https://www.duosecurity.com/<\/a> ) and what your experience has been or even if you are not using it what comes to mind as an Information Security Professional as to the potential risks and implications of using such a cloud based service for two-factor authentication? Any thoughts or insight appreciated.<\/p>","upvoteCount":2,"datePublished":"2015-11-26T15:02:38.000Z","url":"https://community.spiceworks.com/t/endpoint-security-from-duo/454177/1","author":{"@type":"Person","name":"stevemoores","url":"https://community.spiceworks.com/u/stevemoores"}},{"@type":"Answer","text":"I found that pretty good secure authentication?<\/p>\n
If we have corporate smart phones which are under heavy security policy (complex password for lock screen, short idle time, encrypted phone device , etc),<\/p>\n
Duo pushes the authentication request to smart phone or call that number to validate. someone has to steal both our password and the phone.<\/p>","upvoteCount":0,"datePublished":"2015-11-26T21:32:38.000Z","url":"https://community.spiceworks.com/t/endpoint-security-from-duo/454177/2","author":{"@type":"Person","name":"ratnamvairam","url":"https://community.spiceworks.com/u/ratnamvairam"}},{"@type":"Answer","text":"
I’m actually setting up a proof of concept demo for a client that is looking at this for its 2FA needs. In their case they need 2FA for VPN and RDS access. So far it looks like a workable solution. We setup Duo’s radius proxy server for their authentication with their VPN gateway appliance and we are reading through the docs for the RDS solution. They have a smart phone app, and a key fob (for those users who refuse to use/have a smart phone).<\/p>\n
Their other option is the Symantec VIP 2FA product. They placed the symantec solution as a fall back option if the Duo solution doesn’t work out.<\/p>","upvoteCount":0,"datePublished":"2015-11-26T22:28:26.000Z","url":"https://community.spiceworks.com/t/endpoint-security-from-duo/454177/3","author":{"@type":"Person","name":"george1421","url":"https://community.spiceworks.com/u/george1421"}},{"@type":"Answer","text":"
We use Duo’s 2FA solution. Currently working on integrating it to all of our in-house apps. Nothing but good things to say about it. It just works.<\/p>","upvoteCount":1,"datePublished":"2015-11-27T00:11:56.000Z","url":"https://community.spiceworks.com/t/endpoint-security-from-duo/454177/4","author":{"@type":"Person","name":"johnnelson3","url":"https://community.spiceworks.com/u/johnnelson3"}},{"@type":"Answer","text":"
Thanks for the insight! It really seems to me like for the price, one can’t run their own authentication server (and manage it, keeping it healthy, etc.) for any less money. Certainly not an authentication server that does everything this one claims to. I suppose the only real downside is if they had an a extended outage.<\/p>","upvoteCount":0,"datePublished":"2015-11-27T14:25:02.000Z","url":"https://community.spiceworks.com/t/endpoint-security-from-duo/454177/6","author":{"@type":"Person","name":"stevemoores","url":"https://community.spiceworks.com/u/stevemoores"}},{"@type":"Answer","text":"
I have implemented Duo at Several Sites. You choose the failure method (allow access or deny access). It defaults to allow access keep in mind this is still quite secure because the user has already authenticated against a primary mechanism before reaching the Duo Prompt. I would worry about your site connection going down before Duo, especially if they have redundant data centers/connections.<\/p>","upvoteCount":0,"datePublished":"2015-12-01T00:54:11.000Z","url":"https://community.spiceworks.com/t/endpoint-security-from-duo/454177/7","author":{"@type":"Person","name":"kyle-hill","url":"https://community.spiceworks.com/u/kyle-hill"}}]}}