Secure Mobile Access 12.5 Administration Guide

Table of Contents

Integration of SMA with Cisco Duo Security MFA Server

Cisco Duo Security Multiple Factor Authentication (MFA) server can be added as authentication server. This allows users to choose a second factor authentication method on SMA clients to prove their identity. Upon providing primary credentials, users are provided with a list of devices and authentication methods registered with Duo for the user. Based on user choice, user needs to either respond to Push notification or phone-call or other OTP methods to proceed with authentication. Users who fail to authenticate against Cisco Duo Security MFA server will be denied login.

This authentication server can be attached to any primary authentication server supported by SMA. It automatically uses the username provided for primary authentication, thus the user does not have to enter username again for Cisco Duo Security MFA authentication.

Prerequisites:

  • SMA/CMS running 12.4.3 and higher or 12.5.0 as suitable firmware version.

  • Ensure you have an active license or partnership with Cisco Duo Security service to do MFA.