mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-06-11 21:54:56 +03:00
1.6 KiB
1.6 KiB
MFA with Duo Workflows
Workflow 1: Duo Authentication Proxy Deployment
- Install Duo Authentication Proxy on dedicated server
- Configure authproxy.cfg with AD/LDAP primary auth
- Add Duo API credentials (ikey, skey, api_host)
- Set failmode=safe for initial testing, change to secure for production
- Start Duo proxy service, verify connectivity
- Configure VPN/application to use proxy as RADIUS server
- Test with pilot group before full deployment
Workflow 2: User Enrollment
- Admin creates Duo user (manual or AD sync)
- User receives enrollment email/link
- User installs Duo Mobile app
- User scans QR code to link device
- User completes test authentication
- Admin verifies enrollment status in Admin Panel
Workflow 3: MFA Fatigue Attack Response
- Detect multiple rapid push notifications to single user
- Alert security team via SIEM integration
- Temporarily lock user's Duo account
- Contact user to verify if they initiated authentication
- If unauthorized: reset credentials, investigate source
- If authorized: educate user, enable Verified Push
- Update policy to require Verified Push for affected group
Workflow 4: Duo Failover and Emergency Access
- Duo cloud service becomes unreachable
- Authentication Proxy checks failmode setting
- If failmode=secure: deny all access (most secure)
- If failmode=safe: allow primary auth only (business continuity)
- Admin monitors Duo status page for resolution
- After restoration: review all authentications during outage
- Investigate any suspicious access during failover period