Secure Splunk Phantom using two factor authentication
Duo is integrated with Splunk Phantom to enable two factor authentication. When enabled, two factor authentication applies to all local Splunk Phantom users. Splunk Phantom sets each user's email address as the Duo username. If an email address is not available, then the username is used.
Perform the following steps to enable two factor authentication in Splunk Phantom:
- Create a web SDK application in the Duo administrative interface. Refer to your Duo documentation for more information.
- When the web SDK application integration is ready, record the following information to provide to Splunk Phantom:
- Integration key
- Secret key
- API hostname
- In Splunk Phantom, from the main menu, select Administration.
- Select User Management > Two Factor.
- Check the Enable Duo Two Factor Authentication checkbox.
- Provide the information you collected in the Integration Key, Secret Key, and API Hostname fields.
- Click Test Duo Connectivity to verify the keys and hostname are correct.
- Click Save Changes.
Disable two factor authentication for the default admin account as a failsafe mechanism so there is at least one account that can log into Splunk Phantom to administer Duo settings if the integration breaks.
With two factor authentication enabled, two new fields appear in the Edit User page:
- Two Factor Authentication. Set this field to Duo to enable two factor authentication. Select None to disable two factor authentication.
- Duo Username. Use this field to make sure the Splunk Phantom and Duo usernames match. For example, a user's Splunk Phantom username is jsmith but his Duo username is email@example.com. In this case, set the Duo username to firstname.lastname@example.org so the correct Duo user is used when logging in to Splunk Phantom.
Configure single sign-on authentication for Splunk Phantom
Configure role based access control inside Splunk Phantom apps
This documentation applies to the following versions of Splunk® Phantom: 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7