---
title: "Configure Cisco Duo for AIM"
canonical: "https://docs.aryaka.com/space/KNOW/277381162/Configure%20Cisco%20Duo%20for%20AIM"
format: markdown
---
This document explains how to configure your Cisco Duo identity provider (IdP) to synchronize users and user groups between Duo and MyAryaka.  To edit or delete an existing configuration, see the  Manage Duo SAML  topic Some of the procedures described in this document are performed in the Duo administrator interface (known as the  Duo   Dashboard ). While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the Duo UI are beyond our control. Refer to the documentation provided by Cisco to ensure you have the most recent information. Prerequisites MyAryaka account with read and write access Cisco Duo administrator account Configure identity authentication using Duo SAML in MyAryaka Complete the procedure described in this section to add a Duo instance to your Aryaka Identity Management configuration and obtain SAML settings required for subsequent configuration. To configure identity authentication using Duo SAML in MyAryaka Go to MyAryaka at  https://my.aryaka.com/ . The MyAryaka Login page appears. Log in using your MyAryaka credentials. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Add  on the Enterprise’s Duo tile in the Available Identity Providers section. The Configure Enterprise’s Duo page appears and displays the following panes: SAML Identity and Provider Pre-configuration steps for SAML Duo SAML Details In the SAML Identity and Provider section, enter a name for this Duo instance in the Enterprise’s Duo Name field. Note that you can create multiple Duo instances. The fields in the Pre-configuration Steps for SAML section are automatically populated. These fields are required for the Duo SAML configuration described in step 4 in the next section. We recommend leaving this page open, as there are more configuration tasks that you must perform here after working in the Duo Dashboard, as described in the next section. Configure Aryaka as a Duo application Complete the procedure described in this section to configure SAML-based SSO and to create an application in Duo. To configure SAML SSO in Duo Log in to the Duo Dashboard as an administrator.  Click  Applications  >  Protect an Application  in the left navigation pane. The Protect an Application page appears with the application catalog displayed: Locate the Generic SAML Service Provider application in the catalog (you can use the Search field), and then click  Protect  in that row. The Service Provider page appears:   Configure the Service Provider application as follows: Accept the default setting—None (manual input)—in the Metadata Discovery field. Enter the service provider’s unique identifier in the Entity ID field, for example: https://aim.aryaka.com/realms/c2753. This information was obtained from MyAryaka in step 6 of the previous procedure. Enter the URL where this service provider application expects to receive the authorization token in the Assertion Consumer Service (ACS) URL field, for example: https://aim.aryaka.com/realms/c2753/broker/saml/endpoint. This information was obtained from MyAryaka in step 6 of the previous procedure.  Click  Save  to update the service provider application in Duo. Obtain SAML metadata from Duo Complete the procedure described in this section to obtain the metadata URL that is required to configure SAML in MyAryaka. To obtain the SAML metadata URL from Duo Log in to the Duo Dashboard as an administrator.  Click  Applications  >  ApplicationName  in the left navigation pane. The  ApplicationName  page appears:  Click  Copy  next to the URL in the Metadata URL Field. Configure SAML in MyAryaka Complete the procedure described in this section to configure SAML in MyAryaka. You must provide the metadata URL obtained in the previous procedure. To configure SAML in MyAryaka If it is not already open, navigate to the Configure Enterprise’s Duo page: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Add  on the Enterprise’s Duo tile in the Available Identity Providers section. The Configure Enterprise’s Duo page appears. Complete the following in the Duo SAML Details pane: Enter a name for this Duo instance in the Enterprise’s Duo Name field. Note that you can create multiple Duo instances. Click  Use URL , then paste the metadata URL that you copied in step 3 of the previous procedure. Enter the user domain that must be redirected to this instance of Duo in the IdP Redirect Domain field. Click  Submit . MyAryaka obtains the Identity Provider Entity ID and Single Sign-On Service URL from the metadata URL and displays them in the corresponding fields in the Duo SAML Details pane of the < IdPname > page.  Obtain user and group API details in Duo Complete the procedure described in this section to obtain API details that are used by the Aryaka Identity Management system to authenticate with Duo and obtain user and user group data. To obtain user and group API details in Duo Log in to the Duo Dashboard as an administrator. Click  Applications  >  Protect an Application  in the left navigation pane. The Protect an Application page appears with the application catalog displayed. Locate or search for  Admin API  in the applications catalog, and then click  Protect  in that row.  Create a new Admin API application from the existing Admin API application. The new application displays an integration key, a secret key, and an API hostname. Copy or note these credentials to use for API requests as described in the next section.  Configure the following permissions in the Admin API application settings: Do not grant administrators Grant read information Grant applications Do not grant settings Grant read log Grant read resource Do not grant write resource Click  Save  to update the permissions. Configure user and group API details in MyAryaka Complete the procedure described in this section to configure user and group API details in MyAryaka. You must provide the credentials that you obtained in the previous procedure. To configure user and group API details in MyAryaka If it is not already open, navigate to the < IdPname > page for this Duo instance: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Manage  on the Enterprise’s Duo tile in the Configured Identity Providers section. The < IdPname > page appears. Click  Edit  in the User and Group API Details pane. The User and Group API Details page appears in edit mode. Paste or enter the API hostname that was obtained from Duo (step 4 in the previous procedure) into the API Hostname field. Paste or enter the integration key that was obtained from Duo (step 4 in the previous procedure) into the Integration Key field. Paste or enter the secret key that was obtained from Duo (step 4 in the previous procedure) into the Secret Key field. Accept the default 86400 seconds (24 hours) or enter a different synchronization interval (in seconds) in the Sync Period field. This is the amount of time that passes before MyAryaka obtains user and user group information from Duo. (Conditional) Aryaka Identity Management currently supports up to 100 user groups for an organization. If your organization’s total group count is greater than 100, in the Groups section, enter group names in the Filter Groups With Exact Match field or enter partial group names in the Filter Groups Start With field to specify up to 100 groups that you want to configure for user identification. Click  View Filtered Groups  to view included user groups based on your filter criteria. Note:  If needed, you can still configure all IdP users in step 8. In the Users section, select one of the following toggles to specify which users to pull from the IdP: All Organization Users—Regardless of group configuration (specified in step 7), all users are pulled from the IdP and can be used for policy configuration. This option is selected by default. Users from Select Groups—Only users from the configured groups (specified in step 7) are pulled from the IdP. Click  Submit . A message confirms the configuration updates and your entries appear in the read-only User and Group API Details pane on the < IdPname > page. Verify the integration in MyAryaka  Complete the procedure described in this section to verify your Duo integration in MyAryaka. After completing the configuration, you can view the total number of users and user groups in MyAryaka. To verify the Duo integration If it is not already open, navigate to the < IdPname > page for this Duo instance: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Manage  on the Enterprise’s Duo tile in the Configured Identity Providers section. The < IdPname > page appears and displays the following: Sync Status tile—Displays the date and time of the last successful synchronization between Aryaka Identity Management and Duo. Pre-configuration Steps for SAML—Displays read-only fields that were used to configure SAML in Duo. Duo SAML Details pane—Allows you to modify and test the current Duo configuration. User and Group API Details pane—Allows you to modify the API used to query your users and user groups. (Optional) Click  Resync  in the Sync Status summary tile to manually run the sync operation between Duo and MyAryaka. The Last Successful Sync, Users, and User Group tiles are updated. (Optional) Click  Test IdP Configuration  in the Duo SAML Details pane to determine if Aryaka Identity Management can query Duo. A pop-up message indicates whether the test succeeds or fails. (Optional) Click  Test Authorization  in the User and Group API Details pane to verify authorization. A pop-up message indicates whether the test succeeds or fails. In this topic