cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1755
Views
0
Helpful
4
Comments
kyleleighavery
Cisco Employee
Cisco Employee

 

Hello everyone! Here are the release notes for our most recent updates to Duo.

Public release notes are published on the Customer Community every other Friday, the day after the D-release is completely rolled out. You can subscribe to notifications for new release notes by following the process described here. If you have any questions about these changes, please comment below.

Check out the Guide to Duo End-of-Life and End-of-Support Plans. This guide provides an up-to-date list of current and past end-of-life plans for Duo products.

 

New features, enhancements, and other improvements

Now in public preview: Duo Mobile with time-based one-time passcodes (TOTP)

 

Now in public preview: Require user verification with PIN or biometric for WebAuthn roaming authenticators

  • Administrators can require user verification through a PIN or biometric method when enrolling or authenticating with a roaming authenticator through the Authentication Methods policy in the Policies section of the Duo Admin Panel.
  • Please note:
    • This setting will immediately require a PIN/biometric for all policy-affected roaming authenticator registrations and authentications, regardless of whether a PIN/biometric was previously set.
    • Depending on the device and browser you are using, you may need to remove and re-enroll or separately configure a PIN/biometric for your security key before you can continue to use it for authentication. 
    • This option blocks roaming authenticators that do not support FIDO2 user verification.
    • See also: What are the effects of requiring user verification for WebAuthn roaming authenticators in the Authentication Methods policy?
    • While user verification is optional for two-factor authentication (2FA), it is always required for passwordless authentication.

 

The authentication methods section of Policies now shows the option to require user verification with PIN or biometric.The authentication methods section of Policies now shows the option to require user verification with PIN or biometric.

 

Now in public preview: Duo Universal Prompt support for Device Management Portal

  • Administrators using an on-premises Device Management Portal application can now migrate to the Universal Prompt. 
  • An existing Device Management Portal application requires  Duo Web SDK 4 or the Duo OIDC Auth API

 

Now in public preview: Policy Compact View in Duo Admin Panel

  • Administrators can see a new, compact view of Policies. Policies will not change between the original view and the compact view, and admins can switch between them as desired.

 

You can now manage policies in compact view.You can now manage policies in compact view.

An example of the compact view.An example of the compact view.

 

New button to copy the Duo IdP certificate for Duo Single Sign-On (SSO) named integrations

  • Administrators can select Copy certificate In the Duo Admin Panel, under Downloads, to make a copy of the Duo identity provider certificate file text to use while configuring named SSO integrations.

 

Update to the Universal Prompt Progress report

  • Bitwarden apps are now displayed as Update required in the Universal Prompt Progress report.

 

Update to supported browsers for platform authenticators

 

Update to Risk-Based Remembered Devices experience

  • End users will now receive a prompt asking them to acknowledge if they are on a shared device before they set up a new Risk-Based Remembered Devices session.

 

A prompt now asks "Is this your device?"A prompt now asks "Is this your device?"
  • End users will also have a Remember me checkbox in Universal Prompt that they can select to be remembered.

 

There is now a "remember me" checkbox in Universal Prompt.There is now a "remember me" checkbox in Universal Prompt.

 

New and updated applications

Four new named SAML applications with Duo SSO

 

Duo Desktop macOS public beta version 6.5.3 released

  • Fixed an issue that could prevent authentications from completing in the traditional Duo Prompt.

Duo Desktop Windows public beta version 6.5.3 released

  • Minor improvements and enhancements.

Duo Mobile for Android version 4.61.0 released

  • Miscellaneous bug fixes and behind-the-scenes improvements.

Duo Mobile for iOS version 4.61.0 released

  • Miscellaneous bug fixes and behind-the-scenes improvements.

Bug fixes

  • Duo Trust Monitor: Group names that are put into bypass status are now visible in the Duo Trust Monitor Notification Email.
  • Risk-Based Factor Selection: Fixed issue where end users could not resolve their step-up status upon successfully authenticating with a more secure factor.
  • Universal Prompt: Fixed bug that sent SMS refresh codes even though SMS refresh is not supported by Universal Prompt.

 

Comments
Gigawatt
Level 1
Level 1

Now in public preview: Duo Universal Prompt support for Device Management Portal

Can this get elaborated on? We have OnPrem Proxy's in our setup, along with the self service portal on Duo Central. 

 

SAML applications with Duo SSO

Can "Procore", "Paypal", &"Globalscape EFT", be added? A lot of these are templates in Azure & Okta. We have several SAML integrations in Duo SSO, maybe one of these days I'll get to use one of your pre-built named templates  

kyleleighavery
Cisco Employee
Cisco Employee

Please note: Rollout of D287 is currently paused to accommodate fixes and will resume next week.

landyn
Cisco Employee
Cisco Employee

@Gigawatt , if you're using Duo Central Device Management, the Device Management Portal application is not likely to be relevant to you. The documentation linked in the release notes covers how this would be set up, but it is essentially the ability to use our Web SDK 4 (or OIDC Auth API) to directly invoke the Universal Prompt's Self-Service Portal. This assumes you have a website with primary authentication already configured and want to allow your users to access the SSP from a dedicated link. This is identical functionality to using the dedicated URL for Duo Central Device Management, but configured in your environment instead of fully hosted by Duo.

kyleleighavery
Cisco Employee
Cisco Employee

Update: D287 unpaused and rolled out.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Quick Links