Duo is a multi-factor authentication (MFA) and access-security product, not a full identity provider. Duo knows who authenticated to which application and how strongly, but it is not the system of record for those applications’ entitlements. Access edges below reflect demonstrated authentication activity, not a granted entitlement - see Known limitations.
What Oleria discovers
Once connected, Oleria continuously discovers and maps the following from your Duo Security account:- Users - every end user in the Duo directory, including directory-synced users from Active Directory, Azure AD, Google Workspace, or OpenLDAP.
- Administrators - every administrator of the Duo Admin Panel, a separate principal class from end users, along with their administrator role.
- Integration credentials - non-human (NHI) principals such as the Admin API application itself, which holds tenant-wide authority.
- Groups - Duo groups and each user’s group memberships.
- Protected applications - every application integration registered in Duo (the resources users authenticate against).
- Authentication activity - authentication log events, including successful, failed, and fraud-flagged (suspicious) logins, for the last 180 days on paid editions.
Prerequisites
- A paid or trial Duo edition. Duo’s free/Personal edition does not include the Admin API.
- Duo Administrator access, to create an Admin API application.
Create a dedicated Admin API application for this integration rather than reusing employee credentials, to ensure continuity if the employee who provisioned it leaves or changes roles.
Create an Admin API application in Duo
1
Open Applications in the Duo Admin Panel
Log in to the Duo Admin Panel as an administrator, navigate to Applications -> Protect an Application, and search for Admin API.
2
Grant permissions
Select Protect to create the Admin API application, then grant it the following permissions:Also grant Grant resource write if you want Oleria to perform governance actions (disabling/enabling users, adding/removing group membership) on this integration:
- Grant resource read
- Grant administrators read
- Grant read log
These three read permissions cover everything Oleria discovers.
3
Copy the credentials
From the application’s details page, copy the Integration key, Secret key, and API hostname (shown as
api-XXXXXXXX.duosecurity.com).Connect Duo Security to Oleria
1
Open the integration
Log in to your Oleria workspace, navigate to Integrations, and select Duo Security.
2
Complete the connection form
Fill in the connection form with the credentials from the Admin API application:
3
Authenticate
Select Authenticate to validate and save the integration. Oleria checks the credentials against Duo before saving.
4
Verify the connection
Verify the Duo Security integration status from the connected integrations page. After the first sync completes, you can review the discovered users, administrators, groups, and applications in your Oleria workspace.
Governance actions
Beyond discovery, Oleria can act on Duo access to remediate risk. Governance actions require the Admin API application to include the Grant resource write permission (see setup above).Known limitations
- Access is observed, not entitled. Duo has no per-user, per-application assignment record - access is decided by policy evaluation at authentication time, and Duo’s Policy API is not public. The only API-observable evidence of access is a successful authentication event, so access edges carry demonstrated-access semantics: coverage is bounded by log retention and actual usage, and an edge cannot be retracted when entitlement is revoked, only aged out.
- No per-application entitlement API. There is no Duo API to grant or revoke a specific user’s access to a specific protected application, so that action isn’t offered from Oleria. User-level deprovisioning and group-membership management, listed above, are supported.
- Directory-synced users are read-only. A user synced from Active Directory, Azure AD, Google Workspace, or OpenLDAP is managed by that directory - any change to such a user reverts on the next directory sync. Oleria flags these accounts so remediation isn’t attempted against them.
- Administrator roles may show as a single “Administrator” value. Duo does not publicly document the exact field name or values for administrator roles. Where the specific role can’t be resolved, Oleria reports a single generic “Administrator” role rather than guessing.
- Missing “Grant administrators - Read” permission degrades visibly. If the Admin API application lacks this permission, Oleria still syncs but represents the unenumerated administrator population as a single placeholder group rather than omitting it silently.
- Bypass codes, per-integration API scopes, administrative units, and MSP subaccounts are not synced. Each MSP child account requires its own separate Oleria connection.
- Audit logs - authentication activity has a 180-day retention window on paid editions. The separate Duo administrator action log (changes made in the Admin Panel itself) is not synced as a second activity stream.

