Overview

Cisco Duo is an identity management service that eliminates the username and password struggle. Duo authenticates your users using existing on-premises or cloud-based directory credentials and prompts for two-factor authentication before permitting access. Single Sign-On (SSO) from Duo provides users with an easy and consistent login experience for any and every application, whether it’s on-premises or cloud-based.

The Cisco Duo SSO integration in Profit.co uses SAML authentication to allow users to log in to Profit.co securely through Duo, with centralized identity verification and optional two-factor authentication.

What This Integration Supports

With the Cisco Duo SSO integration, you can:

  • Enable SAML-based Single Sign-On for Profit.co
  • Authenticate users via Duo using existing directory credentials
  • Provision users from Cisco Duo to Profit.co User Management via SCIM
  • Automatically deactivate or remove users in Profit.co when removed from a Duo group
  • Enforce two-factor authentication (2FA) before granting access
  • Manage user enrollment and device verification from the Duo Admin Panel
  • Support multiple Profit.co regions (US, EU, ME, SA)

Prerequisites

Before starting, ensure the following requirements are met:

  • You have a valid Cisco Duo admin account
  • You are logged in as a Super User in Profit.co
  • Users have valid email addresses configured in Duo
  • The Profit.co application is accessible from your environment
  • For user provisioning: You have the API Key and SCIM Key from Profit.co Settings -> Security -> API Access

Note: Only Super Users can configure SSO integrations in Profit.co.

Configure Cisco Duo SSO

Step 1:

Log in to your Duo account as an admin or register at https://admin.duosecurity.com/.

Enter your admin credentials and click Continue to proceed.

cisco-duo-admin-login

Step 2:

Navigate to the Applications tab and select Application in the panel.

Click the + Add Application button to open the application catalog.

duo-applications-panel
duo-add-application

Step 3:

In the application catalog search bar, select Generic SAML Service Provider from the list, then click + Add.

duo-generic-saml-service-provider

Enter the Application Name under Basic Configuration. Enter a name based on your preference (e.g. Profit.co).

duo-generic-saml-service-provider

Step 4:

Enter the following information.

Entity IDurn:profit-prod:profit-prod-sso-auth
NameID formaturn:oasis:names:tc:SAML:1.1:nameid-format:emailaddress
NameID Attribute<Email Address>
ACS URL
US region
https://app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=CISCO_DUO_GATEWAY
EU region
https://eu2-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=CISCO_DUO_GATEWAY
ME region
https://me1-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=CISCO_DUO_GATEWAY
SA region
https://sa1-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=CISCO_DUO_GATEWAY
Signature AlgorithmSHA-256
Signing OptionsSign assertion
Map Attributes
Idp AttributeSAML Response Attribute
<usernames>username

Click + Add an ACS URL under the Service Provider section to enter the region URL.

duo-service-provider-entity-id-acs-url
duo-saml-response-nameid-format
duo-map-attributes

Step 5:

Click Save to update the configuration.

duo-settings-save

After saving, click Download XML under the Downloads section to obtain the Issuer ID and X509 Certificate. You will need these values in a later step.

duo-download-saml-metadata-xml

Step 6:

In the left navigation panel, go to Applications → Duo Central.

duo-download-saml-metadata-xml

Click + Add tile to begin adding a Profit.co application tile.

duo-central-add-tile

Step 7:

On the Add Tile page, select Add Application Tile from the options presented.

duo-add-application-tile

Step 8:

On the Add Application Tiles page, locate and select Profit.co.

Click Add Tile to confirm.

duo-select-profit-co-application-tile

Step 9:

Click the Duo Central URL displayed in the top-right corner of the Duo Central page. You’ll be redirected to the SSO login page, where users can enter your email address to sign in.

duo-central-subdomain-url
duo-central-subdomain-url

Click the profit.co link to access the profit.co OKRs page.

duo-central-subdomain-url

Step 10:

Switch to Profit.co to complete the connection.

  • Navigate to Settings from the left navigation panel.
  • Click Integrations.
  • On the Connectors page, switch to the SAML SSO tab.
  • Locate Cisco Duo and click the Authorize button.
profit-co-saml-sso-cisco-duo-authorize
  • In the Register Cisco Duo panel that opens, paste the entity ID and X509Certificate values obtained from the downloaded XML file.
  • Click Authorize to save.
register-cisco-duo-issuer-id-x509-certificate

Configure Cisco Duo User Provisioning for Profit.co

SCIM-based provisioning keeps Profit.co user accounts automatically in sync with Cisco Duo. When a user is added to a provisioned group in Duo, they are automatically created in Profit.co User Management.

Requirements

You need Admin access in Profit.co to retrieve the API Key and SCIM Key.

  • Navigate to Settings -> Security -> API Access in Profit.co
  • Copy your API Key and SCIM Key
  • Form the token using the format: API_KEY:SCIM_KEY
duo-users-device-enrollment

Step 1

Connect Cisco Duo to Profit.co’s SCIM endpoint using your API credentials.

  1. In the Cisco Duo Admin Panel, go to Applications and open the Profit.co app.
  2. Click the Provisioning tab.
  3. Under Provisioning Mode, select Automatic.
  4. In the Authentication section, enter the following:
FieldValue
Authentication ModeBearer Token
Base URL
US region
https://app.profit.co/app/rest/platform/auth/scim/v2
EU region
https://eu2-app.profit.co/app/rest/platform/auth/scim/v2
ME region
https://me1-app.profit.co/app/rest/platform/auth/scim/v2
SA region
https://sa1-app.profit.co/app/rest/platform/auth/scim/v2
TokenAPI_KEY:SCIM_KEY
  1. Click Connect to application to validate the connection.
duo-users-device-enrollment

Step 2

Groups control which Duo users are provisioned to Profit.co.

  1. Navigate to Users -> Groups in the Duo Admin Panel and click + Add group.
  2. Enter a group name and click Save.
duo-users-device-enrollment
  1. Return to the Provisioning tab of the Profit.co app.
  2. Under the Groups section, select Select groups and choose the group you created.
duo-users-device-enrollment

Step 3

  1. Go to Users -> Groups and open the group you created.
  2. Click + Add users to group, search for the user, and click Add User To Group.
  3. Once the user is added to the group, they will be automatically created in Profit.co User Management.
duo-users-device-enrollment

Default Role Sync Based on Configuration in Profit.co

When Update default roles on user update is enabled, a user’s existing role in Profit.co is preserved when their record is updated through SCIM.

When this option is disabled, SCIM updates will assign the user the default role configured in Profit.co.

duo-users-device-enrollment

Restrict Re-Creation of Terminated Users

Profit.co provides a Restrict Re-Creation of Terminated Users option within the SCIM configuration.

When this toggle is enabled, users who have been terminated in Profit.co through SCIM provisioning cannot be automatically recreated, even if their account information is updated in Cisco Duo.

When this toggle is disabled, any subsequent update to a terminated user’s account in Cisco Duo may result in the user being recreated as a new user in Profit.co.

duo-users-device-enrollment

User Enrollment Flow

Once Cisco Duo SSO is configured, users must be enrolled in Duo before they can authenticate. The enrollment process can be initiated by the admin and completed by the user via an email invitation.

Step 1:

Log in to the Duo Admin Panel at https://admin.duosecurity.com/.

Navigate to Users in the left panel and click on the user you want to enroll.

For user enrollment-related queries, refer to the Duo enrollment guide

duo-users-device-enrollment

Step 2:

Under the Device enrollment section, click Send email. A confirmation banner will confirm the email was sent.

Note: You can also click Generate code to share an enrollment link manually.

duo-send-enrollment-email

Step 3:

The user receives an email from Duo Security (no-reply@duosecurity.com) with a unique enrollment link. Click the link to begin enrollment.

duo-security-enrollment-email

Step 4:

Clicking the enrollment link opens the Duo device management portal in the browser.

duo-enrollment-link

The user clicks Get started to proceed.

welcome-to-duo-security-get-started

Step 5:

Select a device type for identity verification:

  • Device verification (Recommended) — Uses the device’s biometrics or PIN.
  • Duo Mobile — Receives a push notification or passcode on a mobile device.
  • Security key — Uses a physical hardware security key.

For Duo Mobile, proceed with the steps below.

duo-add-a-device

Step 6:

Select the country code, enter your phone number, check the consent checkbox, and click Continue.

duo-enter-your-phone-number

Step 7:

Click Send me a passcode to receive a verification code via SMS, or Or call my phone for a voice call.

duo-confirm-your-phone-number

Step 8:

Scan the QR code using your camera app or the Use QR Code option in the Duo Mobile app to complete activation.

duo-mobile-scan-qr-code

Step 9:

Once activation is complete, the Device enrollment field in the Duo Admin Panel updates to Enrolled. The user can now log in to Profit.co using Cisco Duo SSO.

duo-device-enrollment-enrolled

Step 10:

Click the Duo Central subdomain URL. You will be redirected to the Duo page.

Click the profit.co link to access the profit.co OKRs page.

duo-central-profit-co-single-sign-on-tile
profit-co-okrs-view-after-cisco-duo-sso-login

Summary

By configuring Cisco Duo as a SAML identity provider in Profit.co, enabling SCIM-based user provisioning, and completing the user enrollment process, organizations can enforce secure, centralized authentication with two-factor verification. Users provisioned through Duo groups are automatically created in Profit.co, and their access is managed throughout the user lifecycle — ensuring only enrolled, verified users gain access across all supported regions.