Cisco Duo — a login asks a question first

Every Duo session starts the same way: a system asks whether the person logging in is really them, before it asks anything else.

This is what that question looks like.

Most break-ins don't involve any hacking at all — they just log in with a stolen or guessed password. This one extra step is what stops that.

Duo Mobile Login request
Someone is signing in as you.
This is what an attacker sees — the login goes nowhere.
Bengaluru · Chrome on Windows · just now
Approved
Here's what just happened…

Click Approve to see what happens behind the scenes — or try Deny first.

What actually happened behind the scenes

  1. 1

    The moment you tap Approve, Duo quietly asks your phone: "is this really you?"

  2. 2

    Your phone answers using something it already knows — a private detail set up only between it and your account, that no one else's phone has.

  3. 3

    Duo compares that answer to what it has on file. If it matches your device, it trusts the login.

  4. 4

    You're let in. If you tap Deny instead, that whole exchange never happens — and the login is stopped cold.

How the second factor shows up

Duo doesn't insist on one method. Depending on what's set up, the check can arrive as a push approval in the Duo Mobile app like the one above, a rotating one-time passcode typed in by hand, a physical security key, the device's own fingerprint or face unlock, or a phone callback that asks for a key-press to confirm.

What it's usually put in front of

Most deployments gate one of three doors: a VPN or remote-desktop session, a single sign-on layer sitting in front of Microsoft 365, Google Workspace or other everyday cloud apps, or an admin panel that shouldn't be one password away from anyone who finds it. Duo also checks the device itself — is it up to date, is its storage encrypted, has it been tampered with — before it lets the session through, not just the person.

Core capabilities

01

Multi-Factor Authentication

Protect logins with a push notification, passcode, security key, or biometric — not just a password.

02

Phishing-Resistant MFA

Security keys and built-in device unlock methods for logins that fake websites can't trick.

03

Single Sign-On

One login screen gets people into all their everyday cloud apps — no separate password for each.

04

Passwordless

Sign in with a fingerprint, face, or key instead of typing a password at all.

05

Device Trust

Checks that the phone or laptop signing in is a known, healthy device before letting it through.

06

Adaptive Access

Learns what normal looks like for your team, and asks extra questions when something doesn't match.

07

Duo Directory

Can hold everyone's accounts on its own, or plug into a directory the business already uses.

08

Remote Access

Protects VPN connections and remote logins the same way it protects everyday apps.

09

Identity Security

On higher plans, keeps an eye on logins across the whole business — not just one at a time.

Where this tends to land

Duo shows up most in businesses that need real MFA without ripping out whatever already manages logins and accounts — it adds a layer on top instead of replacing it. That's also why it's a common first step toward stronger security overall: it's the simplest way to stop assuming a correct password means the right person is signing in.