Beta
Duo
Use Cisco Duo identity context and enrich its tokens to drive fine-grained access decisions.
About PlainID + Duo
The integration between PlainID and Dou enables organizations to apply a continuous Authentication-Authorization process. The PlainID Dou Authorizer will continue the Authentication process carried out by Dou, to provide the full adaptive access the user is entitled for.
The main objective of Dou, as an IdP (Identity provider), is to handle the authentication process, this is mostly done based on well-defined protocols such as OIDC and SAML. The outcome of the process is an authentication token. During the Authentication process, the PlainID Dou Authorizer dynamically calculates and provides a list of claims and groups based on the policies defined within PlainID. These claims and groups will be used to enrich the token-minted Dou. The objective of the token enrichment flow is to dynamically and contextually calculate and provide the list of claims (Authorizations) to Dou, as part of the login process.
Technical Information
The PlainID Dou Authorizer allows to enrich Dou's JWT as part of the login process. This is done by utilizing Dou’s webhook to obtain the relevant claims for the authenticating user from PlainID’s PDP. The Token Enrichment functionality is supported both by the PlainID Cloud-Based PDP, and the Hybrid, customer-hosted PlainID Policy Authorization Agent.
Architectures
- User logins to the application.
- The app initiates an authentication process (SSO) with Duo (IdP).
- As part of the authentication process, Duo sends a request to PlainID Authorizer via a webhook interface to get an enriching token.
- The PDP dynamically calculates the access decision, utilizing the Policy Information Point (PIP) to retrieve additional user or asset attributes from various data sources if required. PlainID Authorizer then returns access decisions with authorization claims to enrich the access token granted by Duo.
- Duo provides the app with an access token containing the dynamically calculated access decision.

Technology
- Identity Providers
Capabilities
- Manage
- Enforce
Auth Patterns
- Token Enrichment
- Policy information point (PIP)
Need help integrating?
Our experts can help you architect the perfect authorization strategy for your stack.
Better Together
Connect Context. Centralize Policy. Enforce Everywhere.


