Configure Cisco Duo for Arctic Wolf Active Response
With the Active Response service, Arctic Wolf® can perform identity-based response actions in your network using Cisco Duo®.
Cisco Duo supports these response actions:
- Disable/Enable a user
Note:
- Disabling a user also closes the user session.
- Arctic Wolf cannot take this action on users who are managed by directory sync processes.
- Add/Remove a user from a security group
For more information, see Response action descriptions.
Note:
Configure this integration with your primary identity provider in a cloud-based environment. Arctic Wolf does not support hybrid or on-premises environments for identity-based response actions.
These resources are required:
-
A Duo Premier, Duo Advantage, or Duo Essentials plan with Admin API access.
-
Administrator permissions and the Owner role for the Cisco Duo environment that you are configuring.
- Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.
Configure the Admin API for Duo response actions
Configure the Auth API for Duo response actions
Provide Cisco Duo Active Response credentials to Arctic Wolf
Note: If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After a polling failure, Arctic Wolf can't perform actions until the updated credentials are provided.