Home / Integrations / Duo Security
Connect Duo Security MFA and authentication data to Salesforce Agentforce
Duo Security, now part of Cisco, is the multi-factor authentication and zero-trust access platform that enterprise organisations use to secure application access with two-factor authentication, device health checks, and adaptive access policies. When an employee contacts the IT help desk because they cannot authenticate — their MFA device is lost, their Duo push is not arriving, or their authentication is blocked by a device compliance check — the resolution context is in Duo. When a new employee is onboarded and their Salesforce profile is created, Duo enrolment should be part of the onboarding workflow. When Emerge Digital connects Duo Security to Agentforce, authentication and MFA context from Duo is available to IT service agents during help desk conversations — and Salesforce lifecycle events coordinate with Duo to manage user enrolment and bypass in the appropriate governance context.
What this unlocks
- MFA status and authentication context during IT service conversations: when an employee contacts the IT help desk reporting that they cannot authenticate to an application, an agent can read the Duo user record — the enrolled devices, the last successful authentication, whether any push requests have been denied or timed out, and whether device compliance is blocking access — and provide a specific diagnosis rather than asking the employee to walk through a generic troubleshooting script.
- Salesforce onboarding events trigger Duo enrolment invitation: when a new employee is added to Salesforce — from an HR system or an onboarding workflow — an agent can trigger the Duo enrolment email to the new employee, so they can enrol their primary and backup authentication devices before their first day without requiring a manual IT help desk step.
- Authentication failure alerts create Salesforce IT service cases: when a Duo authentication failure pattern is detected — multiple consecutive denied pushes, a new device attempting access outside policy — an agent can create a Salesforce IT service case with the user account, the failure pattern, and the access policy details, so the IT team has a tracked service item for the security review.
- Device compliance context for zero-trust policy conversations: Duo's device health checks enforce that devices meet security requirements before access is granted — an agent can read the device health status for a specific user during an IT service conversation, identifying whether a compliance failure (missing patch, disabled firewall) is blocking authentication.
In the customer journey
Employee cannot authenticate — IT agent reads Duo
An employee calls the IT help desk unable to access their company email on a new laptop. The agent reads the Duo record — the employee has two enrolled devices, but the new laptop is failing the device health check because FileVault is not enabled. The agent guides the employee through enabling FileVault — the compliance check passes — and the employee authenticates successfully. The diagnosis and resolution happen in a single call without the help desk agent logging into the Duo admin panel.
New employee receives Duo enrolment invitation from Salesforce onboarding
A new employee is added to Salesforce as part of the HR onboarding workflow with a start date three days away. The agent reads the new employee's email and department from the Salesforce record, triggers the Duo enrolment email, and creates a Salesforce onboarding task to confirm enrolment completion before the start date. The employee enrolls their devices before they arrive, so authentication is working on day one.
Repeated Duo failures create a security review case
A Duo report shows that a Salesforce operations user has had six consecutive push denials in the past hour — a pattern consistent with an MFA fatigue attack. The agent creates a Salesforce IT service case for the user account, flags the authentication anomaly with the denial timestamps and originating IPs, and routes it as a priority security review. The IT security team investigates a tracked, user-attributed security item rather than a raw Duo alert.
Why not Duo Security's native Salesforce integration?
Duo Security integrates with Salesforce as an application in its SSO catalogue — users can authenticate to Salesforce through Duo's MFA layer. This protects Salesforce access. What it does not provide is Duo authentication and device compliance data queryable by a Salesforce Agentforce agent in real time during an IT service conversation: an IT help desk agent cannot ask Duo's Salesforce integration for why a specific employee's authentication is failing, trigger Duo enrolment for a new employee when their Salesforce onboarding record is created, or create a Salesforce service case with user attribution when Duo detects an authentication failure pattern. Emerge Digital builds the coordination layer that makes Duo authentication and MFA context available to agents in IT service conversations.
Duo Security's Agentforce integration is primarily active in IT service management and HR operations — where authentication failures are IT service events that need to be diagnosed with the actual Duo context, and where new employee onboarding should trigger Duo enrolment as part of the automated workflow. It is relevant for any enterprise organisation that uses Duo as its MFA platform alongside Salesforce for employee or customer records.
How Emerge integrates Duo Security
Emerge Digital connects Duo Security to Salesforce Agentforce as a consulting engagement. We map which Duo user attributes and authentication event types are relevant to IT service conversations, configure the Salesforce onboarding event triggers that initiate Duo enrolment invitations, build the authentication and device compliance retrieval for IT service agents, and define the authentication failure case creation logic. The integration is designed around your Duo Security organisation configuration, access policies, and Salesforce employee or customer data model.
How we structure an engagementRelated integrations
FAQ
Can the agent bypass MFA or disable Duo for a user during an IT service interaction?
Duo bypass actions — creating a temporary bypass code, disabling Duo for a user — can be initiated by agents through an IT admin approval workflow where the request is reviewed and authorised before the bypass is applied. Autonomous bypass without IT admin approval is not permitted, as it is a security control with significant risk.
We use Okta or Microsoft Authenticator for MFA rather than Duo — can you build the same integration?
Yes. Emerge has equivalent integration patterns for Okta's MFA capabilities and Microsoft's Entra ID Authentication. The authentication context in IT service conversations and onboarding enrolment use cases apply across MFA platforms. Emerge builds to the authentication platform your organisation uses.
Does the integration work with Duo's Trusted Endpoints and device trust features?
Yes. Duo Trusted Endpoints and device health data — the device compliance status, the trust status, the registered device list — are part of the user context available to IT service agents. Device trust status is particularly useful for diagnosing authentication failures where the issue is a non-compliant device rather than an authentication credential problem.
How long does a Duo Security + Agentforce integration take?
A focused engagement typically runs four to six weeks: mapping which Duo user attributes and authentication event types are in scope, configuring Salesforce onboarding enrolment triggers, building authentication and device compliance retrieval for IT service agents, defining failure pattern case creation, and testing authentication diagnosis, new employee enrolment, and security anomaly response scenarios.
Ground your agents in Duo Security.
Tell us what your agents need to read and write in Duo Security, and we'll design the integration and the governance around it.
Talk to the practicePrefer email? Write to the practice instead.