---
title: Cisco Duo MFA Integration
slug: kronpam-reference-guide-3-5-0/cisco-duo-mfa-integration
description: Learn how to integrate Kron PAM with Cisco Duo in this step-by-step document. Discover various verification methods, including the use of the Duo Mobile app, and understand the essential parameters, like API key, URL, and integration key. Make necessary a
docTags: 
createdAt: 2022-07-31T18:30:25.000Z
---

For Kron PAM integration with Cisco Duo, users should log in to Cisco Duo with the email addresses defined in Kron PAM. The Username must match the information on Kron PAM. After logging in to the Duo portal, the token verification can be done through different verification methods.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/Zd82QanisjGZtDiK8kFL0_image.png" size="44" width="295" height="419" position="center" caption="Duo Verification Methods" showCaption="true"}

- To use the Duo verification method, users must download th&#x65;**&#x20;Duo Mobile** mobile app. Duo Mobile should be activated from the user portal settings area. Users must be added to the Duo portal. The Duo Mobile app should be activated on the devices.&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/Pbf0eqTgzt2GRG5P6lYI6_image.png" size="64" width="515" height="343" position="center" caption="Duo MFA Activation" showCaption="true"}

Kron PAM integrates with Cisco Duo via API, as long as certain parameters are defined in Kron PAM:

-  API key (the API key is created by Duo for each customer environment)
-  URL (the URL is unique for each customer environment)
-  Integration key (the integration key is created by Duo for each customer environment)

To adjust the Duo Integration Settings:

1. Navigate to **Administration** > **System Configuration Manager**.
2. Set the following parameters:
   mfa.provider=duo (default: internal)
   mfa.external.provider.duo.api.hostname=XXX&#x20;
   mfa.external.provider.duo.integration.key=XXX&#x20;
   mfa.external.provider.duo.secret.key=XXX (encrypted)
   mfa.external.provider.duo.factor = \{passcode, sms, push}
   mfa.external.provider.duo.push.type = "the message which will be shown in the push notification on mobile device" default: Kron PAM **MFA Request**

- With Duo enabled, the token can be sent in different ways:

| **Passcode** | Token in the mobile app is used.                       |
| ------------ | ------------------------------------------------------ |
| **SMS**      | The token is sent by SMS.                              |
| **Push**     | Verification is confirmed from the mobile application. |

