惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Project Zero
Project Zero
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
P
Proofpoint News Feed
量子位
K
Kaspersky official blog
S
SegmentFault 最新的问题
博客园 - 叶小钗
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
博客园 - Franky
F
Fortinet All Blogs
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cisco Blogs
T
Tenable Blog
U
Unit 42
S
Schneier on Security
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
C
Cybersecurity and Infrastructure Security Agency CISA
V
Visual Studio Blog
The Hacker News
The Hacker News
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
I
Intezer
Cyberwarzone
Cyberwarzone
Know Your Adversary
Know Your Adversary
V
Vulnerabilities – Threatpost
L
LINUX DO - 热门话题
Spread Privacy
Spread Privacy
T
The Exploit Database - CXSecurity.com
V
V2EX
Help Net Security
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
大猫的无限游戏
大猫的无限游戏
www.infosecurity-magazine.com
www.infosecurity-magazine.com
PCI Perspectives
PCI Perspectives
腾讯CDC
Webroot Blog
Webroot Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Recorded Future
Recorded Future
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog

The Duo Blog

Identity orchestration & cloud-native IAM: Time to rethink | Cisco Duo Active Directory security: how to stop modern threats | Cisco Duo Duo + PlainID: Dynamic Authorization Meets Enterprise Identity | Cisco Duo Continuous identity security explained | Cisco Duo Salesforce The modern MFA toolkit: push, biometrics, and security keys | Cisco Duo Cisco Duo Identity Summit Preview | Cisco Duo Duo Brings Identity and Authorization Across AI Agent Gateways | Cisco Duo Passwordless for Microsoft 365 starts with federation Token theft, vendor abuse, and the new identity threat surface How Duo Directory automates user lifecycle management Cisco Systems Named a Customers’ Choice in Gartner Peer Insights™ 2026 Voice of the Customer for Access Management Identity provider resilience: backup and split IdP approaches | Cisco Duo Agentic AI Security: Three Threats Your Team Should Know | Cisco Duo Secure client access at scale with Duo and Meraki | Cisco Duo IdP Concentration Risk: Why Single-IdP Dependency Puts You at Risk | Cisco Duo Endpoint Management as an Attack Vector: Lessons from Stryker | Cisco Duo Passwordless authentication without cookies: Duo Push updates Introducing Duo Agentic Identity Solving the double prompt: Better UX with AMR in Duo SSO Simplify compliance with MFA, device trust, and policies Cisco Systems Named a Customers’ Choice in Gartner® Peer Insights™ 2026 Voice of the Customer for User Authentication Why identity-led security matters for MSPs right now The Hitchhiker’s Guide to Shibboleth Launching Active Directory Defense: Strengthen On-Prem AD Security | Duo Security Industry specific IAM for MSPs Duo delivers: 99.99% uptime SLA for every customer
Custom Admin Roles: Granular control for every Duo admin
Aamir Yousufzai · 2026-05-29 · via The Duo Blog

Product & Engineering

Your admins have too much privilege

Headshot of Aamir Yousufzai

6 minute read

You apply least privilege to your end users. You verify their devices, scope their access, and monitor what they can reach. But what about the admins managing your security tools every day?

Admin accounts are some of the highest-value targets in any organization. A compromised admin with broad permissions can generate bypass codes, weaken MFA policies, or modify single sign-on (SSO) configurations—quietly undermining the security layer your business depends on. That is why we are bringing the same least privilege discipline to the people managing Duo.

Custom Admin Roles is now generally available for all Duo customers. You can create your own administrator roles with granular permission controls, so every admin on your team gets exactly the access they need and nothing more.

Ready to get started? Log in to the Duo Admin Panel to create your first custom admin role.

Why the principle of least privilege matters for your admins too

You already apply least privilege to your end users. Your admins deserve the same protection.

Depending on the privilege level, a compromised admin account can cause widespread damage across your identity security configuration. Role-based access control (RBAC) reduces that risk by ensuring each admin operates within a clearly defined scope—one that matches their actual job, not a generic role that happens to be close enough.

Duo has long offered eight built-in admin roles with a fixed set of permissions:

  • Owner

  • Administrator

  • Application Manager

  • User Manager

  • Help Desk

  • Billing

  • Read-only

  • Integration Manager

These built-in roles give you role-based access control with clear segregation of duties right out of the box. For many teams, they are a good fit. But they are not always a perfect match for how your organization actually operates.

Maybe you want an admin with all the permissions of both User Manager and Application Manager, but without the ability to manage policy that comes with the full Administrator role. Or maybe you have multiple levels of help desk—some who need to see sensitive user attributes, and others who should not.

Until now, you had two options: give admins more privilege than they need, or build manual processes that are hard to maintain and harder to audit. Neither approach supports a strong security posture.

Custom Admin Roles removes that tradeoff. You can now create administrator roles that reflect your organization's actual structure, not a predefined template.

What you can do with Custom Admin Roles

Here is what's now available to any Duo admin with the Owner role:

  • Create unlimited custom roles tailored to your organization's operational structure

  • Set granular permissions across five categories: Users & Groups, Devices, Features, Applications, and Accounts

  • Start from templates by basing a new role on any existing built-in or custom role, then adjust individual permissions up or down

  • Assign custom roles anywhere you already use existing roles, including subaccount administration for Managed Service Providers (MSPs) and Administrator Sync

  • Edit roles on the fly – permission changes take effect immediately for every administrator assigned to that role

  • Assume roles without logging out to verify a role’s configuration before rolling it out to your administrators

  • Compare roles any time after creation to highlight the differences and get a full understanding of each role’s privileges

Permissions default to the most restrictive setting unless you apply a template, so you're always building up from least privilege by design.

Common ways teams are using Custom Admin Roles

While every organization structures its security team differently, a few patterns come up often:

  • Tiered help desk: Create a Tier 1 help desk role that can reset MFA devices but cannot view sensitive user attributes, and a Tier 2 role with broader visibility for escalations.

  • User Identity Manager: Grant full management of users but restrict security-sensitive actions, like putting users into bypass mode.

  • Subaccount Lifecycle Manager: Create, configure, and decommission child accounts but disallow any modification of users, policies, or security settings on the parent account.

These scenarios were not possible with built-in roles alone. Custom Admin Roles changes that.

Getting started is simple

Creating a custom role takes just a few steps right from the Duo Admin Panel:

  1. Navigate to Users > Administrators > Admin Roles

  2. Click Add custom admin role

  3. Name your role, optionally apply a template from an existing role, and expand each permission category to fine-tune access to match your security goals

  4. Click Add

That's it! Your new role is ready to use immediately. The role can be assigned anywhere standard roles can be assigned – when manually creating an admin, from an admin’s profile, from the role details page, via Admin API or through admin directory sync.

Before rolling a new role out to your team, we recommend using Assume Role to temporarily experience the Admin Panel exactly as that role will. This lets you verify the configuration matches your intent without affecting a real admin account.

Start building your custom roles today

Custom Admin Roles is available now for customers on Duo Essentials, Advantage, and Premier edition. Any admin with the Owner role can start creating custom roles immediately.

To see the feature in action, watch the video below or visit the Custom Admin Roles documentation for a complete walkthrough.

Already a Duo customer? Log in to the Duo Admin Panel to get started.

New to Cisco Duo? Start a free trial to see Custom Admin Roles and the full identity security platform in action.

Resources

Frequently asked questions

  • What is the principle of least privilege for administrator accounts?

    The principle of least privilege means giving administrator accounts only the minimum permissions required to perform their specific responsibilities. For admin accounts, this is critical because a compromised credential inherits every permission that account holds. Applying least privilege to your admins reduces that exposure by scoping each role to exactly what is needed.

  • How do I decide which permissions to assign to a custom admin role?

  • What is role-based access control and how does it apply to security administrators?

  • What is the difference between built-in admin roles and custom admin roles in Duo?

  • Can I use Custom Admin Roles to manage access for Managed Service Provider subaccounts?

  • What happens to administrators when I edit a custom admin role?

  • Do the Assume Role and Compare Roles features work for both custom and built-in admin roles?