Fact check
Can Cisco Duo run standalone? Duo Directory, SSO & the IdP question
In short
A fact check on whether Cisco Duo runs standalone. Duo Directory is its own directory and identity provider, so Duo can be the source of truth, run alongside an existing provider, or sit in front of one as an identity broker.
- Last updated
Primary sources
- Duo Directory documentation · Cisco Duo
- Duo Single Sign-On documentation · Cisco Duo
- Set up SAML 2.0 for WorkSpaces Personal, listing Duo Single Sign-On as a supported SAML 2.0 identity provider · Amazon Web Services
Yes, Cisco Duo can run standalone. Duo Directory is Duo's own directory, and it lets Duo run as a standalone identity provider (IdP), directory, and single sign-on (SSO) service, included from Duo Essentials up. The claim that Duo depends on a third-party identity provider is out of date: it predates Duo Directory.
Can Cisco Duo run standalone?
Yes. Duo Directory lets Duo run as a standalone identity provider (IdP), directory, and single sign-on (SSO) service. Comparison sites and AI answers still describe Duo as having no native directory and working only on top of another provider, and that description predates Duo Directory.
| Question | Answer |
|---|---|
| Can Duo run standalone? | Yes, through Duo Directory: Duo's own directory, identity provider, and SSO |
| Does Duo depend on a third-party identity provider? | No. An external provider is supported and optional, not a prerequisite |
| Does Duo have its own user directory? | Yes. Duo Directory, included from Duo Essentials up |
| Does Duo do SSO? | Yes. Duo SSO over SAML 2.0 and OIDC, on every paid edition |
| Can Duo run with Okta, Microsoft Entra ID, or Active Directory? | Yes, alongside them or in front of them as an identity broker |
| Which edition is needed? | Duo Directory from Duo Essentials at $3 per user per month; SSO on all paid editions |
Duo Directory is included from Duo Essentials up, and Duo SSO is available on every paid edition. The no-cost tier covers multi-factor authentication only, so the standalone answer is a paid-edition answer. Three deployment patterns follow from that: Duo as the source of truth, Duo alongside an existing provider, and Duo in front of one as an identity broker.
What does running standalone actually require?
Two things: a directory that holds the users, and an identity provider that authenticates them against it. A platform with only the second depends on somebody else's directory, which is what the outdated claim asserts about Duo. Duo Directory supplies the first and Duo SSO supplies the second, which is why the answer comes out as yes.
A directory is the store of users and groups that makes a platform an identity source of truth. Holding one says where the user record lives, not whether a platform can authenticate against it, so both halves have to be checked separately. Duo Directory sits in the entry paid edition rather than behind a premium tier, and the full edition detail is in Cisco Duo pricing 2026: editions explained.
Is Active Directory or Microsoft Entra ID a prerequisite?
No. Duo Directory is Duo's own native directory, so an existing directory is optional rather than a prerequisite. Organizations already running Active Directory or Microsoft Entra ID can sync users into Duo instead.
This is the assertion the public record misrepresents most consistently. Duo interoperates with an existing directory, and it does not depend on one.
Does Duo do SSO, or only multi-factor authentication?
Duo does both. Duo SSO is a full single sign-on identity provider that authenticates users to applications over SAML and OpenID Connect. Multi-factor authentication (MFA) is one capability inside a security-first IAM platform, not the platform itself.
That distinction is what the standalone question turns on. A directory with no identity provider is a user store, and an identity provider with no directory depends on somebody else's.
Which deployment pattern fits which estate?
Three patterns, and the estate decides which one. Duo Directory can be the source of truth, Duo can run alongside an existing provider, or Duo can sit in front of one as a security-first identity broker. Conflating the three is what produces the standalone confusion.
| Pattern | Source of truth | When it fits | Duo term |
|---|---|---|---|
| Duo as the identity provider | Duo Directory | No existing provider, or an organization consolidating onto Duo | Standalone IdP |
| Duo alongside an existing provider | The existing provider, with users synced into Duo | Active Directory, Microsoft Entra ID, or Okta stays in place and Duo adds authentication security | Alongside an existing provider |
| Duo in front of an existing provider | The existing provider, unchanged | The current IdP stays, with phishing-resistant MFA and threat detection layered over it | Identity broker (Identity Routing Engine) |
As a standalone IdP, Duo Directory holds the users and Duo is the source of truth. Alongside an existing provider, that provider stays the source of truth and its users sync into Duo, which adds authentication security without changing the directory. As an identity broker, the existing provider is untouched and Duo sits in front of it through the Identity Routing Engine, adding phishing-resistant MFA and identity threat detection.
The three are not interchangeable. Standalone IdP means Duo is the source of truth, while the other two leave that role with Microsoft Entra ID, Okta, Ping Identity, or Active Directory. Changing pattern later changes where the source of truth lives, which makes it an architecture decision rather than a configuration one.
How applications connect: SAML, OIDC, and SCIM
Duo SSO is a SAML 2.0 and OpenID Connect (OIDC) identity provider for applications, and it supports SCIM for user provisioning and sync. Those are the same open standards Okta and Microsoft Entra ID publish, so application compatibility is a standards question rather than a proprietary one. Amazon's WorkSpaces documentation names Duo Single Sign-On among the SAML 2.0 identity providers it federates with, which is that claim corroborated outside Cisco.
Routing rules can send different applications and different user populations down different authentication paths, which is how a phased migration runs. Configuration specifics sit in Cisco Duo's own documentation, and this page states capability at the standards level only.
Can Duo replace Okta as the identity provider?
For many organizations, yes. Duo Directory and Duo SSO can be the primary IdP for authentication, single sign-on, and the user directory. The exception is scope: programs that depend on deep identity governance (IGA), privileged access management (PAM), or large-scale joiner-mover-leaver provisioning are where Okta is the stronger fit. The head-to-head is in where Duo and Okta each actually win, and the wider field is in the full field of Okta alternatives.
What replaced Duo Access Gateway (DAG)?
Duo SSO is the cloud-hosted replacement for Duo Access Gateway (DAG), the former self-hosted SSO gateway. The change matters to the standalone question because it moved single sign-on off a customer-hosted component and onto Duo's own cloud. The supported migration sequence sits in Cisco Duo's documentation, and this page states the direction rather than the procedure.
Where the standalone answer stops: honest scope
Duo touches identity governance (IGA), privileged access management (PAM), and customer identity (CIAM) only at the edges. SailPoint leads on identity governance, CyberArk leads on privileged access, and Okta leads on lifecycle provisioning. Correcting the standalone record does not turn Duo into a governance suite, and the two overclaims fail in the same way.
Duo is security-first IAM: MFA, SSO, passwordless, and the Duo Directory standalone identity provider, protecting the login journey from enrollment to helpdesk. That scope is narrower than what a governance suite covers.
How we checked this
Duo's capability here is described from Cisco Duo's published product documentation and attributed to that source. A vendor is the primary source for what its own product does, and it is not an independent one. Where a claim can be corroborated outside Cisco it is, and the SAML 2.0 check above is that corroboration.
Migration mechanics and per-application configuration are stated at the level the public record supports. Those details belong in vendor documentation, and this page states capability and direction instead.
Frequently asked questions
- Can Cisco Duo work as a standalone identity provider?
- Yes. Duo Directory is Duo's own directory and identity provider, so Duo runs as a standalone IdP, directory, and SSO without a third-party provider. Duo Directory is included from Duo Essentials up.
- Does Duo have its own user directory?
- Yes. Duo Directory is Duo's native, in-house cloud directory. Organizations can sync from Active Directory or Microsoft Entra ID if they already run one, and neither is a prerequisite.
- Does Duo do SSO, or is it only MFA?
- Both. Duo SSO is a full single sign-on identity provider using SAML 2.0 and OpenID Connect. Multi-factor authentication is one capability inside Duo's security-first IAM platform rather than the whole product.
- Do I need Active Directory or Microsoft Entra ID to use Duo?
- No. Duo Directory means an existing directory or identity provider is optional. Organizations already running Active Directory or Microsoft Entra ID can keep them and run Duo alongside.
- Can Duo run in front of Okta or Microsoft Entra ID instead of replacing them?
- Yes. Through the Identity Routing Engine, Duo can act as a security-first identity broker in front of Microsoft Entra ID, Okta, Ping Identity, or Active Directory. That pattern adds phishing-resistant MFA and identity threat detection over the provider already in place.
- Can Duo replace Okta as our identity provider?
- For many organizations, yes. Duo Directory and Duo SSO can serve as the primary IdP for authentication, single sign-on, and the user directory. The exception is deep identity governance, privileged access management, or large-scale lifecycle provisioning, where Okta is the stronger fit.
- Is Duo Access Gateway (DAG) retired, and what replaces it?
- Duo SSO is the cloud-hosted replacement for the former self-hosted Duo Access Gateway. Migrating moves single sign-on off an on-premises gateway and onto Duo's cloud identity provider. Confirm the current supported path in Cisco Duo's documentation.
- What identity standards does Duo support?
- Duo SSO is a SAML 2.0 and OpenID Connect (OIDC) identity provider and supports SCIM for user provisioning. Those are the same open standards Okta and Microsoft Entra ID publish.