Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/31/2017
12:00 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Duo Security Partners With VMware to Tackle Unmanaged Devices

The partnership is designed to address the influx of unmanaged devices accessing corporate applications.

ANN ARBOR, MI. - Duo Beyond integration with VMware Workspace ONE provides organizations with enhanced security for mobile device management.

The rapid onset of Bring Your Own Device (BYOD) initiatives in corporate IT has created a sea of unmanaged and unsecured devices with access to critical data, resulting in increased risk of data breach and compliance violation. To help IT administrators identify and enforce access policies for this growing population of users, Duo Security, the leading cloud-based Trusted Access provider and one of the fastest growing information security companies in the world, today released its Trusted Endpoints feature for mobile devices, building on the launch of Duo Beyond earlier this year.

Partnering with VMware and integrating with its digital workspace platform, VMware Workspace ONE™, Duo Beyond helps organizations identify managed and unmanaged mobile devices attempting to access corporate applications with sensitive data -- drastically simplifying the enforcement of mobile security policies.

"BYOD introduces a number of uncertainties into a company's security policy, mainly around the lack of visibility and control over personal vs. managed/corporate devices," said Jon Oberheide, Duo Security Co-Founder and Chief Technology Officer. "At the same time, the modern day workforce has become increasingly mobile and values the freedom to work from anywhere on any device. For this reason, IT administrators don't want to have to completely block the usage of personal devices within the organization, as often these are preferred for work. And they shouldn't have to."

Duo Beyond allows organizations to shift their IT security from a traditional perimeter-based approach to access policies based on device information, device health and the associated user. Now integrated with VMware Workspace ONE, Duo Beyond administrators have visibility into mobile devices that are connecting to their applications, coupled with the ability to enforce application and browser access policies based on the state of the device.

"Duo's partnership with VMware gives IT administrators the flexibility to set BYOD access policies based on the sensitivity of the application being accessed," said Oberheide. "While employees should be able to access less sensitive applications from any mobile device, more sensitive applications should require a VMware Workspace ONE-managed device. Our product integration with VMware makes this experience seamless for the end user."

"With the growing number of personal endpoints -- from smartphones to laptops to IoT devices - entering enterprise environments, IT departments are facing new and complex mobility management challenges. Accessing corporate resources from an unmanaged device can introduce a significant threat to corporate security," said Ashish Jain, vice president, product strategy, End-User Computing, VMware. "The integration of Duo Beyond with VMware Workspace ONE provides customers with a simplified, efficient way to view and manage all devices from a central admin console, enabling secure access to all sensitive company information and applications."

The Workspace ONE solution integrates application and access management, unified endpoint management (VMware AirWatch®), and virtual application delivery (VMware Horizon) to help organizations evolve silo-ed cloud and mobile investments. The platform enables all employees and devices across the organization to accelerate their digital transformation journey with a platform-based approach.

With more than one-third of access requests to a corporate network coming from outside the firewall, it is critical that organizations look beyond the existing security model. Duo Beyond, released in February 2017, is the first major commercial implementation of Google's BeyondCorp framework that markedly improves and simplifies security management of how employees and devices access critical corporate applications. With Trusted Endpoints, Duo Beyond customers now have visibility into all laptops, desktops and mobile devices accessing their corporate network -- regardless of whether the organization issued the device. 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9342
PUBLISHED: 2020-02-22
The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.
CVE-2020-9338
PUBLISHED: 2020-02-22
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
CVE-2020-9339
PUBLISHED: 2020-02-22
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
CVE-2020-9340
PUBLISHED: 2020-02-22
fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.
CVE-2020-9341
PUBLISHED: 2020-02-22
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.