John Gunn, CEO, Token
2 minute read
If you are a Cisco Duo customer evaluating hardware token options, this page covers what you need to know. The TokenCore wearable integrates directly with Duo SSO, adds biometric authentication across all your Duo-managed applications and replaces legacy MFA factors that can be bypassed. The sections below cover what the device does, how the integration works and what switching looks like.
The TokenCore wearable is a biometric ring. When a user authenticates, the ring reads their fingerprint and generates a FIDO2-compliant credential bound to the specific site and device. No code is transmitted. Nothing leaves the ring that an attacker can capture or relay.
Authentication requires a live biometric match. Anyone who picks up the ring cannot use it. Credentials are origin-bound, so a phishing site cannot produce a valid challenge for a domain it does not control. The biometric template never leaves the device. There is no central database of fingerprint data to breach.
For Duo customers, this closes the gap that legacy MFA leaves open. Duo manages access. The TokenCore device manages the identity assurance behind each login.

TokenCore integrates with Cisco Duo’s SSO platform. Once configured, users authenticate once with their ring and gain access to all applications managed by Duo without repeated logins.
The integration does not require changes to the application layer. Duo manages the access policies. The TokenCore ring handles the authentication step. For IT teams already running Duo, adding the ring is additive rather than disruptive.
Duo’s existing access policies and conditional access rules apply as normal. Biometric authentication is extended across the full application suite without additional configuration per application.

Users receive the ring, enroll their fingerprint and the setup is complete. From that point, authentication is a tap. There is no app to open, no code to copy and no push notification to approve.
IT teams manage fewer authentication systems. The ring replaces phone-based factors that require per-device enrollment and ongoing support. Lost or forgotten authentication factors are among the most common helpdesk requests. A wearable that stays on the user’s finger addresses that directly.
Rings are provisioned, enrolled and distributed centrally. Duo policies apply automatically across managed applications. No changes to the application layer are required.
Most Duo customers running legacy MFA are using SMS codes, push notifications or time-based OTPs. All three produce factors that can be intercepted, relayed or approved under social pressure. They are better than passwords alone. They are not phishing-resistant.
The TokenCore ring replaces those factors at the authentication layer. It produces nothing that can be relayed. A phishing attack that captures credentials still fails at the authentication step because the ring will not generate a valid credential for a domain it does not recognize.
For Duo customers, the practical question is not whether to add hardware MFA. It is whether the hardware MFA they choose closes the relay gap. The ring does.
The collaboration between Cisco Duo and Token is a step forward in making security both accessible and effective. It addresses the need for a security solution that is easy to implement and use, without compromising on protection. As organizations continue to navigate the complexities of digital security, the Duo-Token integration serves as a model for how to balance security needs with usability.
In essence, this partnership is about providing a streamlined, secure authentication experience that meets the needs of today’s diverse and dynamic work environments. It’s an approach that recognizes the importance of both security and simplicity, offering a blueprint for future advancements in the field.
A study from UC San Diego Health ran nearly 20,000 employees through ten simulated phishing campaigns over eight months. Training made almost no difference. Employees who had recently completed mandatory cyber awareness courses failed phishing tests at virtually the same rate as those who had not. The measured improvement was just 1.7%. More than 75% of employees spent less than a minute on the training material. Millions are spent on annual training. The phishing success rate stays the same. The lesson is clear. Training alone does not protect enterprises from phishing.
The comparison between next-generation MFA and legacy MFA comes down to a single question. What does an attacker need to defeat it? Legacy MFA adds a step to the login process. If that step produces a value that can be intercepted, forwarded or socially engineered out of a user, the step exists but the protection does not. Next-generation MFA is designed so there is nothing to intercept. The sections below cover each core weakness of legacy MFA and the next-generation property that eliminates it.
Phishing attacks no longer rely on obvious tells. Misspelled words, generic greetings, and suspicious domains are yesterday’s problem. Today, the most effective phishing campaigns use Unicode characters that look identical to the characters they replace. The fake URL looks real. The fake site looks real. There is nothing for the human eye or most security tools to catch. The deception happens at a level most people never inspect.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.