This article explains how to connect Duo Cloud to Expel Workbench.

Here's what you need to get started:

  • Duo Cloud administrator account with Owner role.

  • Duo Cloud Admin APIs enabled as these aren't enabled by default. For more information about Duo Cloud Admin APIs, go to https://duo.com/docs/adminapi.

Step 1: Generate API credentials

  1. Log in to the Duo Cloud admin portal as an Owner (https://admin.duosecurity.com) and navigate to Applications > Protect an Application.

    • Click Protect this Application for the Duo Cloud Admin API.

  2. On the next screen, copy and save the Integration key, Secret key, and API hostname for this application. These are the credentials Expel needs to connect to the Duo Cloud service.

    Tip

    These are not shown again, so save them now.

  3. In the Settings section, name the application something descriptive. We recommend Expel API.

  4. Check the following required permissions:

    Permissions

    What Expel does with it

    Grant read information

    Reads total user count.

    Grant read log

    Reads audit logs for security monitoring.

    Grant read resource

    Reads user and groups information and enrich events with this context.

  5. If you prefer to specify the IPs to access the API, list the following in the Networks for API Access field:

Step 2: Configure the technology in Workbench

Note

Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.

  1. In a new browser tab, log into Workbench.

    DUO_Device_Connect.png
  2. Type in this information:

    • Name and Location.

    • API Hostname from Step 1.

    • Integration key from Step 1.

    • Secret key from Step 1.

Tip

This page was accurate at the time of writing, but changes happen. If you find the instructions are outdated, let us know via your engagement manager or account representative.