Details

This incident response workflow allows you to add users involved in an incident to a group in Cisco Duo from a playbook or using an automation rule. When using this workflow in a playbook, the user selects which users to add to the group. When using this workflow with an incident automation rule, all users involved in the incident are added to the group.

Description

This incident response workflow allows you to add users involved in an incident to a group in Cisco Duo from a playbook or using an automation rule. When using this workflow in a playbook, the user selects which users to add to the group. When using this workflow with an incident automation rule, all users involved in the incident are added to the group. Supported observables: user, email

Target: Cisco Duo

Steps:

  • Detect the start type and extract the supported observables
  • Check if supported observables were found (if not, end the workflow)
  • Search for the Duo user group (if not found, end the workflow)
  • For each supported observable:
    • Attempt to find a matching user in Duo
    • If the user was not found, update the workflow result and continue
    • If the user was found, attempt to add them to the group
    • Check if adding them was successful and update the workflow result accordingly
Required targets

This workflow requires the following targets to be available before it can be run.

Integration targets

  • Cisco Duo
About
Author
Cisco
Version
v1.1
Intent
Incident Response
Integration
Average rating
No ratings yet
Authorship
Cisco Managed
Contact and support information
External links
Related workflows
Cisco Managed
This workflow appears in the pivot menu and allows you to add a user to a group in Cisco Duo.
Cisco Managed
This incident response workflow allows you to add users involved in an incident to a group in Cisco Duo from a playbook or using an automation rule.
Cisco Managed
This workflow appears in the pivot menu and allows you to change a user’s status in Cisco Duo.
Cisco Managed
This incident response workflow allows you to change the status of one or more users in Cisco Duo from a playbook or using an automation rule.