We try to use the solution for pretty much everything that we can use with it. The tool helps us to get into our dashboard APIs, and log into Citrix, VPN, and servers.
Network Engineer at a healthcare company with 51-200 employees
Helps to log in to Citrix, VPN and servers
Pros and Cons
- "I love Duo Security's push notifications. It's simple, fast, and secure. From the user's perspective, the solution is seamless. The security aspect is great."
- "We already have Active Directory enabled in our routers and switches. However, if we could do two-factor authentication, then it could go a long way since no one's getting into them unless you want them to."
What is our primary use case?
What is most valuable?
I love Duo Security's push notifications. It's simple, fast, and secure. From the user's perspective, the solution is seamless. The security aspect is great.
For how long have I used the solution?
We have been using the product for about two to three years in our company.
What do I think about the stability of the solution?
I haven't seen any reason to think the solution is unstable.
Buyer's Guide
Cisco Duo
September 2026
Learn what your peers think about Cisco Duo. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,654 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The product is very scalable from what I have seen.
How are customer service and support?
The solution's support is pretty good. It helped us quite a bit. Both Meraki and TAC have been pretty helpful.
Which solution did I use previously and why did I switch?
We switched to Duo Security due to the cybersecurity threats that came with COVID. There was a big one that came against us at one time, but we were able to squash it pretty quickly. The threat was not able to get into the mainframe because of the solution.
How was the initial setup?
The tool's setup was easy and we didn't require too much outside help to set it up.
What was our ROI?
As a network and security guy, security is my return and it has been better with the product's use.
What other advice do I have?
I would rate the solution a nine out of ten. Duo Security can get spotty at the back end but it doesn't break. It would be great if I could use the product to log into the routers or switches in the infrastructure. We already have Active Directory enabled in our routers and switches. However, if we could do two-factor authentication, then it could go a long way since no one's getting into them unless you want them to. We are all for more security in healthcare.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a computer software company with 5,001-10,000 employees
Provides heightened security and has a helpful customer support team
Pros and Cons
- "If you have to log in to something, you must go to Duo Security to confirm that you're who you are on your phone."
- "When you come to the push in Duo Security, there are some integrations where you have to use the code instead of the push functionality."
What is our primary use case?
We use Duo Security to level up security and access to internal systems.
How has it helped my organization?
Duo Security has provided us with heightened security. That's the biggest benefit because, nowadays, security risks are big due to hacking. This solution narrows down a lot of things that we have to go through.
What is most valuable?
If you have to log in to something, you must go to Duo Security to confirm that you're who you are on your phone. From there, you go back to the app, and it allows you access.
What needs improvement?
When you come to the push in Duo Security, there are some integrations where you have to use the code instead of the push functionality. Sometimes, you have to go and push from the app, go to Duo Security, and then go back over after you've accepted the push. It would be good if a seamless web comes down, you press the button at the top, and it goes away while you're still in the app.
For how long have I used the solution?
I have been using Duo Security for about two years.
What do I think about the stability of the solution?
Duo Security is a pretty stable solution.
What do I think about the scalability of the solution?
Duo Security is a scalable solution. You can easily download the app, log in, and you have access. Scaling is not an issue with Duo Security.
How are customer service and support?
Duo Security's customer support is very helpful, going above and beyond what they normally need to do to get things fixed and resolved. I can always reach out to my reps, who try to figure out what's going on to help me.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Since I changed companies, I can't remember the old solution, but it was probably some Microsoft solution. It did almost the same thing as Duo Security, except that Duo Security has the push. So instead of going back and finding the code, it can easily just push to the app, allowing you access. So it's a little bit faster to access your systems than having to find these different apps.
What was our ROI?
We have seen a return on investment with Duo Security because getting hacked once would cost us millions. So investing in a solution like Duo Security saves us all that money.
What other advice do I have?
Most solutions do what we're trying to use Duo Security for. It ensures a person has different access to the system via a different device like a YubiKey.
Duo Security has helped to improve our organization's security posture through reassurance in giving out access. Having something like Duo Security on the back end can help pinpoint who's logging in and ensure there is no random bot.
I highly recommend Duo Security because it's still seamless from my standpoint. I don't know how it would be on the back end, but it'd be a great application for any organization wanting to heighten its security on user access.
Overall, I rate Duo Security ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Cisco Duo
September 2026
Learn what your peers think about Cisco Duo. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,654 professionals have used our research since 2012.
Solutions Architect at a mining and metals company with 1,001-5,000 employees
Video Review
Makes it easy for the user to approve access and go through the process of logging in to the VPN
Pros and Cons
- "The most valuable feature of Duo Security is the ability for the user to easily approve access. The application prompts the user, and they can see the location and the IP address. This makes it easy for the user to approve it and go through the process of logging in to the VPN."
- "Integration between Duo Security and FTDs needs improvement. Integrating Next Generation Firewall safety with Duo Security currently requires a proxy agent between Active Directory and the appliance. It's an additional factor that we need to think about. It would be great to have direct integration with FTD so that we don't have to worry about middleware products. For the rest of the Cisco Secure solutions, the APIs need improvement."
What is our primary use case?
Our primary use case is multifactor authentication for our VPN users. We didn't have multifactor authentication before. After we integrated Duo Security with our systems, everyone has been using it, and it has given us peace of mind when dealing with VPNs.
What is most valuable?
The most valuable feature of Duo Security is the ability for the user to easily approve access. The application prompts the user, and they can see the location and the IP address. This makes it easy for the user to approve it and go through the process of logging in to the VPN.
Duo Security can be used for any type of authentication apart from that for VPNs. It saves time and prevents problems because it is user-friendly.
What needs improvement?
Integration between Duo Security and FTDs needs improvement. Integrating Next Generation Firewall safety with Duo Security currently requires a proxy agent between Active Directory and the appliance. It's an additional factor that we need to think about. It would be great to have direct integration with FTD so that we don't have to worry about middleware products. For the rest of the Cisco Secure solutions, the APIs need improvement.
Duo Security needs to improve the delivery of text messages to the users. This has been a big pain point for us over the years. Though we understand that the local telecoms are the ones responsible for the final delivery of the message, there should be a way to improve the process. Some users don't use the application and rely on SMS messages. It is a problem at times because the messages are not delivered.
For how long have I used the solution?
We've been using Duo Security for almost six years.
We use Cisco Umbrella, ISE, FirePOWER Services, Next Generation Firewalls, FTD, ASA, and Duo Security.
What do I think about the stability of the solution?
The stability of Duo Security is great. We receive notices for any problems or issues in a very timely manner.
What do I think about the scalability of the solution?
The solution is generally easy to scale. If you have the ability to deploy Duo Security yourself or can leverage third-party integrators, there should not be any issues with scalability.
How are customer service and support?
Cisco support for Duo Security has been great. We haven't had many cases, and most of the ones we have had were related to SMS and text messaging delays.
On a scale from one to ten, I'd rate technical support at eight. They are quick to provide solutions but can improve on working with third-party service suppliers so that end-user experience is better.
How would you rate customer service and support?
Positive
How was the initial setup?
Deploying Duo in our environment was very easy because of the pre-staged configuration. It was very quick, and in one to two days, we had a VPN concentrator using Duo Security.
What about the implementation team?
Duo Security was initially deployed using a consultant, but afterward, we deployed multiple additional VPN concentrators ourselves.
What was our ROI?
The return on investment has been huge in terms of protection from cyber-attacks. We have been able to protect our employees by having multifactor authentication. This is invaluable for companies in the current threat landscape.
In terms of support, it's always great to have happy users who are able to easily log in to our environment through VPN without having to bother about non-working software agents or any other type of authentication platforms.
What other advice do I have?
My advice to you if you are evaluating Duo Security would be to do your research and compare it to other competitors. If you are a Cisco-oriented company, you will see that there are several benefits to using Duo Security. You will also see that it has the edge over other solutions on the market.
On a scale from one to ten, I would rate Duo Security at eight. The stability and user experience are great, but there's room for improvement in terms of text message and SMS delivery.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Network Engineer at a tech services company with 11-50 employees
Fast support, good scalability, and helpful for two-factor authentication
Pros and Cons
- "The two-factor authentication is valuable because that is the use case for which we are using it."
- "We first deployed Duo Security for our company with the VPN, and afterward, about a year later, we implemented it for a customer of ours where we offered infrastructure as a service. When I tried to establish a VPN connection through Duo Security, it did not function well on that version, which was the latest one at the time. So, I had to make a copy of the machine and then implement Duo Security with the VPN because it did not function well with the newer version."
What is our primary use case?
We mostly use it for our AnyConnect VPNs and two-factor authentication.
How has it helped my organization?
We use Firepower Defense as a firewall, and we have implemented the IPS system on the firewall. Previously, we had ASA, and two-factor authentication was with the code, but now, it's with a push notification. It has somehow made it easier for non-IT employees to easily connect to the VPN, but it, as such, hasn't saved any time. It didn't reduce any tasks.
It hasn't helped consolidate any tools or applications because we're not using any other security components that can be integrated with it.
What is most valuable?
The two-factor authentication is valuable because that is the use case for which we are using it.
What needs improvement?
We first deployed Duo Security for our company with the VPN, and afterward, about a year later, we implemented it for a customer of ours where we offered infrastructure as a service. When I tried to establish a VPN connection through Duo Security, it did not function well on that version, which was the latest one at the time. So, I had to make a copy of the machine and then implement Duo Security with the VPN because it did not function well with the newer version. I didn't know why, but it did not function. I haven't tried to update it since then, but that could be an area of improvement.
For how long have I used the solution?
I've been using Duo Security for almost four years.
What do I think about the stability of the solution?
It's stable.
What do I think about the scalability of the solution?
It has good scalability.
How are customer service and support?
They were helpful and fast 90% of the time. They have knowledgeable tech engineers. We didn't have many problems, but any problem that required a case to be opened was resolved quickly. I'd rate their support a nine out of ten.
Which solution did I use previously and why did I switch?
We didn't use a similar solution previously. We went for this solution because of the consistency of Cisco products and the best cases that it provides. It fulfills our needs as a company.
How was the initial setup?
It was straightforward. I had some issues, but mostly, I followed the complete path from sandboxing to testing and then going live in production.
What about the implementation team?
We have two people, me and my colleague, but it's mostly me.
What was our ROI?
I am not involved in its pricing, but we haven't yet seen an ROI.
What other advice do I have?
I'd recommend using it. You can read about the product and implement your infrastructure.
I'd rate Duo Security a 10 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a government with 501-1,000 employees
Improves our security and helps in providing context-based access
Pros and Cons
- "It's easy to use for the security part, and it helps to improve our security posture."
- "They can make authentication easier. It should be done in a shorter time. Sometimes, it can take a bit more time to get the answer on your phone. You have to wait a bit longer to get the SMS code and other things. There can be some internet or connection issues. They should make it faster because sometimes, it's urgent, and you need to access something as soon as possible."
What is our primary use case?
We use Duo Security for two different parts. One is for access to one of the servers, and the other one is for accessing the VPN connection.
How has it helped my organization?
It helped free up the time of IT staff. It helped them to manage the control within the users. They can control who gets access to which part of the system. For example, if there is a group of people who need a certain type of permissions, they can set them up easily. They can gather them in groups and give specific permissions. They can also give specific permissions to only one person.
It has been very useful in detecting or fixing threats that come into the organization.
What is most valuable?
It's a good thing for the authentication of your credentials. It's easy to use for the security part, and it helps to improve our security posture.
What needs improvement?
They can make authentication easier. It should be done in a shorter time. Sometimes, it can take a bit more time to get the answer on your phone. You have to wait a bit longer to get the SMS code and other things. There can be some internet or connection issues. They should make it faster because sometimes, it's urgent, and you need to access something as soon as possible.
For how long have I used the solution?
I have been using this solution for about two years.
What do I think about the stability of the solution?
In general, all Cisco products, not just the Duo product, have a lot of stability.
How are customer service and support?
Their tech support is pretty good, but there are some disadvantages. Sometimes, they take a long time to answer. I understand that some of the issues are not very easy, and it takes time to research them. I'd rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't use any non-Cisco products. We were only using Cisco products. The IT part of our organization is using the Duo authentication system, and we are using another part of the server for authentication.
How was the initial setup?
It's not very hard. It doesn't take long. The IT gives us an access code for it.
I just downloaded the app, and after that, just got the security code from that department. I entered that, and it was done. That's it. If you are changing your device and they're just resetting your data, it can take two or three minutes maximum for a new device.
What other advice do I have?
I'd rate Duo Security an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at a wellness & fitness company with 10,001+ employees
One-stop application for multiple MFAs that helped us consolidate tools
Pros and Cons
- "Duo Security improved my organization by helping us secure all access points within the company infrastructure."
- "Duo Security could be improved with the addition of more applications."
What is our primary use case?
Our primary use case for Duo Security is all user access to email.
How has it helped my organization?
Duo Security improved my organization by helping us secure all access points within the company infrastructure.
Duo Security helped our company consolidate tools, including email and VPN.
What is most valuable?
What I find most valuable about Duo Security is that it is our one-stop application for multiple MFAs.
What needs improvement?
Duo Security could be improved with the addition of more applications.
Duo Security has not helped free up our IT department's time.
For how long have I used the solution?
I have been using Duo Security for six months.
What do I think about the stability of the solution?
Duo Security's stability is perfect.
What do I think about the scalability of the solution?
Duo Security's ability to scale is perfect. We have 5,000 people using it in four countries.
How are customer service and support?
I have never used Duo Security's support.
Which solution did I use previously and why did I switch?
We previously used integrated multi-factor security from Microsoft 365 and Fortinet FortiToken. We made the switch to Cisco because we wanted to handle everything in one application.
How was the initial setup?
I was not involved in the initial deployment. I do know however that 10 people were involved in the deployment.
What was our ROI?
We have seen a return on investment because with Duo Security, we do not have to pay for multiple applications. Instead, we pay for one solution.
What's my experience with pricing, setup cost, and licensing?
The cost of Duo Security licensing is OK.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network engineer 2 at a tech vendor with 10,001+ employees
Cloud based security solution that offers end to end MFA functionality and is reliable and stable
Pros and Cons
- "Duo has allowed us to add an additional layer of security to our organization and to establish trust for every access request and secures our environment."
- "Duo Security has helped remediate threats more quickly and offers security end to end."
- "We have a 24 hour timer for our Duo cookie and we would like to reduce this to a shorter time when using Duo."
What is our primary use case?
Duo specifically offers good MFA functionality. We needed support for our VPN and used GlobalProtect as well as Duo for additional security.
How has it helped my organization?
Duo has allowed us to add an additional layer of security to our organization. It prevents people from gaining access unless they have your credentials as well as a device. It has allowed us to establish trust for every access request and secures our environment. We are confident and comfortable with the way the solution handles this. We have tried other solutions but they've not met our expectations.
Duo Security does a good job of helping to support our organization across a distributed network. It does a fantastic job at securing access to applications and networks. It is streamlined and straightforward.
Duo Security provides single-pane-of-glass management.
What is most valuable?
This solution has been most valuable for locking up our VPN solution and providing secure web protection.
What needs improvement?
We have a 24 hour timer for our Duo cookie and we would like to reduce this to a shorter time when using Duo. We use Duo together with GlobalProtect and I am not sure which solution would be responsible for this improvement.
For how long have I used the solution?
I have been using Duo Security for the entire time I've been employed at my company.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution. We have 20,000 users covered by this solution.
How are customer service and support?
We have not needed much help from the Duo support team. Using this solution has been surprisingly easy for us.
Which solution did I use previously and why did I switch?
We were running a different solution on a test gateway we had and it didn't meet our expectations so we moved to Duo. We have previously tested XAML.
What's my experience with pricing, setup cost, and licensing?
You pay per user when using this solution and the pricing is fair.
What other advice do I have?
We have never had an issue in maintaining network connectivity across all workplaces. Duo Security has helped remediate threats more quickly and offers security end to end. Cybersecurity resilience is probably one of the most significant elements of organization because we work in the healthcare industry.
I would rate this solution a ten out of ten. This is because we have not had any vulnerability that has been exposed to or any other issues that we've had to deal with.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
MSP Director at a tech services company with 11-50 employees
Easy to use and gives our customers multi-factor identification on-prem and in the cloud
Pros and Cons
- "The single pane of glass management works very well. That feature is very important because we have a lot of admins who have to manage Duo, and it's much easier when it's a single pane of glass. That single pane is also great because it's easy to enroll new devices."
- "Everybody loves it. They feel a sense of security when they get that prompt to send them a text, or an email."
- "One area that might be improved is that setting up SMS texting is not as easy as using the app, even though it does support it."
What is our primary use case?
We mostly use it for multi-factor authentication with email platforms like Office 365 as well as other apps.
How has it helped my organization?
We were looking to deal with email phishing attacks and brute force attacks, and the like, and Duo has helped a lot. We're more secure with multi-factor and have seen the number of phishing attacks and brute force attacks go down.
Logging in with Duo is baked into anything that we log into, including any applications, email, and web apps. We integrate it with a product called Jump Cloud, which is our cloud-based identity management system. We have also integrated it into WebEx and Box. Duo runs all of our security and MFA, and it's worked out well.
It's helped a lot of our customers with multi-factor in their identity management systems, on-prem and in the cloud. That way, when users log in, they get the MFAs to be able to log in to any resource on the network.
And because everybody is working remotely now, Duo checks all the boxes for hybrid work.
When it comes to remediating threats, it has helped us do so quickly. We don't even see a lot of the threats anymore because it's working behind the scenes. It has definitely decreased the number of threats in the last year compared to what we used to see.
What is most valuable?
The ease of use and the ease of management of all the users have been key for us. The setting up of devices in Duo has been really easy as well. It's better than all the other ones I've worked with.
Another important feature is that Duo considers all resources to be external because even the internal ones look like external ones, and people click on stuff and get caught. It's very important to be more cautious than ever.
Also, the single pane of glass management works very well. That feature is very important because we have a lot of admins who have to manage Duo, and it's much easier when it's a single pane of glass. That single pane is also great because it's easy to enroll new devices.
What needs improvement?
One area that might be improved is that setting up SMS texting is not as easy as using the app, even though it does support it.
Also, a faster management user interface would help. It tends to lag a little bit.
For how long have I used the solution?
I've been using Duo Security for three or four years.
What do I think about the stability of the solution?
It has been stable. We haven't really had many issues with it. It maintains network connectivity across all workplaces and works great. I don't have any complaints.
What do I think about the scalability of the solution?
It can scale to as many employees as you have. It can go from five employees to 1,000 employees. I don't see any issues with the scalability.
How are customer service and support?
Their technical support is great.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
The initial deployment was pretty straightforward. We had a small number of challenges, but nothing we couldn't get by. It was pretty smooth, overall. Setting it up and enrolling new devices into the environment was a breeze. That was the easiest thing.
What about the implementation team?
We do it ourselves.
What was our ROI?
We see ROI in that users feel more secure and their morale goes up. You get to keep those employees a lot longer if they feel better working for an organization that's investing in security. A big benefit is keeping your employees.
Everybody loves it. They feel a sense of security when they get that prompt to send them a text, or an email. It makes them feel like they're working for a company that is really taking the time to secure the environment. It gives them a good feeling when they get a second form of authorization.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty competitive. It's pretty cheap. Anybody can adopt it. We don't have customers that haven't used it because of the price.
Which other solutions did I evaluate?
We evaluated Microsoft Authenticator and Google Authenticator. With those solutions, you don't have the granularity of management of the MFA environment that Duo offers.
What other advice do I have?
Our Duo is all cloud-based, there's nothing on-prem. We typically integrate it with our cloud apps.
Resilience in cyber security is a game-changer. We have the same challenges that every organization goes through with security: phishing attacks, ransomware attacks, et cetera. I wouldn't say it has eliminated 100 percent of them, but it definitely cuts a lot of that stuff out. Every organization should have something like Duo, or MFA in general. But if they're going to do it, they should do it with Duo just because it's so easy to manage and it is resilient.
For management that wants to build more resilience within their organization, they have to implement multi-factor authentication across that organization for everything. It shouldn't just be for email but everything internally as well.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Network Engineer at a tech services company with 11-50 employees
Adds an extra layer of security, is self-managed, and helps remediate threats more quickly
Pros and Cons
- "Multifactor authentication is the most valuable feature."
- "Duo Security just adds another layer; it's a great addition to the security of any network infrastructure."
- "Technical support could be improved. I don't think all support should have to go through an agreement."
What is our primary use case?
With Duo, MFA allows the network to have an authenticated user sign-on seamlessly. If someone's entering a password and their user credentials and they want to get access to the network, the Duo app will have a code that the end-user has to input, which then authenticates them. It's a second layer of security before they can access the network. Even if a third party gets your username and password, without that Duo access, they won't be able to access your network.
How has it helped my organization?
We don't have to worry so much about the end-user that's logging in.
What is most valuable?
Multifactor authentication is the most valuable feature.
As for establishing trust for every access request, that's exactly what this solution does. Outside of having a username and password, you have to get authentication from Duo as well.
You can never eliminate trust, but what Duo Security does do is add an extra layer of security. When it comes to the internet, networks, inbound traffic, and outbound traffic, you're always subject to a potential threat. Duo Security just adds another layer.
It's a great addition to the security of any network infrastructure.
In terms of helping workers feel safe, everyone knows that the information within the enterprise is safe because the people that are logging in have been authenticated in more than one way.
It's pretty easy to maintain network connectivity once it's set up; the end-user uses it to log in. It's not something that you have to constantly manage and deal with apart from pushing updates. It's pretty much self-managed.
In terms of consistency across workspaces, it works all the time, except for when a forced update is needed.
It helped us remediate threats more quickly. For instance, if someone accesses your credentials or you leave your laptop open and someone gains access when it times out, you still need the Duo code that is sent. A new code is always needed to be able to access that laptop or even that phone. Then, from there you're able to safeguard the information that your company has.
Nowadays, data is the number one commodity, so protecting that at all costs is really important. Duo helps with that with end-users. The thing about end-users is that they are volatile. You can't really control what someone does. So, Duo security helps with managing that by having them implement a new time code that's always sensitive.
What needs improvement?
Technical support could be improved. I don't think all support should have to go through an agreement.
For how long have I used the solution?
I've been using this solution for seven years.
What do I think about the stability of the solution?
It's very stable. There aren't many issues with Duo.
What do I think about the scalability of the solution?
The scalability is just fine. If you scale a certain amount, you have to upgrade and update your license. Outside of that, it's fine.
We are a large organization that deals with a lot of high transactional payments, and we have a large number of users, maybe 100,000 a day, and inbound user traffic.
How are customer service and support?
If you open up a TAC case and they get to you quickly, it's fine. If you have a service agreement that says that they will get back to you within one to two hours, that's fine because you can resolve an issue. Now, if you don't have that agreement and are just a regular user, they take 48 hours to get back to you, and if you and the network team or the security team can't figure out the issue, a lot of money could be lost in two days.
Because there's always room for improvement and because I don't think all support should have to go through an agreement, I would rate technical support at eight on a scale from one to ten.
How would you rate customer service and support?
Positive
What was our ROI?
Anytime your network is secure and it's not breached or there's no downtime or infiltration of your perimeter, there's always an ROI.
What's my experience with pricing, setup cost, and licensing?
With regard to pricing, for a small business buying a one-off, it's pretty expensive. If it's an enterprise that has thousands of employees, however, it's really nothing to protect your data because if your network goes down or it's breached, you're losing millions of dollars every minute. When it comes to a large enterprise, it's priced where it should be because you're talking business to business. You're not talking business to consumer.
What other advice do I have?
To leaders who want to build more resilience within their organization's security, I would say that you can't go wrong with Cisco products when it comes to security. You can start with Cisco Umbrella, then go down to their firewalls, and then the next-generation firewalls. Then, you can move down to their end-user security endpoints.
The whole lineup through their security portfolio is really strong. If you're spending $50,000 on a suite and a $100,000 total contract value, you can enter a 3.0 Enterprise Agreement. Then from there, you can lock in prices for one, three, to five years. So, when it comes to any enterprise, when you're talking about security, if you use all of Cisco's security features, from end-user out to your data centers, you'll be pretty well off.
If you have security concerns, implement Duo for your end-users.
Overall, I would rate Duo Security an eight on a scale from one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network engineer at a manufacturing company with 1,001-5,000 employees
Easy to incorporate into any sort of application and makes our company more secure
Pros and Cons
- "Another feature is the single pane of glass management. That's important for analytics and also for troubleshooting. It means there's one place that you go to at least start the troubleshooting process."
- "It has definitely made our company more secure."
- "It could be a little bit more intuitive when it comes to the sign-up process. I know they send out an email, but sometimes our users get a little confused. It could be an end-user problem, but Cisco could work on that a little."
What is our primary use case?
We use it for MFA to secure our Outlook webmail and some other applications as well. We use Duo for pretty much anything that uses MFA.
We were looking for increased security. We wanted to make sure that the person who is trying to log in to our services is actually who they claim to be. We wanted to lock down our applications more and provide extra security.
We have some on-prem servers for the gateways and it's in the cloud as well.
How has it helped my organization?
It has definitely made our company more secure. It's pretty easy to incorporate into any sort of application you want to. We also use it for single sign-on for certain applications and that has been nice. People hate passwords.
It's really great for remote workers and a hybrid workforce nowadays, for people who are trying to access their VPN or any applications from outside of the company. It helps us make sure it's someone who should be accessing those things. It does a good job.
It's definitely a factor in achieving that Zero Trust.
In a way, it helps us remediate threats more quickly. If someone is trying a brute-force attack, trying all the passwords they can, and they're not getting a response through Duo, you can see certain security threats that are happening and remediate them.
Duo has also had a big impact on employee morale. People like it. They feel that their data is more secure. Resiliency is very key to keeping people doing their jobs. Cyber security resilience has been very important for us. It used to be that security was not to be the main focus, but it's extremely important now. There are a lot of ransomware attacks and people need to be very cognizant of that. It's important to have redundant and resilient systems in place to support that.
What is most valuable?
It's nice to have that push notification with the app and it's pretty easy to use. Our users are usually pretty open to it, and it's pretty easy to onboard people.
It also seems like it's accurate, and you can add multiple devices to your account.
In addition, typically, if it detects that you're on an internal network, you can bypass the Duo portion of it. That way, people don't have to do MFA when they're on campus.
Another feature is the single pane of glass management. That's important for analytics and also for troubleshooting. It means there's one place that you go to at least start the troubleshooting process. It also helps with the user experience because you can manage all the user accounts from that one spot, including setting up new users, making adjustments, editing their preferences, et cetera.
What needs improvement?
It could be a little bit more intuitive when it comes to the sign-up process. I know they send out an email, but sometimes our users get a little confused. It could be an end-user problem, but Cisco could work on that a little.
For how long have I used the solution?
I've been using Duo Security for about two years.
What do I think about the stability of the solution?
It seems very stable. I don't think there has been any point at which people have tried to use it and it has failed.
What do I think about the scalability of the solution?
The scalability seems fine. As long as you get the licensing to support it, you can add as many users as you'd like.
We have five or six offices locally, and a few more in different states in the US. We also have one in Shanghai, but they're doing their own thing there. But everyone in our US offices uses it, they all get enrolled. Typically, people will install the app on their phones although they don't have to.
How are customer service and support?
I don't think we've had to use technical support too often, which is a good thing about the product itself.
Which solution did I use previously and why did I switch?
We didn't use an MFA before Duo.
How was the initial setup?
When the solution was rolled out, I wasn't with the company, but we then expanded it in different ways and I have been involved in that. In terms of the initial deployment, from what I can tell, it was relatively straightforward. And from what I've seen since, it hasn't been too hard to expand it to other services.
What was our ROI?
It's definitely a valuable product to have.
Which other solutions did I evaluate?
We may have evaluated other options at a surface level, but we didn't really go too deeply into them. We pretty much went with Duo out the gate.
What other advice do I have?
I would tell leaders who want to build more resilience within their organization to do it right now. It's definitely important and there are a lot of resources out there that can help them on that path. Duo helps with that.
It does what it's marketed to do.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Duo Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Authentication Systems Single Sign-On (SSO) Access Management ZTNA as a Service Cisco Security Portfolio Multi-Factor Authentication (MFA) AI Data AnalysisPopular Comparisons
Cloudflare One
Microsoft Entra ID
Cisco Secure Firewall
Okta Platform
Cisco Umbrella
Prisma Access by Palo Alto Networks
Zscaler Zero Trust Exchange Platform
Cisco Identity Services Engine (ISE)
Cato SASE Cloud Platform
Check Point Harmony SASE (formerly Perimeter 81)
Cyera
Ping Identity Platform
Cisco Secure Email
Auth0 Platform
Cisco Secure Network Analytics
Buyer's Guide
Download our free Cisco Duo Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Duo Security compare with Microsoft Authenticator?
- How would you compare Cisco Duo Security with other Authentication Systems products?
- Which solution do you prefer: Duo Security or RSA SecurID Access?
- When evaluating Authentication Systems, what aspect do you think is the most important to look for?
- Why is Authentication Systems important for companies?
- Which front-end product for authorization and authentication into an Apache Web Server application, PIXIA, would you recommend?
- What is the difference between SPML and SAML?
- How would you compare Cisco Duo Security with other Authentication Systems products?
- What is CAPTCHA and how does it work? How can you use it for Artificial Intelligence (AI)?
- What are some alternatives for UserLock?














