Duo for WordPress – Legacy Plugin – duo.com

by

in
                                         Connect and protect your employees, business partners and customers with identity-powered security.                                         <br>                                                                                  <img src="/img/asset/aW1nL091clByb2R1Y3RfTWVudS5wbmc=?s=b7e36e03570c94a1df95231c56ca650b"                                             class="margin--auto nav-bar--desktop-only" alt="image of a person typing on a laptop">                                                                              <br>Get the security features your business needs with a variety of plans at several price points.<br>Desktop and mobile access protection with basic reporting and secure single sign-on.<br>All Duo Small/Medium Business features, plus adaptive access policies, greater device visibility, plus advanced device insights and remote access solutions.<br>FedRamp authorized, end-to-end FIPS compliant, streamlined solutions.<br>Meet compliance objectives with our friction-free MFA.<br>Duo provides secure access to any application with a broad range of capabilities.<br>Minimize authentication fatigue.<br>Verify the identities of all users with MFA.<br>Provide secure access to on-premise applications.<br>Ensure all devices meet security standards.<br>Provide secure access to any app from a single dashboard.<br>Block or grant access based on users' role, location, and more.<br>                                             Duo’s security is customizable, easy to set up and simple to use, making it the perfect solution for a wide range of industries.                                         <br>                                                                                  <img src="/img/asset/aW1nL1NvbHV0aW9uc19NZW51LnBuZw==?s=c8f2e793034b23d5df25ecc99582b5d4"                                             class="margin--auto nav-bar--desktop-only" alt="image of person on a mobile device">                                                                              <br>Duo provides secure access for a variety of industries, projects, and companies.<br><br><br><br><br><br><br><br><br><br>Whether you're considering a big-picture security strategy like zero trust, or you want to address a specific threat like phishing attacks, Duo has you covered.<br>Stop sophisticated identity-based attacks while providing a seamless authentication experience.<br>This set of tools and policy controls ensures only the right users have access to applications and resources and under the right conditions.<br>A zero trust model establishes trust in users and devices through authentication and continuous monitoring.<br>Duo's comprehensive access security sets the stage for user-friendly, password-free multi-factor authentication.<br>Secure your workforce against phishing attacks with strong multi-factor authentication, device trust and more.<br>Duo’s dynamic solution detects and responds to potential threat signals to secure trusted users and frustrate attackers.<br>                                             With Duo, you can have both, in a platform that integrates across your entire ecosystem. Every user, every device, no exceptions.                                         <br>                                                                                  <img src="/img/asset/aW1nL1doeUR1b19NZW51LnBuZw==?s=33a962ee3eaf9c944e1bf7034680f89c"                                             class="margin--auto nav-bar--desktop-only" alt="image of two people on a mobile device">                                                                              <br>Duo delivers peace of mind with strong security and increased productivity at an unmatched value.<br>Reduce friction and automate processes so that end-users and administrators can focus their time on moving your business forward.<br>Duo continues to pioneer MFA-approaches that keep your business a step ahead of the next threat.<br>Our Risk-Based Authentication reduces the burden placed on users so they can verify their identity quickly and get back to the task at hand.<br>Close the gap on your security perimeter and bring every user and every device under one secure roof.<br>Duo provides secure access for a variety of industries, projects, and companies.<br>Click through our instant demos to explore Duo features.<br>Duo Security is part of Cisco Security — find out how we make global security resilience easier than ever!<br>Was this page helpful? Let us know how we can make it better.<br>Duo's <a href="https://wordpress.org/plugins/duo-wordpress/">WordPress plugin</a> enables two-factor authentication for WordPress logins, complete with <a href="https://guide.duo.com/enrollment">inline self-service enrollment</a> and <a href="https://guide.duo.com/prompt">Duo Prompt</a>. The code is open-source and available on <a href="https://github.com/duosecurity/duo_wordpress">GitHub</a>.<br><div class="callout warning" markdown="1"> <p>Support for the traditional Duo Prompt experience and Duo Prompt delivery via iframe ended on <span class="keyword">March 30, 2024</span>.  <p>See the <a href="/docs/wordpress#migrate-from-the-legacy-wordpress-plugin" alt="Update instructions for WordPress">update instructions for WordPress </a> to update an existing deployment of the iframe-based WordPress software to the latest release. Authenticating once with the updated Duo software is a required step before you can enable the <a href="/docs/universal-prompt-update-guide" alt="Duo Universal Prompt Update Guide" target="_blank" rel="noopener noreferrer">Duo Universal Prompt</a> for your existing WordPress application.</p>  <p>Please visit the <a href="/docs/universal-prompt-update-guide" alt="Duo Universal Prompt Update Guide" target="_blank" rel="noopener noreferrer">Duo Universal Prompt Update Guide</a> for more information about the traditional Duo Prompt end of support.</p>  </div> <br>Support for the traditional Duo Prompt experience and Duo Prompt delivery via iframe ended on <span class="keyword">March 30, 2024</span>.  <br>See the <a href="/docs/wordpress#migrate-from-the-legacy-wordpress-plugin" alt="Update instructions for WordPress">update instructions for WordPress </a> to update an existing deployment of the iframe-based WordPress software to the latest release. Authenticating once with the updated Duo software is a required step before you can enable the <a href="/docs/universal-prompt-update-guide" alt="Duo Universal Prompt Update Guide" target="_blank" rel="noopener noreferrer">Duo Universal Prompt</a> for your existing WordPress application.<br>Please visit the <a href="/docs/universal-prompt-update-guide" alt="Duo Universal Prompt Update Guide" target="_blank" rel="noopener noreferrer">Duo Universal Prompt Update Guide</a> for more information about the traditional Duo Prompt end of support.<br><div class="callout warning"> <div class="callout-heading">Treat your secret key like a password</div> <p>The security of your Duo application is tied to the security of your secret key (skey). Secure it as you would any sensitive credential. Don't share it with unauthorized individuals or email it to anyone under any circumstances!</p> </div> <br>The security of your Duo application is tied to the security of your secret key (skey). Secure it as you would any sensitive credential. Don't share it with unauthorized individuals or email it to anyone under any circumstances!<br><h2>Duo Universal Prompt</h2>  <br>The Duo Universal Prompt provides a simplified and accessible Duo login experience for web-based applications, offering a redesigned visual interface with security and usability enhancements.<br><table>   <tr>     <td style="border:0px;vertical-align:top;text-align:center"><b>Universal Prompt</b></td>     <td style="border:0px;vertical-align:top;text-align:center"><b>Traditional Prompt</b></td>   </tr>   <tr>     <td style="border:0px;vertical-align:top;text-align:center">&nbsp;<img style="display:inline;" width="225" src="/assets/img/documentation/universal-prompt/universal-prompt_2x.png?version=042622" alt="Duo Push in Universal Prompt"></td>     <td style="border:0px;vertical-align:top;text-align:center">&nbsp;<img style="display:inline;" width="300" src="/assets/img/documentation/universal-prompt/traditional-prompt_2x.png" alt="Duo Push in Traditional Prompt"></td>   </tr> </table><br><a href="/docs/universal-prompt-update-guide" target="_blank" rel="noopener noreferrer">Read the Universal Prompt Update Guide</a> for more information about the update process and the new login experience for users.<br>Migration to Universal Prompt for your WordPress application is a three-step process:   <ol>     <li>Install an update for the WordPress application, which implements a redirect to Duo during authentication to support the Universal Prompt.</li>     <li>Authenticate with Duo 2FA using the updated application so that Duo makes the Universal Prompt activation setting available in the Admin Panel. This first authentication after updating shows the traditional Duo prompt in a redirect instead of an iframe.</li>     <li>From the Duo Admin Panel, activate the Universal Prompt experience for users of that Duo WordPress application if the traditional prompt is still selected. Once activated, all users of the application see the Duo Universal Prompt in a redirect.</li>   </ol> <br>  <h3 id="new-application">New WordPress Applications</h3>  <br>If you're configuring Duo for WordPress for the first time now, we recommend installing the updated <a href="/docs/wordpress">Universal Prompt application for WordPress</a> instead of the legacy application described on this page, so your users can experience the Universal Prompt as soon as you finish the Duo configuration steps.<br>WordPress needs a software update installed before you can activate the Universal Prompt experience. The "Universal Prompt" section reflects this status as "Update Required" today.<br><img src="/assets/img/documentation/universal-prompt/universal-app-named-update-required_2x.png" alt="Universal Prompt Info - Update Required" width="800"><br>To update your current WordPress Duo application to a newer version so that you can activate the Universal Prompt experience, follow the <a href="/docs/wordpress#migrate-from-the-legacy-wordpress-plugin">update directions for the Universal Prompt</a>.<br>You **must** perform a Duo 2FA authentication after performing the required update. This authentication will not yet show the Universal Prompt, but will update the status of that application in Duo's service to unlock the Universal Prompt activation control so you can then turn it on for the application if the traditional prompt is still selected. Your users continue to see the current Duo prompt experience until you apply the update and authenticate using the updated application, and then activate Universal Prompt for that application.<br>Click the <span class="keyword">See Update Progress</span> link to view the <a href="/docs/administration#universal-prompt-progress" alt="About the Universal Prompt Update Progress Report">Universal Prompt Update Progress report</a>. This report shows the update availability and migration progress for all your Duo applications. You can also activate the new prompt experience for multiple supported applications from the report page instead of visiting the individual details pages for each application.<br>Log in to your WordPress Dashboard as an administrator.<br>Navigate to <span class="keyword">Plugins</span> → <span class="keyword">Add New</span> in the left navigation bar. Then search for &quot;Duo Security&quot; and click <span class="keyword">Install Now</span> for the <span class="keyword">Duo Two-Factor Authentication</span> plugin.<br>To install the Duo two-factor plugin without using the WordPress Plugin directory, first download the Duo plugin as a <a href="https://wordpress.org/plugins/duo-wordpress/">zipped package</a> from WordPress.<br>In the WordPress console go to <span class="keyword">Plugins</span> → <span class="keyword">Add New</span> and click the <span class="keyword">Upload Plugin</span> button.<br>Click <strong>Choose File</strong> and select the <strong>duo_wordpress.zip</strong> package you downloaded. Click <strong>Install Now</strong> to upload Duo's plugin to your WordPress site.<br>Click <span class="keyword">Activate Plugin</span> after installing the Duo plugin:<br>After activation, click <span class="keyword">Settings</span> to configure the plugin.<br>Copy and paste your <strong>integration key</strong>, <strong>secret key</strong>, and <strong>API hostname</strong> from the Duo WordPress application you created earlier. You may select which WordPress user roles need to authenticate using Duo. For example, you may only require those users with the &quot;Administrator&quot; role to use two-factor authentication, or require all roles to use two-factor.<br>To fully secure your WordPress site Duo recommends that you disable XML-RPC. However, this will prevent use of offline Weblog clients and the WordPress mobile app.<br>Click <span class="keyword">Save Changes</span> to complete configuration.<br>Open a new browser (or <a href="https://support.google.com/chrome/answer/95464">incognito window</a>) and try to log in to your WordPress account. You should be prompted to set up your two-factor authentication. Complete the enrollment process.<br><!-- add this to any integration that shows the Duo Prompt to mitigate potential security issues with U2f/security keys   does not apply to universal prompt/frameless  setting renamed from hostname whitelisting to allowed hostnames in d224--> <div class="callout warning"> <div class="callout-heading">Configure Allowed Hostnames </div> <p>If you plan to permit use of <a href="/docs/administration-devices#managing-webauthn-devices" alt="Managing WebAuthn Devices" target="_blank" rel="noopener noreferrer">WebAuthn authentication methods</a> (security keys, U2F tokens, or Touch ID) in the traditional Duo Prompt, Duo recommends <a href="/docs/protecting-applications#allowed-hostnames" alt="Allowed Hostname Information" target="_blank" rel="noopener noreferrer">configuring allowed hostnames </a> for this application and any others that show the inline Duo Prompt before onboarding your end-users.</p> <p>The Duo Universal Prompt has built-in protection from unauthorized domains so this setting does not apply.</p> </div> <br>If you plan to permit use of <a href="/docs/administration-devices#managing-webauthn-devices" alt="Managing WebAuthn Devices" target="_blank" rel="noopener noreferrer">WebAuthn authentication methods</a> (security keys, U2F tokens, or Touch ID) in the traditional Duo Prompt, Duo recommends <a href="/docs/protecting-applications#allowed-hostnames" alt="Allowed Hostname Information" target="_blank" rel="noopener noreferrer">configuring allowed hostnames </a> for this application and any others that show the inline Duo Prompt before onboarding your end-users.<br>The Duo Universal Prompt has built-in protection from unauthorized domains so this setting does not apply.<br>See the instructions for <a href="#wordpress#migrate-from-the-legacy-wordpress-plugin">migrating to the v2 plugin with universal prompt support</a>.<br><strong class="text--sm">&copy; 2024 Duo</strong><br><br><a href="https://news.google.com/rss/articles/CBMiJWh0dHBzOi8vZHVvLmNvbS9kb2NzL3dvcmRwcmVzcy1sZWdhY3nSAQA?oc=5">source</a>

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Discover more from Wordpress supported for Telkom University

Subscribe now to keep reading and get access to the full archive.

Continue reading