---
source_url: "https://duo.com/docs/duo-directory?utm_source=openai"
title: "Duo Directory | Cisco Duo"
mirrored_at: 2026-08-06T03:40:07.364Z
host: duo.com
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/duo.com/docs/duo-directory__q__utm_source_openai"
---

> **Original source:** https://duo.com/docs/duo-directory?utm_source=openai

Last updated: May 28th, 2026

You can now use Duo as a true identity provider, offering a cloud-based user directory for single sign-on applications and advanced security like phishing-resistant MFA, passwordless authentication, and device trust and security posture evaluation.

## Overview

Duo Directory extends our secure multi-factor authentication (MFA) platform with more identity and access management (IAM) and identity provider (IdP) functionality. Duo isn't just a multi-factor authentication product any more; we're your full-stack identity management solution. [Duo Essentials, Duo Advantage, and Duo Premier plans](https://duo.com/editions-and-pricing) can use Duo's directory features.

Duo Directory is...

-   **Flexible**
    
    Host your users in Duo with no additional identity store required, or leverage your existing on-premises or cloud identity stores as external authentication or user import sources.
    
    Choose between traditional authentication with passwords or opt into complete passwordless authentication for different sets of users.
    
    Protect application access by your third-party users, like contractors or vendors, by adding their existing identity providers as additional Duo SSO authentication sources. Leverage routing rules to direct any user to the correct authentication source.
    
-   **Compatible**
    
    With support for SAML, OIDC, and OAuth, you can federate almost any service provider or client application with Duo Single Sign-On. Perform inbound or outbound SCIM 2.0 provisioning.
    
    Just need MFA? Add secure secondary authentication to RADIUS, LDAP, API, and web applications.
    
-   **Secure**
    
    We embed secure design into every layer of our product, and enable enhanced security options for you by default to protect your users, applications, and information.
    

[Learn more about the benefits of Duo Directory](https://duo.com/product/duo-directory).

## Duo Directory Features

New features and service enhancements include:

-   In-product [onboarding guidance](https://duo.com/docs/getting-started#guided-onboarding).
    
-   User directory with standard and custom [user attributes](https://duo.com/docs/user-attributes).
    
-   [Breached password checking](https://duo.com/docs/enrolling-users#breached-password-checking), [proactive password reset](https://duo.com/docs/sso#sso-controls-for-users-hosted-in-duo), and [forced password change](https://duo.com/docs/administration-users#reset-duo-password).
    
-   [Granular enrollment policies](https://duo.com/docs/enrollment-policy) for allowed authenticators and password requirements.
    
-   [Passwordless new user enrollment](https://duo.com/docs/passwordless#enrollment-and-authentication-experience).
    
-   [Disable fallback to password](https://duo.com/docs/passwordless#passwordless-for-duo-single-sign-on-applications) and enforce passwordless-only logins.
    
-   Flexible [temporary access](https://duo.com/docs/administration-users#bypass-codes) for MFA or complete passwordless flows.
    
-   [Dynamic routing rules](https://duo.com/docs/sso#routing-rules) that direct users to different SSO authentication sources based on your defined conditions.
    
-   Import users and groups into Duo using SCIM 2.0 from [Okta](https://duo.com/docs/oktasync) or [any SCIM-compliant directory](https://duo.com/docs/generic-scim-sync), or from [Microsoft Entra ID](https://duo.com/docs/azuresync), [Google](https://duo.com/docs/googlesync), [Active Directory](https://duo.com/docs/adsync), or [OpenLDAP](https://duo.com/docs/ldapsync) with directory sync.
    
-   [Automated provisioning](https://duo.com/docs/automated-provisioning) into Microsoft 365, Google Cloud, or other applications via SCIM 2.0.
    

## Example Use Cases

These are some sample deployment and configuration journeys for different Duo Directory use cases.

### Duo as the Primary Identity Provider

1.  [Create](https://duo.com/docs/enrolling-users) or [import](https://duo.com/docs/directorysync) Duo users.
    
2.  Create Duo directory [custom attributes](https://duo.com/docs/user-attributes).
    
3.  Set up [routing rules](https://duo.com/docs/sso#routing-rules) for multiple authentication sources (optional).
    
4.  Configure an [SSO application](https://duo.com/docs/sso#create-a-cloud-application-in-duo).
    
5.  Review or edit [policies](https://duo.com/docs/policy).
    
6.  Configure and apply an [enrollment policy](https://duo.com/docs/enrollment-policy).
    
7.  [Enroll](https://duo.com/docs/enrolling-users) a new user via a prior identity provider, enrollment codes, or enrollment emails.
    
8.  [Authenticate](https://guide.duo.com/log-in-with-duo) to your SSO application with Duo password and MFA or with passwordless authentication.
    
9.  Check administrator and authentication [reporting](https://duo.com/docs/administration-reporting).
    

### Passwordless Authentication with Existing Identity Provider and Complete Passwordless

1.  [Create](https://duo.com/docs/enrolling-users) or [import](https://duo.com/docs/directorysync) Duo users.
    
2.  Create Duo directory [custom attributes](https://duo.com/docs/user-attributes).
    
3.  Set up [routing rules](https://duo.com/docs/sso#routing-rules) for multiple authentication sources (optional).
    
4.  Configure an [SSO application](https://duo.com/docs/sso#create-a-cloud-application-in-duo).
    
5.  Review or edit [policies](https://duo.com/docs/policy).
    
6.  Edit the [authentication method policy](https://duo.com/docs/policy#authentication-methods) to disable password fallback by ensuring only passwordless methods remain enabled. Also enable bypass code passwordless method for temporary user access during passwordless authentication.
    
7.  Configure an [enrollment policy](https://duo.com/docs/enrollment-policy) without a password requirement.
    
8.  [Enroll](https://duo.com/docs/enrolling-users) a new user via a prior identity provider, enrollment codes, or enrollment emails.
    
9.  [Authenticate](https://guide.duo.com/log-in-with-duo) to your SSO application with passwordless authentication.
    
10.  Check administrator and authentication [reporting](https://duo.com/docs/administration-reporting).
     

### Automate Provisioning of Users and Groups from Duo into Applications

1.  [Create](https://duo.com/docs/enrolling-users) or [import](https://duo.com/docs/directorysync) Duo users.
    
2.  Create Duo directory [custom attributes](https://duo.com/docs/user-attributes).
    
3.  Configure an [SSO application](https://duo.com/docs/sso#create-a-cloud-application-in-duo).
    
4.  Set up automated provisioning into [Microsoft 365](https://duo.com/docs/sso-m365#automated-provisioning), [Google](https://duo.com/docs/sso-gsuite#automated-provisioning), or [SCIM 2.0 supported](https://duo.com/docs/automated-provisioning#configure-automated-provisioning) applications.
    

### Use Duo SSO and/or Passwordless with Microsoft 365

If you would like to use Duo SSO and/or Passwordless with Microsoft 365 without an on-premises Active Directory, you must set up [automated provisioning for Microsoft 365](https://duo.com/docs/sso-m365#automated-provisioning) for all users. This ensures that the required "Entra Federated User ID" attribute exists for your Duo users.

See [the Entra ID information in the Duo Passwordless and External Identity Providers documentation](https://duo.com/docs/passwordless#duo-passwordless-and-external-identity-providers) for more details about this use case.

1.  [Create](https://duo.com/docs/enrolling-users) or [import](https://duo.com/docs/directorysync) Duo users.
    
2.  Create Duo directory [custom attributes](https://duo.com/docs/user-attributes).
    
3.  Create a [Microsoft 365 SSO application](https://duo.com/docs/sso-m365) and federate Microsoft 365 with Duo SSO.
    
4.  Set up automated provisioning for [Microsoft 365](https://duo.com/docs/sso-m365#automated-provisioning).
    
5.  Review or edit [policies](https://duo.com/docs/policy).
    
6.  Configure and apply an [enrollment policy](https://duo.com/docs/enrollment-policy).
    
7.  [Enroll](https://duo.com/docs/enrolling-users) a new user via a prior identity provider, enrollment codes, or enrollment emails.
    
8.  [Authenticate](https://guide.duo.com/log-in-with-duo) to Microsoft 365 applications with Duo password and MFA or with passwordless authentication.
    

## Guided Onboarding

We recommend that you follow the in-product onboarding guidance as you begin your Duo deployment. Please see the [Getting Started guide](https://duo.com/docs/getting-started) for more information.