Every Duo session starts the same way: a system asks whether the person logging in is really them, before it asks anything else.
This is what that question looks like.
Most break-ins don't involve any hacking at all — they just log in with a stolen or guessed password. This one extra step is what stops that.
Click Approve to see what happens behind the scenes — or try Deny first.
What actually happened behind the scenes
-
1
The moment you tap Approve, Duo quietly asks your phone: "is this really you?"
-
2
Your phone answers using something it already knows — a private detail set up only between it and your account, that no one else's phone has.
-
3
Duo compares that answer to what it has on file. If it matches your device, it trusts the login.
-
4
You're let in. If you tap Deny instead, that whole exchange never happens — and the login is stopped cold.
How the second factor shows up
Duo doesn't insist on one method. Depending on what's set up, the check can arrive as a push approval in the Duo Mobile app like the one above, a rotating one-time passcode typed in by hand, a physical security key, the device's own fingerprint or face unlock, or a phone callback that asks for a key-press to confirm.
What it's usually put in front of
Most deployments gate one of three doors: a VPN or remote-desktop session, a single sign-on layer sitting in front of Microsoft 365, Google Workspace or other everyday cloud apps, or an admin panel that shouldn't be one password away from anyone who finds it. Duo also checks the device itself — is it up to date, is its storage encrypted, has it been tampered with — before it lets the session through, not just the person.
Core capabilities
Multi-Factor Authentication
Protect logins with a push notification, passcode, security key, or biometric — not just a password.
Phishing-Resistant MFA
Security keys and built-in device unlock methods for logins that fake websites can't trick.
Single Sign-On
One login screen gets people into all their everyday cloud apps — no separate password for each.
Passwordless
Sign in with a fingerprint, face, or key instead of typing a password at all.
Device Trust
Checks that the phone or laptop signing in is a known, healthy device before letting it through.
Adaptive Access
Learns what normal looks like for your team, and asks extra questions when something doesn't match.
Duo Directory
Can hold everyone's accounts on its own, or plug into a directory the business already uses.
Remote Access
Protects VPN connections and remote logins the same way it protects everyday apps.
Identity Security
On higher plans, keeps an eye on logins across the whole business — not just one at a time.
Where this tends to land
Duo shows up most in businesses that need real MFA without ripping out whatever already manages logins and accounts — it adds a layer on top instead of replacing it. That's also why it's a common first step toward stronger security overall: it's the simplest way to stop assuming a correct password means the right person is signing in.