Integration

Works with Cisco Duo

Bring your own Duo. Your staff get the same Duo push or sign-in they use for everything else at work — and every customer an MSP manages can use its own Duo tenant.

Duo MFA

After someone signs in with a password, an emailed link or Google, Duo's Universal Prompt asks them to approve — push, Verified Push, passcode, or a security key.

Duo SSO

Duo becomes the front door. People type their work email, choose Continue with SSO, and sign in through Duo with the identity they already have — Active Directory or Microsoft Entra ID behind it.

Per customer, for MSPs

Each company you manage connects its own Duo tenant — typically the customer's subaccount under your Duo MSP account. Your own staff keep signing in your way.

How it fits together

Sign-in settings live on each customer, not on the MSP above it. An MSP's rules for its own technicians don't leak onto its customers' front desks — but an MSP can set a minimum every customer must meet, such as requiring two-factor. A customer can be stricter than that minimum, never looser.

Two-factor is satisfied by Duo MFA, by signing in through Duo SSO (Duo already did it), by a passkey, or by an authenticator app. Passkeys work alongside Duo and count as two-factor on their own.

Set up Duo MFA

You need to be an administrator in the customer's Duo account, and an owner of that customer in GuestPass (or on the MSP team that manages it).

1

Create a Web SDK application in Duo

In the Duo Admin Panel: Applications → Protect an Application, search for Web SDK, and choose Protect. Give it a name your staff will recognise in the prompt, such as “GuestPass”.
2

Copy three values

From that application's page: the Client ID, the Client secret, and the API hostname (it looks like api-xxxxxxxx.duosecurity.com). Keep the secret somewhere safe — Duo only shows it in full on this page.
3

Paste them into GuestPass

In GuestPass open the customer's company page → Sign-in & securityDuo MFA. GuestPass runs Duo's health check before saving anything, and stores the secret encrypted. It is never shown again.
4

Pick the username format

Duo matches people by username. If your Duo users are named by email address, leave it on full email. If they come from Active Directory as short names (jane rather than jane@company.com), choose just the part before the @. The wrong choice makes Duo treat enrolled people as strangers.
People must be enrolled in Duo first. The prompt can only approve someone Duo already knows. Enrol staff in Duo before switching this on, or allow self-enrolment on the Duo application's policy.

Set up Duo SSO

Duo SSO needs an authentication source configured in Duo first — Active Directory, or a SAML identity provider such as Microsoft Entra ID. That's set up once in Duo under Single Sign-On; it isn't a GuestPass step.

1

Create a Generic OIDC Relying Party

In the Duo Admin Panel: Applications → Protect an Application, search for Generic OIDC Relying Party, and choose Protect.
2

Add GuestPass's redirect URL

Under Sign-In Redirect URLs, add exactly: https://guestpass.simple-technologies.net/auth/sso/callback
3

Turn on the email scope

Under Scopes, make sure email (and profile) are enabled. GuestPass checks the email address Duo sends against the domains the customer has claimed — without it, sign-in is refused.
4

Paste the values into GuestPass

On the customer's company page → Sign-in & securityDuo SSO: the Issuer, Client ID and Client secret from Duo's application page, plus the email domain(s) that should sign in this way. GuestPass fetches the issuer's configuration before saving, so a typo is caught immediately.
5

Switch it on

Tick Single sign-on is on. Staff then use Continue with SSO on the sign-in page. You can also send them the customer's direct sign-in link, shown under the settings.
Why the domain list matters. An identity provider can vouch for any address. GuestPass only accepts addresses in the domains a customer has claimed, only lets an existing account sign in if it already belongs to that customer, and lets each domain be claimed by one customer only. That's what stops one company's identity provider signing someone into another company's account.

Questions

Do I need Duo MFA and Duo SSO?

No — pick one. Duo SSO already includes Duo's authentication, so there's no second prompt after it. Duo MFA is the simpler option when a customer doesn't have Duo SSO set up.

Which Duo edition do I need?

Duo MFA works on every Duo edition. Duo SSO is included in Duo's paid editions — check your plan with Cisco or your Duo reseller.

What happens if Duo is down?

People who have a passkey or an authenticator app enrolled in GuestPass can still sign in with those. We recommend every administrator adds a passkey as a backup.

Can a customer use Entra ID or Okta instead?

Yes. The SSO settings work with any OpenID Connect provider — Duo is simply the one we've documented step by step.

Already on Duo?

Connect a Duo tenant in a few minutes — the credentials are checked with Duo before anything is saved.

Cisco and Duo are trademarks or registered trademarks of Cisco Systems, Inc. GuestPass Cloud is an independent product and is not affiliated with or endorsed by Cisco.

Products · Pricing · Blog · Works with Duo · Legal · Security · What's new · Sign in

Built by Simple Technologies · simple-technologies.com · support@simple-technologies.com

UniFi® and Ubiquiti® are trademarks of Ubiquiti Inc. GuestPass Cloud is an independent product, not affiliated with or endorsed by Ubiquiti Inc.