Getting Your MFA Actually Ordered Without Losing Your Mind
The Cisco Duo Ordering Guide is basically a document you'll find when you're trying to provision Duo Security through Cisco's procurement channels. It outlines the steps for licensing, deployment configurations, and integration pathways between Duo and Cisco's broader identity ecosystem. You don't really need it if you're doing everything direct through Duo's portal, but if you're going through Cisco's procurement or partner channels, it's the thing that tells you which licenses go where and what integration options actually exist. I used to gloss over this guide early in my career because I didn't understand why I needed it. Then I ran into a real mess where we had tried to deploy Duo with Cisco Secure Endpoint integration without checking which license tier supported the API endpoints we needed. The guide would have told us that some of the deeper integrations only exist in the Advanced or Complete tiers. We ended up with a deployment that looked right on paper but couldn't authenticate properly through the Cisco side. Took about three weeks to untangle.
Cisco Duo Ordering Guide: What It Actually Covers
This isn't a full technical deployment manual. It's primarily a purchasing and planning document. It walks through license types, what each tier includes, how to estimate seat counts, and the general workflow for ordering through Cisco channels. If you need deployment configuration details, that's a separate document from Duo's documentation site. The Ordering Guide just tells you what you can buy and roughly what it does. The section most people skip is the one about deployment models. Duo can operate as a standalone MFA provider, but it also integrates with Cisco Identity Services Engine, Cisco Secure Firewall Management Center, and several other Cisco products. The ordering guide maps out which integrations require which license levels and which deployment architectures are supported. This matters because if you're planning to use Duo withISE for device authentication alongside user authentication, you need to know upfront whether your licensing covers both use cases.
How to Actually Use It When Ordering
Start by determining your user count and device count separately. Duo charges per user, but some integrations are also affected by device count because the policy engine evaluates both. A common mistake is underestimating devices. If you have 500 users and each user has four devices, you're potentially licensing for 2,000 endpoints in certain integration scenarios, not just 500 users. The guide lays this out, but it's easy to miss if you're focused only on human users. Next, identify which Cisco products you want Duo to integrate with. Write them down. Then check the ordering guide for which license tier supports each integration. Not every integration is available in every tier. The Starter tier is mostly standalone MFA. Advanced adds things like post-authentication controls and some Cisco product integrations. Complete is where you get the full feature set including tight integration with Cisco's security stack. One thing I learned the hard way: check whether your organization already has a Cisco services contract or a volume discount agreement. Sometimes the ordering guide prices don't reflect what your account team can actually offer. I once calculated a quote that came out to roughly $12 per user per year based on the guide, then found out our existing Cisco agreement dropped that to around $8. The guide is a reference point, not the final price.
Get the Full Details

When you submit the order through Cisco's procurement system, you'll need to provide a few things: your Duo account information if you already have one, the list of integrations you want enabled, the estimated user and device counts, and the deployment timeline. Some integrations require additional configuration steps after ordering. For example, if you're connecting Duo to ISE, there's a separate configuration process that happens post-deployment. The ordering guide mentions this but doesn't go into the technical details.
What the Guide Doesn't Tell You
The ordering guide won't cover the actual technical work of deploying Duo. It won't walk you through generating API keys, configuring RADIUS proxies, or setting up push notification infrastructure. That's all in Duo's documentation. The guide is purely about what to buy and how to buy it through Cisco's channels. Another gap: the guide doesn't address multi-tenant or reseller scenarios well. If you're a MSP or a partner ordering for multiple customers, the workflow is different and not clearly laid out in the standard ordering guide. You need to go through Cisco's partner procurement channels, which have their own processes. I spent a morning trying to figure out why my reseller portal wouldn't accept the ordering guide's recommendations. Turned out partner ordering requires different license SKUs entirely. There's also the question of legacy hardware integrations. If you're dealing with older Cisco ASA firewalls or older ISE deployments, some Duo integrations may not be supported or may require additional compatibility layers. The ordering guide assumes relatively current infrastructure. If your environment is a mix of old and new, plan for extra time on the integration side.
When the Ordering Guide Falls Short
If you're a small organization with fewer than 100 users and no Cisco products beyond basic firewalls, the ordering guide might be overkill. You can skip Cisco's procurement channel entirely and go direct through Duo's website. It's often faster and sometimes cheaper because you avoid any Cisco intermediary fees. The guide is most useful when you're already in Cisco's ecosystem and want single-vendor billing or when your organization has a Cisco services agreement that makes this route more cost-effective. The biggest practical limitation is that the guide can become outdated between Cisco product releases. New integrations drop periodically, and the guide sometimes lags. I've seen cases where the latest Cisco Secure Client integration wasn't reflected in the most recent ordering guide version. Always verify the guide's version date and cross-reference with Duo's current documentation before making a final decision. If you need the actual guide, it's available through Cisco's official documentation portal. Search for "Cisco Duo Security Ordering Guide" on cisco.com or ask your Cisco account team to send you the latest version. Don't rely on third-party PDFs floating around forums. Those are often outdated and can lead to ordering the wrong license tier.
