For details, see:
Secure Splunk SOAR (On-premises) using two factor authentication
This feature is deprecated. |
---|
The Duo two factor authentication feature is deprecated as of Splunk SOAR (On-premises) version 5.5.0. Although this feature continues to function, it might be removed in a future version.
|
Duo is integrated with Splunk SOAR (On-premises) to enable two factor authentication. When enabled, two factor authentication applies to all local Splunk SOAR (On-premises) users. Splunk SOAR (On-premises) sets each user's email address as the Duo username. If an email address is not available, then the username is used.
Perform the following steps to enable two factor authentication in Splunk SOAR (On-premises):
- Create a web SDK application in the Duo administrative interface. Refer to your Duo documentation for more information.
- When the web SDK application integration is ready, record the following information to provide to Splunk SOAR (On-premises):
- Integration key
- Secret key
- API hostname
- In Splunk SOAR (On-premises), from the Home menu, select Administration.
- Select User Management > Two Factor.
- Check the Enable Duo Two Factor Authentication checkbox.
- Provide the information you collected in the Integration Key, Secret Key, and API Hostname fields.
- Click Test Duo Connectivity to verify the keys and hostname are correct.
- Click Save Changes.
Disable two factor authentication for the default admin account as a failsafe mechanism so there is at least one account that can log in to administer Duo settings if the integration breaks.
With two factor authentication enabled, two new fields appear in the Edit User page:
- Two Factor Authentication. Set this field to Duo to enable two factor authentication. Select None to disable two factor authentication.
- Duo Username. Use this field to make sure the Splunk SOAR (On-premises) and Duo usernames match. For example, a user's Splunk SOAR (On-premises) username is jsmith but his Duo username is jsmith@splunk.com. In this case, set the Duo username to jsmith@splunk.com so the correct Duo user is used when logging in to Splunk SOAR (On-premises).
Configure single sign-on authentication for Splunk SOAR (On-premises) | Configure role based access control inside Splunk apps |
This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.5.0, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0
Feedback submitted, thanks!