. Click Protect to create the integration. Copy the Integration key (ikey), Secret key (skey), and API hostname.

  3. Under Permissions, enable at minimum: Read users, Read groups, Read administrators.

  4. In ComplianceScout, go to Data & Secrets → Integrations → Add Connector → Duo Security and enter the three credential values.

Ready to connect Duo Security?

Start a free trial — your tenant is provisioned instantly and you can wire up this integration from the connectors page.