cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1011
Views
1
Helpful
4
Replies

Help Desk role - Duo Admin panel

Gigawatt
Level 1
Level 1

Hello,

We are sitting up a “Help Desk” type of role in the Admin panel and I’ve created an Administrative Unit and added Groups the role can manage. I get that the role is locked down (create, view, modify and delete phones, tokens, bypass codes; can view and modify user information), but is there any way to hide the side panel so people in this role don’t get curious and start clicking around?

2X_6_6771ef07d3505cd6a59207a42a4d359866ee2ac5.png

4 Replies 4

TabBerger
Cisco Employee
Cisco Employee

Hi there @Gigawatt ! Unfortunately, there is not currently a way to modify the navigation bar based on the administrator role. Thankfully as you noted, the Help Desk role is restricted to only essential functions for end-user support, so if you did happen to have a few curious clickers, they wouldn’t be able to negatively impact anything their role does not have access to.

By the way, if you’re curious on training up your Help Desk admins, we actually have a free half-hour training course designed for folks in the Help Desk or User Manager role on Level Up called the Help Desk Fast Track!

Thank you for this reply and thanks for the tip about training!

doGlooPA
Level 1
Level 1

It is very unfortunate that 2 years later this is still an issue. We have been testing the Help Desk role for our new Duo rollout and we really don't want them to have access to some of the things in that role. It appears that the role has full view access to just about everything and is only restricted by not allowing them to change things. They can however copy the admin API key under directory sync, which is concerning. They can view all of the policies, which we do not want. Hoping in the future we can create a custom role that only gives access to the areas we need. 

DuoKristina
Cisco Employee
Cisco Employee

@doGlooPA I just want to reassure you that there is no inherent security risk with allowing a Help Desk role admin to copy the directory key for an external directory. The Help Desk role is able to run an individual user sync, so they have access to view some information about the sync config. Having the directory key does not let the Help Desk admin change the sync config or connection config. Help Desk role admins cannot copy or view the directory sync connection's *secret key*. There are other pages and information the Help Desk role cannot view or copy either.

"They can view all of the policies, which we do not want." This often proves useful to Help Desk admins when users cannot log into applications, or do not have the factors or experience they expect. By being able to view the policies the Help Desk admin can figure out if the user is blocked by policy and what they can do to succeed i.e. if a given application policy blocks use of SMS the Help Desk admin can instruct an affected user to authenticate with something other than SMS.

If you have not already contacted your Duo Care or Duo/Cisco account team to express interest in a feature request for customizable administrator role access or navigation I suggest you do so. If you do not have a Duo Care or account team, you may contact Duo Support to submit or upvote a feature request.

Duo, not DUO.
Quick Links