Duo Security Review 2026

Affiliate disclosure: This article contains affiliate links. If you click a link and make a purchase, we may earn a commission at no extra cost to you. Our editorial recommendations are never influenced by commissions — read our full disclosure policy.
Duo Security
Cisco Duo is an access-security platform, not just an authenticator app: it verifies the user with a second factor and can also check the device's security posture before granting access. Cisco lists four tiers as of August 2026 — Free ($0, up to 10 users), Essentials ($3/user/mo), Advantage ($6) and Premier ($9). The catch is that standard Duo Push, the default, is the weakest method Duo offers, and full device-health checking requires Advantage or above.
Best for
Organisations that need MFA plus single sign-on without a long IAM implementation
Not for
Individuals — a standalone authenticator app or a hardware key is the right tool
Prices verified April 2026. Always confirm directly with provider.
Pros
- Free tier covers up to 10 users with strong MFA and integrations at no cost (Cisco pricing page, August 2026)
- Single sign-on, Trusted Endpoints and unlimited applications start at $3/user/month on Essentials
- Verified Duo Push (number matching) is classified as fatigue-resistant in Cisco's own authentication-methods guide
- Supports genuinely phishing-resistant methods: FIDO2 security keys and platform authenticators such as Touch ID, Face ID and Windows Hello
- Duo Desktop can require firewall, disk encryption and a system password before granting access
- Duo Directory provides a built-in user store, so no separate identity platform is needed to start
Cons
- Standard Duo Push is the out-of-the-box default, and Cisco states it "does not protect against phishing proxy attacks"
- Device health checks need Advantage or Premier — Essentials can only require that Duo Desktop is installed, with no health-check options
- Security-agent (antivirus) verification is Premier only, at $9/user/month
- Cisco sells licences in blocks of 10 below 100 users, so a 12-person team buys 20 seats
- There is no numeric device health score to work towards — posture is binary pass/fail
- Built for organisations; individuals do not need it

Duo Security is Cisco's cloud multi-factor authentication and device-trust platform. It sits in front of your applications, verifies the user with a second factor — most often a push notification to the Duo Mobile app — and can additionally check whether the device being used meets your security requirements before letting the session through. Cisco lists four tiers as of August 2026: Duo Free ($0, up to 10 users), Essentials ($3/user/month), Advantage ($6) and Premier ($9).
This review is for the person deciding whether to deploy Duo. It is based on Cisco's published documentation and pricing, Duo's authentication-methods security guide and NIST's authentication standard — not on first-hand deployment. This site has no commercial relationship with Cisco and earns nothing from this page.
What Duo Security is, and whether a "Secured by Duo" prompt is legitimate
Duo is a cloud-delivered access security product owned by Cisco, which completed its acquisition on 1 October 2018 for $2.35 billion in cash and assumed equity awards. What separates it from a plain authenticator app is the second check: an authenticator app proves you hold a secret, while Duo can additionally require that the laptop in your hands has its disk encrypted and its firewall switched on.
Duo is a mainstream enterprise product and duosecurity.com is its genuine domain — worth stating plainly, because Duo prompts arrive unannounced at employees and students who have never heard of the company. A page reading "Secured by Duo" is the standard Duo prompt, shown because an organisation you already have an account with has placed Duo in front of its login. It is not a phishing page in itself. It is, however, recognisable enough to be worth imitating, so the usual habit applies: check the domain in the address bar, and never approve a request you did not start.
Duo tiers and pricing, as of August 2026
From Cisco Duo's own pricing page, per user per month. Enterprise pricing is frequently negotiated at volume — confirm before budgeting.
- Duo Free — $0. Up to 10 users, strong MFA, integrations, free authenticator app.
- Duo Essentials — $3/user/month. Adds Duo Directory, phishing-resistant MFA, complete passwordless authentication, single sign-on, Trusted Endpoints and unlimited applications.
- Duo Advantage — $6/user/month. Adds Cisco Identity Intelligence (cross-identity visibility, ISPM and ITDR), Duo Passport, session theft protection, Active Directory Defense and Risk-Based Authentication.
- Duo Premier — $9/user/month. Adds VPN-less remote access to private resources and complete device trust with an endpoint protection check.
One licensing detail catches small buyers out. Cisco states that "for under 100 users, Duo licenses are purchased in increments of 10. For over 100 users, Duo licenses are purchased in increments of 25." A twelve-person company buys twenty seats.
The free tier is unusually generous and unusually easy to misread. Ten users of real MFA at no cost is a serious offer for a micro-business, but it is MFA only — single sign-on, Trusted Endpoints and any form of device health begin at Essentials. If device trust is why you are looking at Duo, the free tier does not do the thing you came for.
What is the Duo Security "health score"?
Duo does not publish a numeric health score. If you are searching for one, you will not find it, and that is a design decision rather than a missing feature. Duo's device posture model is binary pass/fail. A device either satisfies the checks you have configured or it is blocked. There is no 0–100 rating, no letter grade and no dashboard number to improve.
What people are almost always looking for is the Device Health application, now branded Duo Desktop — the agent Duo installs on an endpoint to inspect its security posture at the moment of authentication. Per Cisco's device health documentation, it checks:
- Firewall enabled — blocks access if the firewall is disabled.
- Disk encryption — FileVault on macOS, BitLocker on Windows, LUKS on Linux; blocks access if disabled.
- System password set — blocks access if no password is configured.
- Security agent installed and running — verifies the presence of an antivirus or anti-malware product. This check is Premier only.
It runs on Windows, macOS 12 through 26 and mainstream Linux distributions. ChromeOS has no Duo Desktop support; device health there requires the Chrome Enterprise browser data source. Tier availability is the part administrators most often get wrong. On Essentials you can require that Duo Desktop is installed, but Cisco's documentation states there are no device health check options at that tier. The actual checks are Advantage and Premier, and security-agent verification is Premier only.
Just as important is what Duo Desktop does not check. It is a posture gate, not an endpoint protection product. It does not scan for malware, detect intrusions, inspect files, or tell you whether a device is currently compromised. It confirms that a handful of configuration controls are switched on at the moment of login. A fully patched machine with its firewall enabled and its disk encrypted can still be running an infostealer, and Duo Desktop will wave it through. Reading a Duo pass as evidence of a clean endpoint is a category error: it is evidence of a compliant configuration, which is a much smaller claim.
Two related controls are worth separating. Trusted Endpoints (Essentials and above) classifies devices as managed or unmanaged and lets policy require trusted status — again binary. Risk-Based Authentication, the default on Advantage and Premier, does perform genuine analysis, examining IP and device patterns to either suppress a prompt or demand one when anomalous access is detected. Even there, the output is a decision, not a published score.
Push notifications, and why push fatigue is the thing to plan for
Duo's signature experience is Duo Push: you attempt a login, your phone buzzes, you tap approve. Duo Mobile supports push, biometrics and time-based one-time passcodes, runs on iOS and Android including tablets and many smartwatches, and can also hold third-party TOTP accounts.
Push is better than SMS. It is also the origin of the most important weakness on this page. In a push fatigue attack, someone who already holds a valid password triggers login attempt after login attempt, each one sending a push to the real user's phone, until at two in the morning the user taps approve to make it stop. Duo's own documentation names the variants: push harassment, "multiple successive push notifications to bother a user into accepting a push for a fraudulent login attempt," and push fatigue, where "constant MFA means users pay less attention to the details of their login."
Duo's answer is Verified Duo Push, or number matching: the login screen displays a code the user must type into Duo Mobile to approve, and an attacker who cannot see the victim's screen cannot supply it. Cisco's authentication methods security guide classifies Verified Duo Push and Duo Desktop authentication as fatigue-resistant — and says plainly of the default that "standard Duo Push does not protect against phishing proxy attacks."
Fatigue-resistant is not the same as phishing-resistant. Cisco reserves that label, citing NIST SP 800-63B-4, for methods with a cryptographic binding between the authentication and the site being accessed: platform authenticators (Touch ID, Face ID, Windows Hello), roaming FIDO2 security keys, and Duo Mobile push with Bluetooth proximity verification. NIST is blunter — out-of-band authentication, the category push belongs to, "is not phishing-resistant." SMS and OTP tokens sit lower still, with Cisco flagging SMS exposure to SIM swapping, number porting and SS7 interception.
The practical consequence: standard push is the weakest configuration Duo offers, and it is the one you get if you change nothing. Turn on Verified Duo Push at minimum, and move privileged accounts to FIDO2 keys — see our YubiKey review for that hardware, and our comparison of 2FA apps for how Duo Mobile sits against the consumer alternatives.
Who Duo actually suits
Duo's strongest fit is organisations between roughly ten and a few hundred users, where Essentials delivers SSO and unlimited applications without the professional-services engagement enterprise IAM platforms usually demand. Below ten users, Duo Free is close to unbeatable. Above that, Duo competes credibly where Cisco is already embedded, though buying Advantage alongside an existing IAM suite can mean paying twice for risk-based authentication. In every band the hard part is the same, and it is not technical — enrolment resistance, and the account-recovery process for lost devices, which is where MFA deployments most often break.
Individuals do not need Duo. Start with two-factor authentication generally, read how 2FA actually works, and pair it with a password manager — MFA does not fix password reuse, and the two controls solve different problems. For the closest consumer equivalent of the Duo Mobile experience, see the Microsoft Authenticator review.
Verdict
Cisco Duo is a mature access-security platform with a genuinely useful free tier and device-posture controls that go further than an authenticator app can — a reasonable default for small and mid-sized organisations needing MFA and SSO without a long implementation. The reservations are specific: the default push method is the weakest configuration in the product, Verified Duo Push should be treated as mandatory rather than optional, and the capabilities many buyers assume are included — full device health, risk-based authentication, identity analytics — sit at Advantage and above. Price Duo at the tier that contains the feature you are actually buying, not at $3.
Sources checked 1 August 2026: Cisco Duo pricing (duo.com/pricing), Duo Desktop device health documentation (duo.com/docs/device-health), Duo Authentication Methods Security Guide (duo.com/docs/authentication-methods-security-guide), Duo policy documentation (duo.com/docs/policy), the Duo Mobile product page, Duo's Verified Duo Push blog post, Cisco Investor Relations "Cisco Completes Acquisition of Duo Security" (1 October 2018), and NIST SP 800-63B (26 August 2025). Cisco Duo is not an affiliate partner of this site and no commission is earned from this page.
Reviewed by NorwegianSpark Editorial — written with AI assistance and reviewed by the NorwegianSpark SA editorial team · How we review


