Bring your own Duo. Your staff get the same Duo push or sign-in they use for everything else at work — and every customer an MSP manages can use its own Duo tenant.
After someone signs in with a password, an emailed link or Google, Duo's Universal Prompt asks them to approve — push, Verified Push, passcode, or a security key.
Duo becomes the front door. People type their work email, choose Continue with SSO, and sign in through Duo with the identity they already have — Active Directory or Microsoft Entra ID behind it.
Each company you manage connects its own Duo tenant — typically the customer's subaccount under your Duo MSP account. Your own staff keep signing in your way.
Sign-in settings live on each customer, not on the MSP above it. An MSP's rules for its own technicians don't leak onto its customers' front desks — but an MSP can set a minimum every customer must meet, such as requiring two-factor. A customer can be stricter than that minimum, never looser.
Two-factor is satisfied by Duo MFA, by signing in through Duo SSO (Duo already did it), by a passkey, or by an authenticator app. Passkeys work alongside Duo and count as two-factor on their own.
You need to be an administrator in the customer's Duo account, and an owner of that customer in GuestPass (or on the MSP team that manages it).
api-xxxxxxxx.duosecurity.com). Keep the secret somewhere safe — Duo only shows it in full on this page.Duo SSO needs an authentication source configured in Duo first — Active Directory, or a SAML identity provider such as Microsoft Entra ID. That's set up once in Duo under Single Sign-On; it isn't a GuestPass step.
https://guestpass.simple-technologies.net/auth/sso/callbackNo — pick one. Duo SSO already includes Duo's authentication, so there's no second prompt after it. Duo MFA is the simpler option when a customer doesn't have Duo SSO set up.
Duo MFA works on every Duo edition. Duo SSO is included in Duo's paid editions — check your plan with Cisco or your Duo reseller.
People who have a passkey or an authenticator app enrolled in GuestPass can still sign in with those. We recommend every administrator adds a passkey as a backup.
Yes. The SSO settings work with any OpenID Connect provider — Duo is simply the one we've documented step by step.
Connect a Duo tenant in a few minutes — the credentials are checked with Duo before anything is saved.
Cisco and Duo are trademarks or registered trademarks of Cisco Systems, Inc. GuestPass Cloud is an independent product and is not affiliated with or endorsed by Cisco.
Products · Pricing · Blog · Works with Duo · Legal · Security · What's new · Sign in
Built by Simple Technologies · simple-technologies.com · support@simple-technologies.com
UniFi® and Ubiquiti® are trademarks of Ubiquiti Inc. GuestPass Cloud is an independent product, not affiliated with or endorsed by Ubiquiti Inc.