Two-Factor Authentication (TFA) or Multi-Factor Authentication (MFA) is an extra layer of security provided to secure your accounts. This authentication process significantly reduces the risk of unauthorized access, even if your password is compromised. Duo Security, a leading cloud-based Multi-Factor Authentication provider, offers a seamless way to secure your accounts with TFA. By integrating Duo Security with PAM360, you can enhance the security of your privileged access management system, ensuring that only authorized users can access critical resources.
This document will walk you through the following topics:
If you have the Duo application in your environment, you can integrate it with PAM360 and leverage the Duo security authentication as the second level of authentication. This section explains the configurations involved:

Additional Detail
PAM360 uses the latest Web SDK version and it offers support for both the traditional prompt and the universal prompt methods of authentication.
Upon above Duo configuration, enable Duo Security as the TFA in PAM360 and enforce it to the PAM360 users. Refer here for detailed instructions. When enabling Duo Security as TFA in the PAM360 web interface, enter the Client ID, Client secret, and API hostname that are copied from the Duo application.
As explained here, the first level of authentication will be through the usual authentication i.e. users have to authenticate through PAM360's local authentication or Active Directory/LDAP authentication. The users for whom TFA is enabled, will have to authenticate twice successively.
Upon launching the PAM360 web interface with Duo Security as TFA,





Caution
If you have configured High Availability, whenever you enable TFA or when you change the TFA service type, you need to restart the PAM360 secondary server once for it to take effect.