Duo for WordPress – Duo Universal Prompt – Duo Security

Connect and protect your employees, business partners and customers with identity-powered security.
image of a person typing on a laptop
Get the security features your business needs with a variety of plans at several price points.
Desktop and mobile access protection with basic reporting and secure single sign-on.
All Duo Small/Medium Business features, plus adaptive access policies, greater device visibility, plus advanced device insights and remote access solutions.
FedRamp authorized, end-to-end FIPS compliant, streamlined solutions.
Meet compliance objectives with our friction-free MFA.
Duo provides secure access to any application with a broad range of capabilities.
Minimize authentication fatigue.
Verify the identities of all users with MFA.
Provide secure access to on-premise applications.
Ensure all devices meet security standards.
Provide secure access to any app from a single dashboard.
Block or grant access based on users’ role, location, and more.
Duo’s security is customizable, easy to set up and simple to use, making it the perfect solution for a wide range of industries.
image of person on a mobile device
Duo provides secure access for a variety of industries, projects, and companies.

Whether you’re considering a big-picture security strategy like zero trust, or you want to address a specific threat like phishing attacks, Duo has you covered.
Stop sophisticated identity-based attacks while providing a seamless authentication experience.
This set of tools and policy controls ensures only the right users have access to applications and resources and under the right conditions.
A zero trust model establishes trust in users and devices through authentication and continuous monitoring.
Duo’s comprehensive access security sets the stage for user-friendly, password-free multi-factor authentication.
Secure your workforce against phishing attacks with strong multi-factor authentication, device trust and more.
Duo’s dynamic solution detects and responds to potential threat signals to secure trusted users and frustrate attackers.
With Duo, you can have both, in a platform that integrates across your entire ecosystem. Every user, every device, no exceptions.
image of two people on a mobile device
Duo delivers peace of mind with strong security and increased productivity at an unmatched value.
Reduce friction and automate processes so that end-users and administrators can focus their time on moving your business forward.
Duo continues to pioneer MFA-approaches that keep your business a step ahead of the next threat.
Our Risk-Based Authentication reduces the burden placed on users so they can verify their identity quickly and get back to the task at hand.
Close the gap on your security perimeter and bring every user and every device under one secure roof.
Duo provides secure access for a variety of industries, projects, and companies.
Click through our instant demos to explore Duo features.
Duo Security is part of Cisco Security — find out how we make global security resilience easier than ever!
Was this page helpful? Let us know how we can make it better.
Duo’s WordPress plugin enables two-factor authentication for WordPress logins, offering inline self-service enrollment and authentication with Duo Universal Prompt. The code is open-source and available on GitHub.

Support for the traditional Duo Prompt experience and Duo Prompt delivery via iframe ended on March 30, 2024.

See the update instructions for WordPress to update an existing deployment of the iframe-based WordPress software to the latest release. Authenticating once with the updated Duo software is a required step before you can enable the Duo Universal Prompt for your existing WordPress application.

Please visit the Duo Universal Prompt Update Guide for more information about the traditional Duo Prompt end of support.

Support for the traditional Duo Prompt experience and Duo Prompt delivery via iframe ended on March 30, 2024.
See the update instructions for WordPress to update an existing deployment of the iframe-based WordPress software to the latest release. Authenticating once with the updated Duo software is a required step before you can enable the Duo Universal Prompt for your existing WordPress application.
Please visit the Duo Universal Prompt Update Guide for more information about the traditional Duo Prompt end of support.
Previously, the Client ID was called the “Integration key” and the Client secret was called the “Secret key”.

Treat your secret key like a password

The security of your Duo application is tied to the security of your secret key (skey). Secure it as you would any sensitive credential. Don’t share it with unauthorized individuals or email it to anyone under any circumstances!

The security of your Duo application is tied to the security of your secret key (skey). Secure it as you would any sensitive credential. Don’t share it with unauthorized individuals or email it to anyone under any circumstances!

Duo Universal Prompt

The Duo Universal Prompt provides a simplified and accessible Duo login experience for web-based applications, offering a redesigned visual interface with security and usability enhancements.

Universal Prompt Traditional Prompt
 Duo Push in Universal Prompt  Duo Push in Traditional Prompt

Migration to Universal Prompt for your WordPress application is a three-step process:

  1. Install an update for the WordPress application, which implements a redirect to Duo during authentication to support the Universal Prompt.
  2. Authenticate with Duo 2FA using the updated application so that Duo makes the Universal Prompt activation setting available in the Admin Panel. This first authentication after updating shows the traditional Duo prompt in a redirect instead of an iframe.
  3. From the Duo Admin Panel, activate the Universal Prompt experience for users of that Duo WordPress application if the traditional prompt is still selected. Once activated, all users of the application see the Duo Universal Prompt in a redirect.

Before you activate the Universal Prompt for your application, it’s a good idea to read the Universal Prompt Update Guide for more information about the update process and the new login experience for users.
When you install the latest version of Duo for WordPress you’re ready to use the Universal Prompt. If you’re configuring WordPress now, proceed with the installation instructions in this document.
The “Universal Prompt” area of the application details page shows that this application is “Ready to activate”, with these activation control options:

  • Show traditional prompt: (Default) Your users experience Duo’s traditional prompt via redirect when logging in to this application.
  • Show new Universal Prompt: Your users experience the Universal Prompt via redirect when logging in to this application.

Universal Prompt Info - Application Ready for Universal Prompt
Duo for WordPress needs a software update installed to support the Universal Prompt. The “Universal Prompt” section of your existing WordPress application reflects this status as “Update required”. To update Duo for WordPress application to a newer version, follow the update directions below.
Universal Prompt Info - Update Required
Once a user authenticates to Duo for WordPress via the updated Duo plugin, the “Universal Prompt” section of the WordPress application page reflects this status as “Ready to activate”, with these activation control options:

  • Show traditional prompt: Your users experience Duo’s traditional prompt via redirect when logging in to this application.
  • Show new Universal Prompt: (Default) Your users experience the Universal Prompt via redirect when logging in to this application.

Universal Prompt Info - Application Ready for Universal Prompt
In addition, the “Integration key” and “Secret key” property labels for the application update to “Client ID” and “Client secret” respectively. The values for these properties remain the same.
Activation of the Universal Prompt is a per-application change. Activating it for one application does not change the login experience for your other Duo applications.
Enable the Universal Prompt experience by selecting Show new Universal Prompt, and then scrolling to the bottom of the page to click Save.
Once you activate the Universal Prompt, the application’s Universal Prompt status shows “Activation Complete” here and on the Universal Prompt Update Progress report.
Universal Prompt Info - Universal Prompt Activation Complete
Should you ever want to roll back to the traditional prompt, you can return to this setting and change it back to Show traditional prompt. However, this will still deliver the Duo prompt via redirect, not in an iframe. Keep in mind that support for the traditional Duo prompt ended for the majority of applications in March 2024.
Click the See Update Progress link to view the Universal Prompt Update Progress report. This report shows the update availability and migration progress for all your Duo applications. You can also activate the new prompt experience for multiple supported applications from the report page instead of visiting the individual details pages for each application.
To install and configure the Duo Universal plugin, proceed as follows:
Log in to your WordPress Dashboard as an administrator.
Navigate to PluginsAdd New in the left navigation bar. Then search for "Duo Security" and click Install Now for the Duo Universal plugin.
Click Activate Plugin after installing the Duo plugin:
Proceed to Configure the Duo Plugin.
To install the Duo Universal plugin without using the WordPress Plugin directory:
Download the Duo Universal plugin as a zipped package from WordPress.
In the WordPress console go to PluginsAdd New and click the Upload Plugin button.
Click Choose File and select the duo-universal.n.n.n.zip package you downloaded (where n.n.n reflects the actual plugin version). Click Install Now to upload Duo’s plugin to your WordPress site.
Click Activate Plugin after installing the Duo plugin:
Proceed to Configure the Duo Plugin.
After activation, click Settings to configure the plugin.
Copy your Client ID, Client secret, and API hostname from the Duo WordPress application you created earlier in the Duo Admin Panel and paste the values into WordPress.
(Optional) The "Failmode" setting determines plugin behavior if Duo’s authentication service becomes unreachable. Leave it set to open to allow users to log in if MFA is unavailable. Change to closed to deny all login attempts if there is a problem contacting the Duo service. Default: open.
Select which WordPress user roles need to authenticate using Duo. For example, you may only require those users with the "Administrator" role to use two-factor authentication, or require all roles to use two-factor.
To fully secure your WordPress site we recommend that you disable XML-RPC. However, this will prevent use of offline Weblog clients and the WordPress mobile app.
Click Save Changes to complete configuration.
To test your setup, log into WordPress using the hostname or fully-qualified domain name URL. Successful verification of your username and password redirects you to Duo. Complete Duo two-factor authentication when prompted and then you’ll return to WordPress to complete the login process.
To update an existing Duo Universal plugin, install the most recent version:
Log into your WordPress Dashboard as an administrator.
If a newer version of the Duo plugin exists then you’ll see a notification icon under both Home – Updates and Plugins. Click either one to view the available update.
WordPress lists the available plugin updates. Check the box next to the Duo Universal plugin to select it, and then click the Update Plugins button (if you clicked the Updates navigational link in step #2), or click the update now link in the Duo plugin description (if you clicked the Plugins navigational link in step #2).
WordPress updates the Duo plugin and reports status when complete.
There is no direct update path from the legacy Duo WordPress plugin to the Duo Universal WordPress plugin. To complete the migration:
If you are updating an existing Duo WordPress deployment to use the Universal Prompt, you will need to authenticate once using the updated Duo Universal plugin first before you can enable the Universal Prompt for WordPress in Duo.

Troubleshooting

Need some help? Take a look at our WordPress Knowledge Base articles or Community discussions. For further assistance, contact Support.
© 2024 Duo

source

Leave a Reply

Your email address will not be published. Required fields are marked *