What is our primary use case?
Our primary use case is for two-factor authentication. We also use the solution to secure Microsoft Remote Desktop, VPN, and SSH connections.
We deployed the product primarily to address security concerns, for example, implementing a more secure security posture using Duo Security.
My initial deployment of the product at a previous employer was across multiple environments and business units. We were primarily an active directory shop using Windows servers and desktops and Wise desktops, all of which utilized Duo Security as their two-factor solution.
In my current environment, the tool is implemented in different forms, on-premise and in the cloud. We deploy it everywhere.
How has it helped my organization?
Duo Security has been utilized in multiple organizations I've worked for, and it simplifies connecting securely via VPN, Microsoft Remote Desktop, and SSH.
What is most valuable?
The app has greater stability than rival solutions such as Google Authenticator, and Duo Push authentication is a valuable feature.
The product worked to establish trust for as long as I've used it. It's a more functional solution than some competitors, which I discovered during the POC process. I think that Duo Security considering all resources to be external is one of the reasons why they are at the top of their field.
Duo Security simplified establishing trusted connections, making it easier to implement distributed network solutions. I've always found it to be a good part of a layered defense strategy.
Most of the end users when I was responsible for implementation, didn't quite understand the value of the solution until it was demonstrated.
The tool does provide single-pane-of-glass management in my experience. I haven't implemented the solution for years, but I'm a user in my personal and professional life. Therefore, I can say that feature is essential in making Duo Security one of the critical steps in a defense-in-depth strategy.
I never had any problems maintaining network connectivity, and it always performs well.
Based on the logging I have seen Duo Security use, I would say their solution does help with threat remediation. It is an integral part of the defense strategy.
A robust two-factor authentication solution is a massive part of a proper defense strategy, and having Duo makes it easier to implement and manage that two-factor solution.
What needs improvement?
I would like to see some features simplified, such as securing, configuring, and implementing Microsoft Remote Desktop. Other than that, the solution was rock solid throughout my time administering it.
For how long have I used the solution?
I have been using the solution for six years.
What do I think about the stability of the solution?
The solution is very stable, I've never seen it go down.
What do I think about the scalability of the solution?
The product is incredibly scalable.
How are customer service and support?
I had to contact technical support on a few occasions, and my problem was always resolved, but it took some time and work to reach a workable solution. My experience with them is primarily positive, but there is room for improvement.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
At the job in which I carried out the POC for the solution, we used physical RSA tokens, and I have been at locations that use HID tokens. In my opinion, the soft token solution is far better; it's more user-friendly, and staff can utilize the strategy more efficiently, effectively, and, unfortunately for RSA, more securely than the physical tokens offer.
How was the initial setup?
The basic deployment is very straightforward, though some Microsoft Remote Desktop support elements were a little more complicated. Primarily in getting the correct values and additional resources required for the deployment.
I wasn't involved in the deployment at my current company. At my previous employer, I did the POC and the initial training for our help desk groups.
What about the implementation team?
I carried out the implementation myself; I was responsible for maintaining all of the integration points and training the help desk team members to support the product.
What was our ROI?
It's hard to precisely measure an ROI for security solutions, but I would say it provides a return.
What's my experience with pricing, setup cost, and licensing?
I haven't seen any information on the pricing in four years, so I can't comment on that.
Which other solutions did I evaluate?
We tested a SecureAuth solution that didn't meet our security standards. We wanted to try RSA Authentication Manager, but that was more complex for users, so we decided to go with Duo Security.
What other advice do I have?
I would rate this solution an eight out of ten.
When I carried out the POC for Duo Security at my former employer, I pitched it to them because it simplifies the login process and has excellent notifications. Physical tokens can be hard to read, especially for admins and staff trying to remediate problems late at night. We wanted a solution that was easy to set up and configure, and that is what we got; being a cloud-based solution, Duo Security is much easier to manage. We don't need to worry about managing, upgrading, and configuring much on our side; that's all handled in the cloud.
The first company I mentioned working for was based in Ann Arbor, and Duo Security is or was based there too. I had personal relationships with several team members and recognized their product's value.
The solution improved trust models within our organization, significantly changing how people view connecting to the network. I don't think that it has had an impact on employee morale.
Disclosure: I am a real user, and this review is based on my own experience and opinions.