We're considering Cisco Duo to add multi-factor authentication to our VPN and possibly other services. Before moving ahead, I'd like to hear from people who have deployed and supported it: How easy was implementation, how reliable and user-friendly has it been, and how responsive is support? We have also had difficulty reaching Cisco's sales team despite calling and submitting multiple web forms, so advice on purchasing or onboarding would be useful too.
5 Answers
Overall, Duo has been reliable, straightforward to deploy, and very easy for users. People have used it for VPN, Windows logon, RADIUS, SSH, and third-party applications with few problems. The documentation is unusually good, including setup guides for common Microsoft integrations.
There are a few practical limitations. Network outages can make push authentication frustrating, although offline authentication can help. Some remote desktop scenarios have limited authentication options, and repeated prompts when laptops lock, unlock, or switch between docked and wireless networks can get annoying. For a normal VPN deployment, though, most administrators report a smooth experience.
The main purchasing advice is not to depend on Cisco's direct sales process. Duo is commonly sold through a VAR or reseller, and that route tends to make onboarding, pricing, and implementation assistance much smoother. Bulk pricing may also be better than the standard public rate.
The product is solid, but check the pricing and compare it with capabilities you may already own. Organizations heavily invested in Microsoft Entra may find Microsoft Authenticator covers most of their MFA and SSO requirements without adding another platform. Running both can also be inconvenient for users.
The user experience is one of Duo's strongest points. Push approvals are quick, phone replacement is handled fairly well, and users can fall back to calls, texts, hardware tokens, or security keys depending on the setup. There is also a free tier and trial, which can be useful for testing before committing.
The downside is that some users refuse to install an authenticator on a personal phone. Hardware tokens work well for those cases, but text and voice authentication can have usage limits and extra costs.

I had a similar experience. It was one of the easier MFA rollouts I've handled, even with a large number of integrations and less technically confident users.