Skip to content
Independent thinking. Connected delivery.
UAEAustraliaCompanyClient access ↗
Emerge Digital
Explore Emerge
Talk to Emerge →

Integration guide

Security and Identity

Connect Duo Security MFA and authentication data to Salesforce Agentforce

Duo Security, now part of Cisco, is the multi-factor authentication and zero-trust access platform that enterprise organisations use to secure application access with two-factor authentication, device health checks, and adaptive access policies. When an employee contacts the IT help desk because they cannot authenticate — their MFA device is lost, their Duo push is not arriving, or their authentication is blocked by a device compliance check — the resolution context is in Duo. When a new employee is onboarded and their Salesforce profile is created, Duo enrolment should be part of the onboarding workflow. When Emerge Digital connects Duo Security to Agentforce, authentication and MFA context from Duo is available to IT service agents during help desk conversations — and Salesforce lifecycle events coordinate with Duo to manage user enrolment and bypass in the appropriate governance context.

Discuss your Duo Security integration

The opportunity

What the connection unlocks

  • MFA status and authentication context during IT service conversations: when an employee contacts the IT help desk reporting that they cannot authenticate to an application, an agent can read the Duo user record — the enrolled devices, the last successful authentication, whether any push requests have been denied or timed out, and whether device compliance is blocking access — and provide a specific diagnosis rather than asking the employee to walk through a generic troubleshooting script.
  • Salesforce onboarding events trigger Duo enrolment invitation: when a new employee is added to Salesforce — from an HR system or an onboarding workflow — an agent can trigger the Duo enrolment email to the new employee, so they can enrol their primary and backup authentication devices before their first day without requiring a manual IT help desk step.
  • Authentication failure alerts create Salesforce IT service cases: when a Duo authentication failure pattern is detected — multiple consecutive denied pushes, a new device attempting access outside policy — an agent can create a Salesforce IT service case with the user account, the failure pattern, and the access policy details, so the IT team has a tracked service item for the security review.
  • Device compliance context for zero-trust policy conversations: Duo's device health checks enforce that devices meet security requirements before access is granted — an agent can read the device health status for a specific user during an IT service conversation, identifying whether a compliance failure (missing patch, disabled firewall) is blocking authentication.

Illustrative workflows

Where it can make a difference

These scenarios explain possible workflows. They are not claims of delivered client results; licensing, permissions and feasibility are confirmed during discovery.

Employee cannot authenticate — IT agent reads Duo

An employee calls the IT help desk unable to access their company email on a new laptop. The agent reads the Duo record — the employee has two enrolled devices, but the new laptop is failing the device health check because FileVault is not enabled. The agent guides the employee through enabling FileVault — the compliance check passes — and the employee authenticates successfully. The diagnosis and resolution happen in a single call without the help desk agent logging into the Duo admin panel.

New employee receives Duo enrolment invitation from Salesforce onboarding

A new employee is added to Salesforce as part of the HR onboarding workflow with a start date three days away. The agent reads the new employee's email and department from the Salesforce record, triggers the Duo enrolment email, and creates a Salesforce onboarding task to confirm enrolment completion before the start date. The employee enrolls their devices before they arrive, so authentication is working on day one.

Repeated Duo failures create a security review case

A Duo report shows that a Salesforce operations user has had six consecutive push denials in the past hour — a pattern consistent with an MFA fatigue attack. The agent creates a Salesforce IT service case for the user account, flags the authentication anomaly with the denial timestamps and originating IPs, and routes it as a priority security review. The IT security team investigates a tracked, user-attributed security item rather than a raw Duo alert.

Why not Duo Security's native Salesforce integration?

Duo Security integrates with Salesforce as an application in its SSO catalogue — users can authenticate to Salesforce through Duo's MFA layer. This protects Salesforce access. What it does not provide is Duo authentication and device compliance data queryable by a Salesforce Agentforce agent in real time during an IT service conversation: an IT help desk agent cannot ask Duo's Salesforce integration for why a specific employee's authentication is failing, trigger Duo enrolment for a new employee when their Salesforce onboarding record is created, or create a Salesforce service case with user attribution when Duo detects an authentication failure pattern. Emerge Digital builds the coordination layer that makes Duo authentication and MFA context available to agents in IT service conversations.

Journey fit

Connect the workflow to the outcome.

Duo Security's Agentforce integration is primarily active in IT service management and HR operations — where authentication failures are IT service events that need to be diagnosed with the actual Duo context, and where new employee onboarding should trigger Duo enrolment as part of the automated workflow. It is relevant for any enterprise organisation that uses Duo as its MFA platform alongside Salesforce for employee or customer records.

Delivery

Built around your environment.

Emerge Digital connects Duo Security to Salesforce Agentforce as a consulting engagement. We map which Duo user attributes and authentication event types are relevant to IT service conversations, configure the Salesforce onboarding event triggers that initiate Duo enrolment invitations, build the authentication and device compliance retrieval for IT service agents, and define the authentication failure case creation logic. The integration is designed around your Duo Security organisation configuration, access policies, and Salesforce employee or customer data model.

Explore AI and automation

Practical questions

Before we connect.

Can the agent bypass MFA or disable Duo for a user during an IT service interaction?

Duo bypass actions — creating a temporary bypass code, disabling Duo for a user — can be initiated by agents through an IT admin approval workflow where the request is reviewed and authorised before the bypass is applied. Autonomous bypass without IT admin approval is not permitted, as it is a security control with significant risk.

We use Okta or Microsoft Authenticator for MFA rather than Duo — can you build the same integration?

Yes. Emerge has equivalent integration patterns for Okta's MFA capabilities and Microsoft's Entra ID Authentication. The authentication context in IT service conversations and onboarding enrolment use cases apply across MFA platforms. Emerge builds to the authentication platform your organisation uses.

Does the integration work with Duo's Trusted Endpoints and device trust features?

Yes. Duo Trusted Endpoints and device health data — the device compliance status, the trust status, the registered device list — are part of the user context available to IT service agents. Device trust status is particularly useful for diagnosing authentication failures where the issue is a non-compliant device rather than an authentication credential problem.

How long does a Duo Security + Agentforce integration take?

A focused engagement typically runs four to six weeks: mapping which Duo user attributes and authentication event types are in scope, configuring Salesforce onboarding enrolment triggers, building authentication and device compliance retrieval for IT service agents, defining failure pattern case creation, and testing authentication diagnosis, new employee enrolment, and security anomaly response scenarios.

Keep exploring

Related integrations

Start with one useful connection.

Tell us which workflow needs to improve. We will map the systems, access rules and success measures with you.

Talk to Emerge

Your Emerge companion

AI thinking. Human expertise.

A good place to start

What could we
build together?

Explore an idea, shape a project, or get help from our team. We’ll find the right next step with you.

Explore solutions at your own pace ↗