Hello everyone! Here are the release notes for our most recent updates to Duo.
Public release notes are published on the Customer Community every other Friday, the day after the D-release is completely rolled out to commercial deployments. You can subscribe to notifications for new release notes by following the process described here. Check the Duo cloud service release version for your Duo account from the Duo Admin Panel.
If you have any questions about these changes, please comment below.
Review the Guide to Duo End-of-Life and End-of-Support Plans. This guide provides an up-to-date list of current and past end-of-life plans for Duo products.
Cisco Duo
New Features
New “Optimize” Menu in Admin Panel
- The Admin Panel header now features a new "Optimize" menu in the header, which houses the "What's New" link previously found within the "Help" menu, and a new link for Duo Essentials, Advantage, and Premier customers and trials called "Optimize Your Setup".

- "Optimize Your Setup” provides a guided walkthrough for new and existing customers with recommended steps they can take when configuring Duo. Learn more about the optimization journeys in our Getting Started with Duo Security documentation.

- Administrators now have more secure default sessions in the Admin Panel, with a 30-minute default inactivity timeout and 60-minute default absolute timeout. These options are now configurable by owners on the Users > Administrators > Admin Login Settings page. The public preview rollout will expand gradually over the next few weeks.

- This management integration is supported for Windows OS and supports Universal Prompt and Duo Passwordless.
Enhancements
- Managed Service Providers: Subaccounts listed in the Accounts Page and in the drop-down Account Switcher are now filtered for non-Owner administrators based on Access Tags.
- This means that administrators cannot see subaccounts they do not have access to. If you only see a subset of subaccounts in the Accounts Switcher or Accounts Page, please check your Access Tags.
- Admin API responses for /phone endpoints now include the installed Duo Mobile version (if present) as app_version.
- Risk-based factor selection policy modal updated to include two additional secure methods for higher-risk authentications : “Desktop authentications” and “Passwordless Verified Duo Push”.

- Chrome OS operating system policy has been expanded from Allow/Block all to support static versioning and less than latest policy options.

- Passwordless remember me sessions have been increased from a maximum of 3 days to a maximum of 7 days.
- The global search (in the header at the top of the Admin Panel) can now search for users in the order (Last Name) (First Name), whereas before it was only (First Name) (Last Name).
New and Updated Applications
Reminder: Duo Access Gateway reached end of support for commercial customers on October 26, 2023. It remains supported only for Duo Federal customers.
- Adds support for new Duo certificate authorities.
- IPv6 support for communicating with other on-premises applications, servers, and devices. Please note that communication with Duo's cloud service will still resolve the API hostname to an IPv4 address.
- Connections to DNS hostnames will now honor multiple IP addresses and choose the fastest connection.
- No longer prints ModuleNotFoundError during successful build.
- Fix logfile rotation when an extra file exists in log directory
- Improves handling of None values in HTTP client.
- Add rate-limiting logic for 429 errors.
- Upgrade Python to 3.11.10 to address multiple CVEs, such as CVE-2024-6923 and CVE-2024-4030.
- Upgrade to Cryptography 43.01 / OpenSSL 3.3.2 to address CVE-2024-6119.
- Updates to various third-party dependencies.
- Bug fix to address Windows firewall issue with DuoConnect 2.0.6 and Application Relays. (Windows only)
- Maintenance release. (macOS and Linux)
- Release details:
- Public preview releases promoted to GA releases for macOS and Windows with no changes on April 17, 2025.
- Released as GA for Linux on April 21, 2025.
- Now a Universal Application that supports Apple ARM and Intel processors. (macOS only)
- Bug fixes to address Windows 11 24H2 issues with Application Relay support (RDP, SMB, etc.). (Windows only)
- Updated Go version used to compile DuoConnect to v1.24.1.
- Updated third-party libraries.
- Miscellaneous bug fixes and behind-the-scenes improvements.
- Miscellaneous bug fixes and behind-the-scenes improvements.
Bug Fixes
- Sorting the Admin Panel’s list of administrators by status now works correctly.
- Passwordless: Users no longer see the “Log In” page when they have a remembered device session.
- Additionally, users will no longer see the “Log In” page more than once during an interactive authentication. Previously they would see “Log In” at the beginning of authentication and again if they navigated to the self-service portal and then returned to that same authentication.