Cisco's DUO Multi-factor Authentication (MFA) is a security product that requires a second authentication factor during login for access to VPNs, web applications, and custom systems. It supports various authentication methods, including push notifications via the Duo Mobile app, biometric and WebAuthn verification, physical security keys compliant with FIDO2 and U2F standards, hardware OTP tokens, SMS and time-based one-time passcodes, and phone call verification. The system can inspect the security posture of connecting devices by checking for enabled firewalls, screen locks, device encryption, and specific operating system versions, enforcing health standards before granting access. Administrators can define distinct access policies for individual applications, dynamically adjust authentication requirements based on contextual risk signals like geolocation, and configure bypass codes for exception cases. DUO integrates with existing infrastructure through standard protocols such as SAML, RADIUS, and LDAP, and provides APIs for custom integrations, while also offering detailed authentication logs and reporting.