Skip to main content

Put Cisco Duo MFA In Front Of Files.com

Connect Files.com to Cisco Duo with SAML. Now Duo's MFA and device-trust checks run before anyone opens a file. The access policy your security team already uses can now cover file transfer too. And Files.com adds its own 2FA on SFTP, FTP, and WebDAV.

No credit card required · 7-day free trial · Live in minutes

#1 MFT vendor in Gartner Peer Insights
Trusted by 4,000+ companies
Every protocol included
Cisco DuoFiles.com
  • G2 Leader — Managed File Transfer, Summer 2026
  • G2 Best Results — Managed File Transfer, Summer 2026
  • G2 Best Usability — Managed File Transfer, Summer 2026
  • G2 Best Relationship — Managed File Transfer, Summer 2026
  • G2 Easiest Setup — iPaaS, Summer 2026
  • AWS Partner — Files.com is a verified AWS Partner.
  • Google Cloud Partner — Files.com is a verified Google Cloud Partner.
  • Microsoft Partner — Files.com is a verified Microsoft Partner.

4,000+ organizations rely on Files.com every day

Real companies. Real file flows. Real results.

Marc Jacobs logo
Cognizant logo
Bloomberg logo
TowneBank logo
PBS logo
Carrier logo
Hot Topic logo
Planet Fitness logo
Kaplan logo
Ashley Furniture logo
KFC logo
Mitsubishi logo
Stamps.com logo
Kyndryl logo
CRISPR Therapeutics logo
Equifax logo
Banner Health logo
Norton Rose Fulbright logo
Michelin logo
Redis logo
e.l.f. logo
Lilly Pulitzer logo
New Era logo
Digicert logo
Toyota logo
BBB logo
GoDaddy logo
Hershey logo
Toast logo

Why Teams Put Duo In Front Of File Transfer

Your security team already runs Cisco Duo for strong sign-in and device trust. Connect Files.com to Duo, and signing in to your files runs through that same policy.

File Access Sits Behind The Policy You Already Run

People sign in to Files.com through Duo, so Duo's MFA and device-trust checks happen before anyone reaches a file. An unmanaged laptop is stopped at sign-in, not after it has your files.

A Second Factor Is The Default

Duo's MFA runs in front of every sign-in. Some accounts aren't managed by Duo. For those, Files.com adds its own 2FA, including hardware keys and authenticator apps.

Strong Logins Reach SFTP, Not Just The Browser

Strong sign-in doesn’t stop at the website. Files.com can require its own 2FA on the file-transfer protocols too. A partner connecting over SFTP gets the same check as someone signing in on the web, so the protocol nobody usually guards is locked down like everything else.

Connects Over SAML

Files.com connects to Duo through Duo's Generic SAML Service Provider. That's the standard sign-in method. Turn on SCIM and it syncs your users automatically too.

Duo Handles Sign-In, Files.com Handles Access

Duo handles strong sign-in: who the person is, and whether their device is trusted. It doesn't decide which folders that person can open once inside. Files.com adds that part. You get folder-by-folder access and a full record of every sign-in and sync.

Nine Levels Of Folder Access

Set access per person or group, folder by folder. You get nine levels, the option to block a folder, and fenced-off admins. Your Duo groups feed straight into Files.com folder permissions, so nobody sets file access by hand.

Every Event In The Audit Log

Every sign-in, sync, and permission change is captured in the Files.com audit log. The SCIM sync gets its own detailed log. It’s the record a compliance review asks for.

Hardware Keys And Authenticator Apps First

Files.com uses hardware keys and authenticator apps as the main 2FA methods. SMS and email are backups only. It's the same approach your Duo security team already takes.

SSO Enterprises Already Rely On

4,000+ organizations rely on Files.com, and SSO against Duo, Okta, Entra ID, or any SAML provider is how enterprise deployments keep file access tied to sign-in policy.

The Details That Matter For Cisco Duo

Duo Handles The Whole Account Lifecycle

With SCIM 2.0, Duo creates, updates, and turns off Files.com users and groups on its own. Group memberships sync too, and Files.com maps them to folder permissions and admin roles. Nobody has to touch Files.com.

Hardware-Key 2FA Reaches SFTP Too

For accounts Duo doesn't manage, Files.com 2FA covers Yubikey (WebAuthn and Native OTP), other hardware keys, authenticator apps, SMS, and email. Yubikey Native OTP and authenticator-app codes work over SFTP, FTP, and WebDAV. That's strong sign-in on the file-transfer protocols, not just the browser.

Connect Cisco Duo The Way That Fits Your Workload

SSO With SAML

This is the main connection. Add Files.com as an app in Duo through its Generic SAML Service Provider, then point Files.com back at Duo. Now your team signs in through Duo, and Duo’s MFA runs as part of that login. Your people get one less password to manage, and you get one place to enforce the policy.

Automatic Provisioning With SCIM

Turn on SCIM to have Duo create, update, and remove Files.com users and groups by itself. This is what shuts off access automatically when someone leaves.

Accounts On First Login (JIT)

There's nothing extra to set up. When SCIM is off, Files.com creates the account the first time a person signs in through Duo. It's good for getting started fast. JIT can't remove people, so add SCIM when you need that.

How Teams Use Cisco Duo On Files.com

Signing In With An MFA Check

A person clicks Sign in with Duo, passes Duo's MFA check, and lands in Files.com. Strong sign-in is confirmed before they reach any file.

A New Hire Is Set Up Automatically

Assign someone to Files.com in Duo. SCIM creates their account, puts them in the right groups, and applies their folder permissions. All on its own.

A Departing Person Is Cut Off

Turn someone off in Duo and the next sync shuts off their Files.com account across the web, SFTP, and the Desktop App at once. There’s no second user list to clean up.

A Hardware Key On A Partner's SFTP

A partner account that Duo doesn't manage can be required to use a Yubikey for 2FA. The Yubikey works on their SFTP connection too.

Files.com Features Teams Use With Cisco Duo

User Management & Permissions

The folder-by-folder access, with nine levels, that your Duo groups feed into.

Learn More

Audit Log & Forensic Trail

Where every Duo sign-in, sync, and permission change is recorded, ready to export for a compliance review.

Learn More

SFTP & Protocol Access

How 2FA and folder permissions reach SFTP, FTP, and WebDAV, not just the browser a person signs into.

Learn More

Data Retention & Governance

Rules that decide how long files stick around once someone has put them in Files.com.

Learn More
Files.com's strengths are simplicity, ease of use, and the cloud connectors. We don't have to invent custom infrastructure for every partner.
Tommy Chapley, Equifax
Tommy Chapley
Senior Software Engineer, Equifax
Files.com is versatile — it can manage many different situations from a single platform. We've consolidated multiple tools onto it.
Regis Litre, Rag & Bone
Regis Litre
Chief Information Officer, Rag & Bone
Files.com is robust and scales to a large enterprise. We get multiple files per minute, per second — and we're a 24/7 organization, so everything has to always be up.
Nelson Miranda, Spirit Airlines
Nelson Miranda
Sr. Systems Engineer, Spirit Airlines

Frequently Asked: Cisco Duo On Files.com

Here’s how sign-in, provisioning, and 2FA work once Duo sits in front of your Files.com site.

Yes. Files.com connects to Cisco Duo over SAML, set up through Duo's Generic SAML Service Provider. Your team signs in through Duo, so Duo's MFA runs before they reach Files.com.

Yes. Duo's MFA check runs as part of the sign-in, before the person is let into Files.com. For outside accounts Duo doesn't manage, Files.com can also require its own 2FA, which covers SFTP, FTP, and WebDAV.

Yes. With SCIM 2.0, Duo creates, updates, and turns off Files.com users and groups on its own. If you don't turn on SCIM, Files.com instead makes accounts on first login (JIT), but JIT can't turn people off.

Files.com supports Yubikey WebAuthn (recommended), Yubikey Native OTP, other WebAuthn hardware keys, authenticator apps, SMS, and email. Hardware keys and authenticator apps are the main methods; SMS and email are backups. Yubikey Native OTP and authenticator-app codes work over SFTP, FTP, and WebDAV.

No. Signing in through Duo works for the website and the Files.com Desktop App. SFTP, FTP, and WebDAV connections authenticate with an SSH key, an API key, or a password. Password sign-ins on those protocols can still be required to carry a Files.com 2FA code.

Files.com connects to Cisco Duo through Duo's Generic SAML Service Provider application. Files.com publishes its SAML metadata: the entity ID and ACS URL. Paste those into the Duo app, then copy Duo's IdP metadata back into Files.com's SSO settings. Once linked, every Files.com web and Desktop App login routes through Duo and its MFA.

Yes. When Duo provisions users into Files.com over SCIM 2.0, it syncs group memberships, and Files.com maps those groups to folder permissions and admin roles. Access follows the groups you already manage in Duo, with no per-user setup inside Files.com.

Yes. Every login lands in the immutable Files.com audit log with its authentication context, alongside every file action that session performed. The record covers who got in, how, and what they touched.

Yes. Internal users sign in through Duo while outside partners use local Files.com credentials scoped to their own folders. Files.com 2FA can be required on those partner accounts too.

Put File Transfer Behind Your Duo Policy

Start a 7-day free trial. Connect Duo with SAML, sign in with an MFA challenge, and see your file transfer sit behind the same access policy as everything else.

No credit card required • 7-day free trial • Live in minutes