Duo Push Approvals
Users can now approve secret access requests and workflows using Duo push notifications. The push notification includes information, displayed on the user's screen, that helps the approver make the access decision.
Prerequisites
To use Duo push notifications:
- Duo must set up for Secret Server. See Duo Security Authentication.
- Duo user must be set up for Duo two-factor authentication. See Duo Security Authentication.
- The permission "Approve via DUO" must be granted to a role that is assigned to a group that includes all who will be approving requests via Duo. This allows enough flexibility so that those not wanting Duo push approvals can be configured to not receive them.
Assigning the Duo Approval Permission
To associate the permission with users:
-
Go to Access > Roles.
-
Click the Create Role button to create a new role. Name it "Duo Push Approver" or another name of your choosing.
-
Assign the Approve Via DUO Push permission to the new role.
-
Click the Save button.
-
If you choose to create a separate group for approvers, do this by navigating to Access > Groups.
-
Click the Create Group button to create a new group.
-
Add the desired users (chosen approvers) to that group.
You can also assign users to the group later. This method is a shortcut when creating a group. -
Click the Save button.
-
Go to the page for the newly created group.
-
Click the Roles tab.
-
Click the Edit Roles button.
-
click the Scope dropdown list to select Unassigned.
-
Click to select the DUO Push Approver role.
-
Click the Save button. Setup is now complete.