https://store-images.s-microsoft.com/image/apps.18070.b63b5fdc-76e9-40e6-8fa7-5e6702a60825.97ecf712-b762-4b43-a7f6-9639ab196d3f.b42eac9c-7e0b-43da-a895-f5a101de1c36

Cisco Duo for Microsoft Sentinel

作成者: Cisco Systems, Inc.

Stream Cisco Duo logs to Microsoft Sentinel for identity intelligence and automated remediation.

The Cisco Duo connector for Microsoft Sentinel delivers an intelligence-led identity defense. By integrating Duo’s Auth and Admin APIs with Cisco Identity Intelligence, you stream high-fidelity risk signals and device health directly into your SOC.

This enables Microsoft Sentinel to correlate phishing-resistant MFA telemetry with environmental logs to expose sophisticated threats like session hijacking. Use automated Sentinel Playbooks to trigger instant remediation—such as disabling compromised accounts—via Duo’s Admin API. It’s the premier way to unify identity context and security operations for a proactive, resilient, and user-friendly perimeter.