Let Oomnitza be your single source of truth!
You'll get visibility of your Duo Security users as data from Duo Security is automatically transformed into consumable information and actionable insights.
The Duo Security User Load uses the Duo Admin Users API, which returns a paged list of users. For further information, see Duo Admin API: Users.
Connect Oomnitza and Duo Security in minutes
Get the information and insights that you need to reduce costs and the time that you spend on administration tasks such as:
- Configurable dashboards and list views of key user information
- Configurable reports to share information about users with your colleagues and management
-
Configurable workflows that you can easily create for:
- Getting a user's last login activity, enabling you to identify accounts that are underutilized or that can be canceled
Navigation
Before you start
Before you create the user integration, you need to have added your Duo Security credentials to Oomnitza.
You can create two user loads for Duo Security:
- Duo Security Federal Edition User Load
- Duo Security User Load
The integrations are essentially the same, except for the variation in the API request URLs. Specifically, the Duo Security Federal Edition User Load uses the duofederal.com URL for its requests, whereas the Duo Security User Load allows the use of the duosecurity.com or duofederal.com URL for making requests. For information on the API used in both user loads see Duo Admin API: Retrieve Users.
Adding global variables
To save time entering information when you create the integration, you can add your domains as a global variable in Oomnitza.
Procedure
- Click Configuration>General>Global Settings.
- Click Add new variable(+).
- Depending on which user integration you choose, add the following variable as the key Duo Federal.Duo Api Domain or Duo Security.Duo Api Domain.
- For the Duo Federal key, you must supply the hex value of your Duo Security Federal subdomain. For example, if your URL is
https://123.duofederal.com
you need to supply123
. For the Duo Security key, you need to supply the hex value of your Duo Security subdomain and the domain, for example,123.duosecurity
or123.duofederal
. For example, if your URL ishttps://123.duosecurity.com
you need to supply123.duosecurity
. - Save your changes.
Creating the user integration
- In Oomnitza, click Configuration > Integrations > Overview.
- Click Block view
.
- On the Integrations page, scroll down to the Extended section for user integrations.
- Click NEW INTEGRATION.
- In the sidebar, search for the integration.
- Click ADD.
Integration details overview
More information is provided about the following fields to help you complete the integration:
- User only. Add user records.
- User plus SaaS user. Add user and SaaS user records.
The benefit of adding SaaS user records is that you can run a workflow to validate the status and activity of SaaS users and retrieve information such as the role of the SaaS user. The information that can be retrieved depends on whether SaaS user workflows are available for the integration.
Installation types
- Cloud. Store credentials in the Oomnitza cloud.
- Local. Store credentials locally. If you want to sync Oomnitza with vendor applications that require AWS or OAUTH authentication, select cloud as the type of installation. Local installations don't support AWS and OAuth authentication.
Integration preferences
- Create & Update. Add and update records.
- Create only. Add records.
- Update only. Update records.
Editing the integration details
- Click Edit
.
- Make your changes.
Editing the credential details
If you selected Cloud as the installation type, choose one of the following options:
- Select the credentials that were created for the integration.
- Edit the credentials that were created for the integration.
- Create new credentials
Scheduling the integration
By default, data is synced once every day. Change the interval or the time so that the data is streamed when your system isn't busy.
- Click Edit
.
- Make and save your changes.
Mapping fields to Oomnitza
To map the fields to Oomnitza, click Edit .
Selecting Edit integration to add rules for syncing data.
Filtering integration results.
You can add new fields to your integration by selecting Add new field on the mapping page.
Creating custom API fields.
Creating custom mappings
Map the Duo Security fields to Oomnitza fields and create custom mappings to get the user information that you need.
Complete these actions:
- Click Smart Mapping to automatically detect appropriate mapping fields. Values from the integration can also be dragged to the appropriate field on the Oomnitza side, or selected from the integration field dropdown.
- Map other fields or create custom mappings to map any other field that you want to add to Oomnitza. To create an optional custom mapping, do the following:
- Click the down arrow on the field that you want to map.
- Select Add new Oomnitza users field.
- Change the name of the field.
- Click CREATE.
- Ensure that the Email is mapped to the Email field on the Oomnitza side (required for integration).
- Ensure that the Username is mapped to the Username field on the Oomnitza side (required for integration).
- Select the Role field on the Oomnitza mapping side.
- Choose a suitable role from the list (a defined role is necessary for the integration)
- Assign a sync key to a unique field, such as the Email.
- Click UPDATE.
Duo Security User Load mappings
Alias 1
Alias 2
Alias 3
Alias 4
Creation Date
Email
First Name
Is Enrolled
Last Directory Sync
Last Login
Last Name
Notes
Real Name
Status
User ID
Username
Duo Security Federal Edition User Load mappings
Alias 1
Alias 2
Alias 3
Alias 4
Created
Email
First Name
Is Enrolled
Last Directory Sync
Last Login
Last Name
Notes
Real Name
Status
User ID
Username
Launching the integration
Your integration is in Draft mode until the required mandatory fields are added. When added, click Launch to activate your integration.
If you selected Cloud as the installation type when creating the integration, see Running an extended integration
If you selected Local as the installation type when creating the integration, see Running an extended integration locally.
Viewing data ingested by Oomnitza
Viewing ingested asset data
For asset integrations, click Hardware. If the asset integration also ingests software data, click Software.
Viewing ingested user data
For user integrations, click People. If you chose the option to ingest User and SaaS user data, click Software > SaaS, click the SaaS app, and then click the Users tab.
Related Links
Unleash the power of Oomnitza
To get valuable actionable insights that help you manage your assets, learn how to:
- Configure dashboards for your users and software
- Configure custom reports about your users and software
- Create workflows to automate tasks
See Getting started for more information.
Comments
0 comments
Please sign in to leave a comment.