This article explains how to connect DUO Cloud to Expel Workbench.
Here's what you need to get started:
-
DUO Cloud administrator account with Owner role.
-
DUO Cloud Admin APIs enabled as these aren't enabled by default. For more information about DUO Cloud Admin APIs, go to https://duo.com/docs/adminapi.
Step 1: Generate API credentials
-
Log in to the DUO Cloud admin portal as an Owner (https://admin.duosecurity.com) and navigate to Applications > Protect an Application.
-
Click Protect this Application for the DUO Cloud Admin API.
-
-
On the next screen, copy and save the Integration key, Secret key, and API hostname for this application. These are the credentials Expel needs to connect to the DUO Cloud service.
Tip
These are not shown again, so save them now.
-
In the Settings section, name the application something descriptive. We recommend Expel API.
-
Check the following required permissions:
Permissions
What Expel does with it
Grant read information
Reads total user count.
Grant read log
Reads audit logs for security monitoring.
Grant read resource
Reads user and groups information and enrich events with this context.
-
If you prefer to specify the IPs to access the API, list the following in the Networks for API Access field:
Step 2: Configure the technology in Workbench
Note
Expel secures all login information our SOC analysts need about your devices in a MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.
-
In a new browser tab, log into Workbench.
-
Type in this information:
-
Name and Location.
-
API Hostname from Step 1.
-
Integration key from Step 1.
-
Secret key from Step 1.
-
Comments
0 comments
Please sign in to leave a comment.