Duo Push verification for your MSP help desk
For clients standardized on Duo, Mizo's End User Verification Agent sends a Duo Push to the requester's enrolled device before a password reset, MFA change or access request goes any further.
- Status
- Live · native integration
- Connection
- Duo API application, configured per client
- Works in
- ConnectWise PSA · Autotask · HaloPSA
- Agents
- End User Verification
About Duo: Duo (Cisco Duo) is a multi-factor authentication and access security platform; Duo Push sends an approve-or-deny prompt to the user's enrolled device.
What Mizo does with Duo
Help desks are a favorite social engineering target. Duo turns “the caller sounded legitimate” into proof.
Duo Push before sensitive changes
Password resets, MFA re-enrollment and access requests wait for the requester to approve a Duo Push on the device already enrolled for them.
Your existing Duo setup, unchanged
Verification uses the enrollment your client already has in Duo. No new app for end users, no new enrollment campaign.
Mixed Duo and Microsoft 365 clients
Choose the method per client: Duo Push where Duo is the standard, Microsoft Authenticator where it isn't. One verification process across your book.
Proof on the ticket
Method, result and timestamp are written to the PSA ticket, ready for a client review, an auditor or a cyber insurance questionnaire.
How to connect Duo
Mizo runs in recommendation mode first, writing its reasoning to each ticket, and moves to autonomous handling only where you allow it.
Create a Duo application for Mizo
In the client's Duo Admin Panel, create an API application for Mizo. We walk you through it during onboarding.
Pick the requests that need verification
Decide per client which ticket types require a Duo Push, such as password resets, MFA changes or new access.
Start in recommendation mode
Mizo records the verification result and its reasoning on the ticket while your technicians stay in control.
Mizo and Duo: common questions
Which Duo factor does Mizo use?
Duo Push, sent to the device already enrolled for the requester. Mizo never uses a phone number or address provided in the ticket as the verification channel.
What if the requester isn't enrolled in Duo?
Depending on what you configure for that client, Mizo can use a Microsoft 365 Authenticator push or a one-time verification link instead, or flag the ticket for a technician.
Can different clients use different Duo accounts?
Yes. Verification is configured per client, so each client's own Duo setup is used for their users.
Where is the verification recorded?
On the ticket in ConnectWise PSA, Autotask or HaloPSA, with the method used, the outcome and the time.
Agents and pages that work with Duo
End User Verification Agent
Proves who is behind a ticket before any account change.
Mizo for Microsoft 365
End-user verification through your clients' tenants.
Agentic L1 for MSPs
Automating password resets, access requests and L1 work.
Phone Agent
Answers calls, matches the caller and opens a complete ticket.