If you have implemented or want to implement Duo Security as a third-party multi-factor authentication (MFA) solution, and Oracle Identity Cloud Service manages your primary authentication and identity management, you can connect to and integrate with Duo to secure Oracle IaaS, PaaS, or SaaS applications or to secure applications already secured by Oracle Identity Cloud Service.
- Enable Duo. Oracle must enable this feature for you. To learn about the features that Oracle must enable for you and how to enable them, see Service Request Features for Oracle Identity Cloud Service.
- Download and install the Duo Mobile app from the Google Play Store or the Apple Store.
- Subscribe to Duo and a create a Duo administrator account.
- Create and activate the Duo-protected Web SDK app.To create and activate the Duo-protected Web SDK app, refer to the Duo documentation for the latest instructions.
- Note the credentials and connecting host information.
These values were generated when you created and activated the Duo-protected Web SDK app. You need the values for Integration key, Secret key, and API hostname. Refer to the Duo documentation for the latest instructions.
- In the Oracle Identity Cloud Service console, expand the Navigation Drawer, click Security, Factors. and then Duo Security.
- Enter the credentials and connecting host information (Integration key, Secret key, and API hostname) that was generated from your Duo Administrative account, and then choose a User Identifier.The User Identifier that you choose must map to the user identifier set in the Duo user account. For example, User Name in the Oracle Identity Cloud Service user account must map to Username in the Duo security user account.
- In the Oracle Identity Cloud
Service console, expand the Navigation Drawer, click Security, MFA, turn on Duo Security, and then click Save.You may have to log out and log in again to see Duo Security.
Post Requirement: Understand the user Duo enrollment workflow.
User accesses the login screen.
Duo Security prompts the user to enroll.
Duo sends the User a notification asking them to enroll in Duo. Options are PUSH, TOTP, SMS, or SECURITY_QUESTIONS.
User accepts the enrollment verification.
User is created in Duo.
Optional. User sets up an additional factor. Options are PUSH, TOTP, SMS, or SECURITY_QUESTIONS. Or click Done.
User is logged in to Oracle Identity Cloud Service.
User can now use Duo Security MFA factors to sign in to Oracle Identity Cloud Service.