Hello everyone! Here are the release notes for our most recent updates to Duo. This will be our last release update for the year. We’ll see you again in January 2026.
Public release notes are published on the Customer Community every other Friday, the day after the D-release is completely rolled out to commercial deployments. You can subscribe to notifications for new release notes by following the process described here. Check the Duo cloud service release version for your Duo account from the Duo Admin Panel.
If you have any questions about these changes, please comment below.
Review the Guide to Duo End-of-Life and End-of-Support Plans. This guide provides an up-to-date list of current and past end-of-life plans for Duo products.
Cisco Duo
New Features
Now Available in Beta: Remote onboarding identity verification
- Identity verification now appears as a section in User Enrollment & Account Management Policies. When configured and enabled, this policy will require enrolling users to complete a successful identity verification in Persona before enrolling any devices. They will be redirected to Persona from the Universal Prompt and will be returned to Duo to complete enrollment once they have successfully verified their identity.
- Allows MSP employees set up as users on the parent account and placed into a group to authenticate using Duo into subaccount applications.
- Refresh Token behavior changed to add offline_scope in scopes list, which can be assigned.
Enhancements
- The Device Enrollment section UI on the User details pages in the Admin Panel has been updated. The order and spacing of text and buttons has been changed to be more consistent, and the timestamp text displayed after sending an enrollment email has been updated to be more accurate.
- Updated UI for unenrolled users:


- Activity logs - When Duo Mobile generates an activation code for a phone number that has not been added to Duo, the affected item is now labeled as a “Pending Phone Activation” to help distinguish these cases from activations on already enrolled phones.
New and Updated Applications
- There are four new named SAML applications:
- There are two new named OIDC applications:
- Corrects an issue where enrollments for offline access and passwordless OS logon were not persisted on upgrade via silent install.
- Corrects an issue where custom registry keys (such as ProvidersWhitelist) may not have persisted on upgrade via silent install.
- Corrects an issue where the GUI installer may not have deleted registry export files after completing installation.
- The ARM64 installer now supports a specified value for EnableCertPinning during silent install.
- RHEL 10 and CentOS Stream 10 packages correctly include an SELinux module.
- Beta release of Duo Universal Prompt authentication for Epic Hyperdrive. The browser-based Universal Prompt now appears in an Edge webview window. Learn more in the beta documentation.
- Disable CGO on Linux DuoConnect build.
- Miscellaneous bug fixes and behind-the-scenes improvements.
- Miscellaneous bug fixes and behind-the-scenes improvements.
Bug Fixes
- Fixed an issue where Verified Push checkbox was disabled for admin login factors if Push was used to login to the admin panel.
- Update Veeam Backup Replication Integration to make SSO URL schema flexible.