Duo Security

@duosec.bsky.social

📱 | Duo.com 🔑 | Duo is now a part of @Cisco.com 💚 | Human-Centered Security Solutions

The least-privilege principle has guided access management for decades. Now it needs to evolve for agents. Autonomous systems work best when their access matches their purpose. Good agentic design isn't about restriction, it's about precision: cs.co/63323BE7R6l

Behind every secure login, every seamless MFA prompt, every 2 a.m. fire drill—there's a SysAdmin making sure the business never notices a thing. Today, we notice. Happy SysAdmin Day from Duo Security. We know exactly how hard you work to keep access secure and systems running.

SysAdmin Day

50 million rides a month means 50 million reasons to get security right. Lyft needed device visibility, strong access controls, and a path to zero trust. Here's how they consolidated MFA, MDM, and device trust without slowing anyone down: cs.co/63325BEIu2R

50 million rides a month means 50 million reasons to get security right.

An AI agent with access to corporate email was tricked into forwarding AWS credentials and a CRM export containing $1.28M in customer revenue data. Researchers found the weak point wasn't the model — it was overprivileged access and a lack of human oversight. cs.co/63323BEIuLV

An AI agent with access to corporate email was tricked into forwarding AWS credentials and a CRM export containing $1.28M in customer revenue data.

Your organization might have thousands of user accounts. Do you know which ones still have access to systems they shouldn't? IGA manages digital identities across their full lifecycle, keeping permissions aligned with roles, policies, & compliance requirements. Learn more: cs.co/63326BEIuIQ

Your organization might have thousands of user accounts. Do you know which ones still have access to systems they shouldn't?

"How do I get consistent identity controls when my agent infrastructure is all over the place?" Agents operate 24/7 across diverse gateways-without unified authorization, every deployment creates a blind spot. Your policies should travel with you. Learn more: cs.co/63325BEx8e7

"How do I get consistent identity controls when my agent infrastructure is all over the place?"

Fact or Fiction? Zero Trust only protects your network perimeter. Fiction: Zero Trust eliminates the idea of a perimeter entirely. Every user, device, and access request is treated as potentially hostile — whether it's coming from the office, home, or a café's Wi-Fi. cs.co/63326BEcXRk

We often think of phishing as a problem that happens before authentication. But that's only half the story. Security that stops at the login screen isn't full coverage. It's just the beginning. Here's what protecting the full authentication journey looks like: cs.co/63329BEcXux

We often think of phishing as a problem that happens before authentication.

Most identity breaches don't start with a sophisticated attack. They start with an undetected gap that nobody knew existed. Episode 4 of Duo's podcast explores how Cisco Identity Intelligence closes the gaps before they become breaches. cs.co/63323BEcXPN

A single breach can follow a student for life. In Texas, some academic and disciplinary records are kept permanently. IDEA Public Schools rethought their security posture to match the sensitivity of the data they protect. See how: cs.co/63320BEcXGK

A single breach can follow a student for life.

"We'd love to go passwordless, but we'd have to migrate hundreds of apps." We hear this a lot. Federating your domain to Duo leaves your Entra ID-connected apps exactly where they are. What changes: your users stop typing passwords. Learn how it works: cs.co/63321BEcX1D

"We'd love to go passwordless, but we'd have to migrate hundreds of apps."

Every hour your team spends managing authentication incidents is an hour not spent on real threats. Forrester found Duo reduced authentication-related incident response by 50% — giving security teams back the time and visibility to focus on what matters. cs.co/63320BEpUhr

The most exploited credential in security isn't a weak password. It's the idea that passwords are still acceptable. Passkeys eliminate the guessing, sharing, and phishing that make passwords a liability. Check out the PCMag article to learn more: cs.co/63320BEpUCC

The most exploited credential in security isn't a weak password. It's the idea that passwords are still acceptable.

Non-compliance isn't just a regulatory issue. It's a risk to your reputation, operations, & bottom line. The companies staying ahead treat compliance as a foundation, not an afterthought. Strong security & compliance should be accessible to everyone. Learn more: cs.co/63326BEpUCY

Non-compliance isn't just a regulatory issue.

When an employee leaves, how fast does their access actually disappear? Done well, user lifecycle management protects the business without slowing people down. Done manually, it introduces errors, delays, & orphaned accounts that attackers can exploit. Learn more: cs.co/63320BEpdJ6

When an employee leaves, how fast does their access actually disappear?

Duo Passport changes how authentication works. Instead of repeated logins that frustrate users & create risk, it verifies identity & device trust, then stays out of the way. Continuous security, zero interruptions, & fewer gaps for threats to slip through. cs.co/63320BEHZoA

Duo Passport

When the U.S. Open tees off, millions are watching, but behind the scenes there's an IT team making sure everything runs without a hitch. For the USGA, world-class golf means world-class IT. See how their team secures one of the most complex environments in sports: cs.co/63329BEBSWN

When the U.S. Open tees off, millions are watching, but behind the scenes there's an IT team making sure everything runs without a hitch

Duo Passport changes how authentication works. Instead of repeated logins that frustrate users & create risk, it verifies identity and device trust once, then stays out of the way. Continuous security, zero interruptions, & fewer gaps for threats to slip through. cs.co/63325BEBuTd

Duo Passport changes how authentication works. Instead of repeated logins that frustrate users & create risk

7,500+ faculty and staff, an open campus, & a help desk that couldn't afford to be overwhelmed. The University of Queensland needed MFA that people would actually use. They got it — SSO & VPN protected, fully enrolled in days, and barely a support ticket raised. cs.co/63329BD0C4V

7,500+ faculty and staff, an open campus, & a help desk that couldn't afford to be overwhelmed.

Attackers didn't break MFA last month. They went around it — four times. Stolen tokens, a breached identity agency, weaponized Apple notifications, & encrypted apps accessed without cracking a single cipher. The full breakdown is in our 1st monthly Identity Threat Brief: cs.co/63327BDLu2l

Attackers didn't break MFA last month. They went around it — four times.

The MSPs winning in 2026 are moving from "we deployed MFA" to "we continuously manage identity risk" — covering the full lifecycle from phishing-resistant authentication to identity threat detection and response. Find out what security-first identity looks like: cs.co/63322BDw98y

Find out what security-first identity looks like

What does your team do in the first 10 minutes of a cyberattack? If the answer isn't clear, that's a problem. A strong incident management policy gives your team a repeatable process before a breach becomes a crisis. Check out Duo's step-by-step guide: cs.co/63329BDwgfJ

What does your team do in the first 10 minutes of a cyberattack?