{
"vendor": "Duo Security",
"slug": "duo-security",
"platform": "statuspage",
"status_url": "https://status.duo.com",
"last_checked": "2026-09-16T12:28:20Z",
"last_state": "ok",
"history_backfilled": true,
"first_watched": "2026-09-04T07:06:16Z",
"incidents": [
{
"body": "This issue has been resolved.\n\nDuo hardware token authentication is now functioning normally on affected US deployments. Other Duo authentication methods were not expected to be impacted.\n\nThank you for your patience. If you continue to experience issues, please contact Duo Support.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-09-03T19:24:45.141-04:00",
"resolved_inferred": false,
"started_at": "2026-09-03T18:04:57.446-04:00",
"state": "resolved",
"title": "Duo - Partial Hardware Token Authentication Issues - United States",
"updated_at": "2026-09-03T19:24:45.160-04:00",
"url": "https://stspg.io/qh1zvjqv58d7"
},
{
"body": "This incident has been resolved.\n\nNew Duo account registrations are now functioning normally.\n\nThank you for your patience. If you continue to experience issues, please contact Duo Support.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-10T18:46:22.161-04:00",
"resolved_inferred": false,
"started_at": "2026-08-10T16:34:20.644-04:00",
"state": "resolved",
"title": "New Signups Unavailable",
"updated_at": "2026-08-10T18:46:22.177-04:00",
"url": "https://stspg.io/p0m52ps2474t"
},
{
"body": "Phone call authentication delivery for customers in the United States has returned to normal operation.\nIf customers continue to experience issues, please contact Duo Support.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-08T20:07:49.607-04:00",
"resolved_inferred": false,
"started_at": "2026-08-08T17:13:48.193-04:00",
"state": "resolved",
"title": "Duo Phone Call Authentication Failures - United States",
"updated_at": "2026-08-08T20:07:49.632-04:00",
"url": "https://stspg.io/7d70dz419kvq"
},
{
"body": "The SMS and VoIP delivery issue affecting users in Israel has been resolved. If customers continue to experience issues, please contact Duo Support.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-27T16:41:00.126-04:00",
"resolved_inferred": false,
"started_at": "2026-07-23T14:02:17.681-04:00",
"state": "resolved",
"title": "VoIP and SMS Delivery Issues in Israel",
"updated_at": "2026-07-27T16:41:00.140-04:00",
"url": "https://stspg.io/1rn7jrdl6864"
},
{
"body": "The third-party carrier issue affecting VoIP and SMS services in the Australia region has been resolved.\n\nPhone call and SMS authentication services are operating normally. We appreciate your patience and understanding while we addressed this issue.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-07-08T11:01:47.978-04:00",
"resolved_inferred": false,
"started_at": "2026-07-07T19:15:30.087-04:00",
"state": "resolved",
"title": "Duo - Phone call and SMS authentication issues - Australia",
"updated_at": "2026-07-08T11:01:47.996-04:00",
"url": "https://stspg.io/7kcxvr3mvzcl"
},
{
"body": "The SMS delivery issue affecting the UAE region has been resolved.\n\u00a0\nOur team has verified that SMS services are operating normally and full functionality has been restored. Thank you for your patience while we resolved this issue",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-23T10:21:26.315-04:00",
"resolved_inferred": false,
"started_at": "2026-06-22T23:58:45.000-04:00",
"state": "resolved",
"title": "UAE Telephony SMS issue",
"updated_at": "2026-06-23T10:21:26.342-04:00",
"url": "https://stspg.io/5rc0kcbkfcz9"
},
{
"body": "The issue affecting AI Assistant functionality in the US-W1 region has been resolved.\n\nOur team has verified that services are operating normally, and monitoring has confirmed system stability. Thank you for your patience while we resolved this issue.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-10T11:35:32.775-04:00",
"resolved_inferred": false,
"started_at": "2026-06-10T10:17:36.833-04:00",
"state": "resolved",
"title": "AI Assistant Service Disruption in US-W1",
"updated_at": "2026-06-10T11:35:32.795-04:00",
"url": "https://stspg.io/10mjtlhmcrgg"
},
{
"body": "The issue affecting AI Assistant functionality across all US deployments has been resolved, and full functionality has been restored. We will continue to monitor service performance to ensure stability.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-18T16:30:27.365-04:00",
"resolved_inferred": false,
"started_at": "2026-05-18T14:37:07.769-04:00",
"state": "resolved",
"title": "All US Deployments: AI Assistant failures",
"updated_at": "2026-05-18T16:30:27.396-04:00",
"url": "https://stspg.io/hrj4ndmlvbrc"
},
{
"body": "The issue causing authentication failures on DUO57 with the Duo Core Authentication Service is now resolved and full functionality has been restored.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-13T12:03:58.557-04:00",
"resolved_inferred": false,
"started_at": "2026-05-13T09:22:34.649-04:00",
"state": "resolved",
"title": "Authentication failures",
"updated_at": "2026-05-13T12:03:58.574-04:00",
"url": "https://stspg.io/4nd44tt9pgs6"
},
{
"body": "The issue affecting first-time access to the AI Assistant for administrators in the EU has been fully resolved, and normal functionality has been restored.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-07T18:40:14.439-04:00",
"resolved_inferred": false,
"started_at": "2026-05-07T10:17:04.835-04:00",
"state": "resolved",
"title": "AI Assistant First-Time Access Failures for EU Administrators",
"updated_at": "2026-05-07T18:40:14.459-04:00",
"url": "https://stspg.io/tynt4q38fktt"
},
{
"body": "The issue has been resolved. Services have returned to normal operation, and customers should no longer experience delays or failures.\nWe apologize for any inconvenience caused and thank you for your patience.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-04-30T14:07:29.028-04:00",
"resolved_inferred": false,
"started_at": "2026-04-30T13:54:25.955-04:00",
"state": "resolved",
"title": "Desktop Authenticator Enrollment Degradation",
"updated_at": "2026-04-30T14:07:29.046-04:00",
"url": "https://stspg.io/hvsyg07k91dy"
},
{
"body": "The issue causing elevated authentication latency has been fully resolved. Authentication performance has returned to normal levels, and customers should no longer experience delays during login attempts.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-04-28T11:26:01.191-04:00",
"resolved_inferred": false,
"started_at": "2026-04-28T10:22:52.942-04:00",
"state": "resolved",
"title": "Elevated Authentication Latency in DUO6",
"updated_at": "2026-04-28T11:26:01.209-04:00",
"url": "https://stspg.io/dn03t2b4zw5t"
},
{
"body": "The SMS delivery issue impacting customers in the US region has been resolved. SMS passcode authentication is now functioning normally.\nWe apologize for any inconvenience caused and thank you for your patience.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-04-18T03:09:46.010-04:00",
"resolved_inferred": false,
"started_at": "2026-04-18T00:30:07.406-04:00",
"state": "resolved",
"title": "SMS Delivery Failures",
"updated_at": "2026-04-18T03:09:46.031-04:00",
"url": "https://stspg.io/kwcmc8m4mhtc"
},
{
"body": "VoIP authentication has returned to normal operation with sustained success rates observed.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-22T22:23:37.639-04:00",
"resolved_inferred": false,
"started_at": "2026-03-22T18:13:19.684-04:00",
"state": "resolved",
"title": "Duo Phone Call Authentication Failure for US Based Carriers",
"updated_at": "2026-03-22T22:23:37.654-04:00",
"url": "https://stspg.io/43mz410cgng5"
},
{
"body": "VoIP authentication has returned to normal operation with sustained success rates observed.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-22T16:33:37.195-04:00",
"resolved_inferred": false,
"started_at": "2026-03-22T13:18:21.000-04:00",
"state": "resolved",
"title": "Duo Phone Call Authentication Failure for US Based Carriers",
"updated_at": "2026-03-22T16:33:37.212-04:00",
"url": "https://stspg.io/gb8nrv3dcbml"
},
{
"body": "The service outage affecting DUO81 has been resolved. \nAll impacted customers have been successfully migrated to an alternative Duo deployment. \nThis migration has restored full service functionality for all affected users.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-03T18:46:57.479-05:00",
"resolved_inferred": false,
"started_at": "2026-03-02T03:30:50.898-05:00",
"state": "resolved",
"title": "Service Outage on DUO81",
"updated_at": "2026-03-03T18:46:57.496-05:00",
"url": "https://stspg.io/gp7rp6359lj0"
},
{
"body": "The issue was resolved by rerouting traffic.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-01T11:39:00.559-05:00",
"resolved_inferred": false,
"started_at": "2026-03-01T08:29:24.094-05:00",
"state": "resolved",
"title": "Service degradation on DUO81",
"updated_at": "2026-03-01T11:39:00.575-05:00",
"url": "https://stspg.io/tpfjfz4nwf7n"
},
{
"body": "# Summary\n\nOn\u00a0February 23, 2026, US-based\u00a0users\u00a0utilizing\u00a0the Duo integration with Azure Identity management experienced\u00a0increased authentication failures\u00a0and timeouts. These errors were occurring specifically when accessing\u00a0applications using Microsoft Entra\u00a0and Duo\u00a0as the MFA provider. Duo engineering\u00a0was alerted to the issues via monitoring\u00a0at 9:15 AM and promptly began investigating various factors that could have caused this error to occur, including checking the health of the different third-party services involved. Finally, the root cause was identified to be\u00a0increased\u00a0CPU usage\u00a0resulting from\u00a0a code change that\u00a0added\u00a0additional\u00a0validation for security operations.\n\nThe incident was remediated by scaling the\u00a0backend services that support this integration.\n\nDuring the incident, updates were posted to the status page as new information became available. At the beginning of the incident, the impact of the issue was underestimated, and thus notifications were not set to go out along with these status updates. When the impact assessment changed, notifications should have been set to go out, but this was missed. Processes have been improved to help prevent this from happening in the future.\n\n# Timeline of Events\n\n| **Time \\(in EST\\) 2/23/2026** | **Event** |\n| --- | --- |\n| 9:15 am | Engineering begins investigating\u00a0AzureAuth\u00a0errors |\n| 9:27\u00a0am\u00a0 | Duo\u00a0begins receiving reports of 504 gateway timeout errors for customers\u00a0accessing\u00a0applications using Microsoft Entra and Duo.\u00a0\u00a0 |\n| 10:02\u00a0am\u00a0\u00a0 | First\u00a0status\u00a0page from Duo is put up\u00a0regarding\u00a0investigating the root cause. This status page is posted without notifications due to\u00a0assumed\u00a0scale of\u00a0incident.\u00a0\u00a0 |\n| 11:10\u00a0am\u00a0 | Duo scales resources for the\u00a0Azureauth\u00a0US\u00a0deployment.\u00a0 |\n| 11:19\u00a0am\u00a0\u00a0 | Errors\u00a0begin to\u00a0subside.\u00a0 |\n| 11:24\u00a0am | The incident is\u00a0moved\u00a0to monitoring.\u00a0 |\n| 11:30\u00a0am\u00a0 | The incident\u00a0is\u00a0resolved.\u00a0 |\n\n# Root Cause\\(s\\)\n\nThe Duo team follows a regular and disciplined release process across all services. Changes are routinely deployed to improve functionality, security posture, and overall reliability.\n\nAll releases undergo comprehensive validation, including:\n\n* Unit testing\n* Integration testing\n* Frontend testing\n* Performance testing\n\nThis layered testing strategy is designed to identify functional defects, regressions, and performance impacts prior to production deployment.\n\nIn the days leading up to the incident, a software update was deployed to the backend service that supports the Duo integration with Azure Identity management. This update was part of a broader security improvement effort. The change successfully passed all standard validation processes and was not expected to introduce downtime or performance degradation.\n\nDuring the Monday morning traffic peak, this backend\u00a0service experienced elevated CPU utilization, resulting in service degradation. The following points all contributed to the service interruption:\n\n* **Increased CPU Utilization Per Request**\n\n    * The deployed change approximately doubled CPU consumption per request within this service.\n    * This materially increased overall compute demand during peak traffic.\n    \n* **Performance Test Coverage Gaps**\n\n    * Existing performance tests did not identify the increased CPU usage introduced by the change.\n    * The specific workload characteristics that amplified CPU consumption under peak conditions were not fully represented in pre-production testing.\n    \n* **Monitoring Gaps**\n\n    * A recent migration of our monitoring services missed CPU monitors for this service, leading to an alerting gap when CPU consumption started trending upward.\n    * Alerts were triggered only after peak load conditions were reached.\n    \n\n# Remediation and Future Work\n\nTo address all the causes for the incident, Duo is committed to doing the following:\n\n* **Addressing increased CPU Utilization per Request**\n\n    * **This backend service has been scaled up \\(Completed\\)**\n    \n        * Additional resources have been added to the infrastructure powering this backend service to provide additional compute headroom.\n        * This ensures sufficient capacity to absorb higher per-request of CPU costs.\n        \n    * **Connection Efficiency Improvements \\(In Progress\\)**\n    \n        * Investigate using persistent connection pooling, and/or caching mechanism to reduce connection overhead and lower per-request for CPU consumption.\n        \n    * **Graceful Degradation Enhancements \\(In Progress\\)**\n    \n        * Improvements being explored to ensure systems degrade gracefully under high CPU load, with the goal of protecting critical authentication flows and reducing user impact during resource saturation events.\n        \n    \n* **Addressing Performance Testing Coverage Gaps**\n\n    * **Expanded Performance Test Coverage \\(In Progress\\)**\n    \n        * Performance testing will be updated to explicitly model this failure scenario.\n        * Peak-load and stress conditions will be more accurately simulated.\n        \n    * **Performance-Based Release Gates \\(In Progress\\)**\n    \n        * Performance tests will become release-gating criteria.\n        * Changes that materially impact resource consumption will be identified before production deployment.\n        \n    \n* **Addressing Monitoring\u00a0Gaps**\n\n    * **Capacity Monitoring\u00a0Enhancement \\(Completed\\)**\n    \n        * Missing capacity monitors \\(inadvertently omitted during a recent migration\\) have been restored.\n        * Monitoring coverage for this service has been expanded.\n        \n    * **Comprehensive Monitoring Audit \\(Completed\\)**\n    \n        * Full audit of all capacity monitors underway to ensure complete monitoring coverage and eliminate similar gaps across services.\n        \n    \n* **Customer Communication Improvements**\n\n    * **Improved Status Page Notifications**\n    \n        * Status page processes have been updated to ensure faster and clearer communication.\n        * Commitment to timely, transparent, and regular updates to all customers during future incidents, with notifications.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-23T12:52:14.082-05:00",
"resolved_inferred": false,
"started_at": "2026-02-23T10:04:40.642-05:00",
"state": "postmortem",
"title": "All Deployments - Entra 504 Gateway Timeouts",
"updated_at": "2026-02-25T10:07:59.212-05:00",
"url": "https://stspg.io/7vb8y4jjt0fy"
},
{
"body": "The issue causing an abnormal phone call authentication success rate has been resolved by the third-party carrier.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-23T13:20:37.122-05:00",
"resolved_inferred": false,
"started_at": "2026-02-23T09:02:53.920-05:00",
"state": "resolved",
"title": "[US Deployments]: Duo Phone Call Authentication Failures for US Region",
"updated_at": "2026-02-23T13:20:37.147-05:00",
"url": "https://stspg.io/fckcy3h0p8jr"
},
{
"body": "The issue causing the AI Assistant to be unavailable for administrators in India has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-19T13:01:56.530-05:00",
"resolved_inferred": false,
"started_at": "2026-02-19T09:46:52.000-05:00",
"state": "resolved",
"title": "[Multiple Deployments] AI Assistant not available in India",
"updated_at": "2026-02-19T13:01:56.549-05:00",
"url": "https://stspg.io/hr2mrj5bgpgv"
},
{
"body": "The deployed fix for this incident has resolved the issue. We will continue to monitor these results.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-19T17:32:33.871-05:00",
"resolved_inferred": false,
"started_at": "2026-02-19T09:35:48.792-05:00",
"state": "resolved",
"title": "[All Deployments] AI Assistant Outage for new users",
"updated_at": "2026-02-19T17:32:33.896-05:00",
"url": "https://stspg.io/d9mrkcydwss0"
},
{
"body": "The issue causing the failures for administrators access of the AI Assistant is now resolved and full functionality is restored.\n\nWe will be posting a root-cause analysis (RCA) here once our engineering team has finished its thorough investigation of the issue.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-18T20:31:11.877-05:00",
"resolved_inferred": false,
"started_at": "2026-02-18T13:28:00.444-05:00",
"state": "resolved",
"title": "[All Deployments] AI Assistant Outage for new users",
"updated_at": "2026-02-18T20:31:11.899-05:00",
"url": "https://stspg.io/x1l174zfxrnd"
},
{
"body": "# **Enrollment Timeout Outage**\n\nIncident Report \u2013 02/04/2026\n\n## Summary\n\nA recent software update Duo made related to certificate security improvements inadvertently changed the order of operations for user sessions in our legacy enrollment experience. This resulted in user sessions not being properly initialized, prompting the system to mistakenly identify these sessions as expired. Affected users were unable to complete enrollment and saw the message: \u201cYour session has expired. Please try again.\u201d The issue only affected enrollment flows using the legacy Traditional Prompt.\u00a0Customers were able to successfully enroll by switching to the Universal Prompt enrollment experience as a workaround.\n\nDuo identified and corrected the issue by ensuring sessions are fully initialized before they are used. The fix was deployed on 2026-02-04, and enrollment is now functioning normally.\n\nDuo has implemented additional safeguards to prevent similar session handling issues in future updates.\n\n## Timeline of Events\n\n**Date/Time \\(in EST\\)**\n\n02/04/2026 03:57AM\u00a0\u00a0- Duo\u00a0receives\u00a0reports that\u00a0customers are unable to complete enrollments\n\n02/04/2026\u00a009:00\u00a0AM\u00a0- Authentication team starts investigating\n\n02/04/2026 10:42 AM\u00a0- Authentication team\u00a0identifies\u00a0root cause\n\n02/04/2026 3:40 PM\u00a0- The fix begins\u00a0rolling\u00a0out to customers\n\n02/04/2026 7:26\u00a0PM\u00a0- The fix finishes rolling out to customers\n\n02/04/2026 7:26 PM\u00a0- Duo confirms that enrollments are\u00a0working as intended",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-04T20:11:56.564-05:00",
"resolved_inferred": false,
"started_at": "2026-02-04T13:55:37.231-05:00",
"state": "postmortem",
"title": "All Deployments: Duo Enrollment URL Session Expired Errors",
"updated_at": "2026-02-10T16:23:19.351-05:00",
"url": "https://stspg.io/bs249142w38z"
},
{
"body": "The issue causing authentication failures on our DUO4 deployment has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-22T15:18:19.234-05:00",
"resolved_inferred": false,
"started_at": "2026-01-22T13:36:01.034-05:00",
"state": "resolved",
"title": "[DUO4] Authentication Failures",
"updated_at": "2026-01-22T15:18:19.252-05:00",
"url": "https://stspg.io/wv8bv5ypbr1y"
},
{
"body": "We have identified the cause of the issue for authentication failures with newly created MSP Sub-accounts on all our deployments and remediation steps have been applied to correct this.  \n\nIf you continue to experience any additional issues related to this, please contact us at https://duo.com/support referencing this incident, (https://status.duo.com/incidents/tymgyq32v7dw).",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-21T18:32:48.954-05:00",
"resolved_inferred": false,
"started_at": "2026-01-21T16:38:23.000-05:00",
"state": "resolved",
"title": "All Deployments: Authentication Failures for Newly Created MSP Sub-Accounts",
"updated_at": "2026-01-21T18:32:48.975-05:00",
"url": "https://stspg.io/nb6y4p5qz2r5"
},
{
"body": "According to our telephony service provider, the issue affecting SMS, Phone Call, and Push delivery has been resolved. Currently our services are now back to normal.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-15T01:16:11.525-05:00",
"resolved_inferred": false,
"started_at": "2026-01-14T14:35:15.147-05:00",
"state": "resolved",
"title": "SMS, Phone Call, Push delivery failures due to ongoing carrier outages",
"updated_at": "2026-01-15T01:16:11.541-05:00",
"url": "https://stspg.io/28p5yghfsf9r"
},
{
"body": "The issue affecting call connectivity between customers and our Support Engineers has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-12-23T03:59:45.791-05:00",
"resolved_inferred": false,
"started_at": "2025-12-23T02:35:54.490-05:00",
"state": "resolved",
"title": "Duo Support Phone System Issue",
"updated_at": "2025-12-23T03:59:45.809-05:00",
"url": "https://stspg.io/cz4544pm3tyt"
},
{
"body": "The issue affecting Duo Trial signups has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-12-19T16:03:06.987-05:00",
"resolved_inferred": false,
"started_at": "2025-12-19T12:59:32.563-05:00",
"state": "resolved",
"title": "New Duo Trial Signup Failures",
"updated_at": "2025-12-19T16:03:07.001-05:00",
"url": "https://stspg.io/thvf5xvz17gq"
},
{
"body": "The issue affecting phone-based authentication and SMS delivery has now been resolved. System performance has remained stable, and all services are operating as expected across deployments.\nWe will continue to monitor for any anomalies, but no further impact is anticipated at this time.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-20T07:06:57.553-04:00",
"resolved_inferred": false,
"started_at": "2025-10-20T04:28:57.666-04:00",
"state": "resolved",
"title": "All Deployments: Duo Phone Call and SMS Delivery Failure",
"updated_at": "2025-10-20T07:06:57.590-04:00",
"url": "https://stspg.io/6n75c2qyq7lj"
},
{
"body": "The issue affecting email delivery has been resolved. System performance has remained stable, and all services are functioning normally across deployments.\nWe\u2019ll continue to monitor to ensure ongoing reliability. Thank you for your patience throughout this incident.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-20T07:20:52.969-04:00",
"resolved_inferred": false,
"started_at": "2025-10-20T03:54:46.733-04:00",
"state": "resolved",
"title": "All Deployments: Email delivery issues",
"updated_at": "2025-10-20T07:20:52.992-04:00",
"url": "https://stspg.io/3qn5hhxphry7"
},
{
"body": "We have identified an issue with a recent Windows update that has caused Duo Desktop to not be recognized on Windows 11 24H2 and 25H2 and have provided remediation steps in a Knowledge Base article linked below.\n\nWhile we work with Microsoft to ensure a permanent solution is provided via update, we will be marking this incident resolved and providing further updates through the KB article as well as via email communications.\n\nWhy is Duo Desktop not detected on my Windows device after installing updates to Windows 11?\nhttps://help.duo.com/s/article/9527\n\nPlease check the KB article for any further updates.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-15T16:01:02.605-04:00",
"resolved_inferred": false,
"started_at": "2025-10-15T08:19:13.850-04:00",
"state": "resolved",
"title": "[All Deployments] Duo Desktop not being recognized on Windows 11 24H2/25H2",
"updated_at": "2025-10-15T16:01:02.634-04:00",
"url": "https://stspg.io/mj2k66xr7vzf"
},
{
"body": "# **DUO34 Deployment Outage**\u00a0\n\n## Incident Report \u2013 10/7/2025\u00a0\n\n### Summary\u00a0\n\nOn October 7, 2025, between 2:40pm EDT and 3:40pm EDT, all services on Duo 34 were unavailable. This was due to a misconfiguration in our edge load balancer which stopped all traffic to that deployment. Duo engineering promptly fixed the misconfiguration and have fixed the underlying cause, to ensure our systems are more resilient.\u00a0\n\n### Details\u00a0\n\nDuo\u2019s application platform has two parts to manage our services. One-part handles creating the network setup, and the other controls how traffic reaches running services. A service disruption occurred because of a misalignment between these two key systems. Even though the network was set up correctly, changes were not reflected in the traffic routing settings. This caused traffic to stop reaching the services, resulting in the outage.\u00a0\u00a0\u00a0\n\nTo restore service, a manual fix was put in place to connect these network servers with the right settings. As a long-term solution, we have updated the system settings to point to the right destinations. This will ensure that the misalignment will not happen again. To avoid this problem in the future, we're reviewing how we manage system configurations, improving our setup process to avoid local files, and adding checks to stop changes that could cause similar issues.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-10-07T15:56:22.869-04:00",
"resolved_inferred": false,
"started_at": "2025-10-07T15:13:20.610-04:00",
"state": "postmortem",
"title": "[DUO34] Full Deployment Outage",
"updated_at": "2025-10-09T10:05:12.099-04:00",
"url": "https://stspg.io/wq4v1sjz9rl4"
},
{
"body": "This incident has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-09-29T12:52:53.610-04:00",
"resolved_inferred": false,
"started_at": "2025-09-29T05:46:36.025-04:00",
"state": "resolved",
"title": "[All Deployments] Entra ID Failing to Sync Custom Attributes",
"updated_at": "2025-09-29T13:28:21.125-04:00",
"url": "https://stspg.io/dwbztn8sr1j9"
},
{
"body": "We have confirmed the issue is now fully resolved.  An RCA will be provided as soon as it is available.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-09-26T18:41:14.108-04:00",
"resolved_inferred": false,
"started_at": "2025-09-26T10:54:19.979-04:00",
"state": "resolved",
"title": "[Multiple Deployments] Administrators unable to access the Duo AI Assistant for the first time",
"updated_at": "2025-09-26T18:41:14.124-04:00",
"url": "https://stspg.io/kcxpl067ddrf"
},
{
"body": "### Summary\n\nOn September 9, 2025, between approximately 12:10 pm ET and 12:40 pm ET, some multi-tenant administrators were unable to access the admin panel or use accounts API due to a configuration change that inadvertently disrupted traffic requests. \n\nDuo engineering promptly reverted the change to restore service and resolve the issue.\n\n### Details\n\nOn September 9, Duo engineering executed a planned integration of two services related to the admin panel and billing. This integration aimed to reduce database load and address infrequent internal errors. Although the change was tested in lower environments, it was incompatible with the production region it targeted, causing issues when deployed in production.\n\nDuo engineering promptly began reverting the change to address the errors and minimize customer impact. On the same day, the team implemented a fix to resolve the configuration incompatibilities.\n\nMoving forward, Duo is enhancing our testing processes to identify incompatibilities before implementing approved changes and to reduce downtime for our customers. \n\nWe apologize for any disruption this may have caused.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-09-09T13:09:28.771-04:00",
"resolved_inferred": false,
"started_at": "2025-09-09T12:43:58.221-04:00",
"state": "postmortem",
"title": "[Multiple Deployments] Admin Panel Login Failures",
"updated_at": "2025-09-10T17:31:21.946-04:00",
"url": "https://stspg.io/stlp3mmx91fl"
},
{
"body": "### Summary\n\nAn apparent defect in v136 of Chromium-based browsers \\(such as Google Chrome and Microsoft Edge\\) caused newly added code in Duo\u2019s web-based prompt, when interacting with Duo Desktop, to freeze or crash the browser tab. The issue was specific to version 136; all other versions did not exhibit the problem.\u00a0Duo has deployed a fix to ensure this behavior is not present in these versions.\n\n### Timeline of Events\n\n* 8/29/2025 1:25am EST - Duo engineering is alerted of a customer reporting the issue \n* 8/29/2025 1:22pm EST - Incident created \n* 8/29/2025 9:35pm EST - Started deploying the update to fix the issue \n* 8/29/2025 11:36pm EST - Finished deploying the update to fix the issue \n* 8/30/2025 12:07am EST - Status page is updated to monitoring \n* 8/30/2025 1:02am EST - Status page is updated to resolved \n\n### Details\n\nUpdates were added to D322 to check whether the Chrome Local Network Access permission setting was enabled in the browser being used to authenticate. The Local Network Access permission is being added to Chromium-based browsers in v141, and changes were added to improve the user experience if the Local Network Access permission is not enabled. More details can be found in [this Duo Knowledge Base article](https://help.duo.com/s/article/9470?language=en_US). In v136 of Chromium-based browsers, the change that was added to check the Local Network Access permission caused the browser to freeze or crash.\n\nTo resolve this issue, Duo added a change to not check the Chrome Local Network Access permission if v136 of a Chromium based browser is being used. Since the Chrome Local Network Access permission is being released in v141, this change did not have any negative impact.\n\nDuo will explore adding additional testing and alerting for issues like this one, where only specific browser versions are impacted by an issue.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-08-30T01:03:18.274-04:00",
"resolved_inferred": false,
"started_at": "2025-08-29T13:30:46.812-04:00",
"state": "postmortem",
"title": "Blank Duo Prompt issue impacting users authenticating from both Chrome and Edge version 136 browsers and Epic Hyperdrive",
"updated_at": "2025-09-03T11:12:07.346-04:00",
"url": "https://stspg.io/rvtbcm6c9c51"
},
{
"body": "The issue affecting updates or changes made to users in the Admin Panel on selected deployments has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-08-26T10:58:15.158-04:00",
"resolved_inferred": false,
"started_at": "2025-08-26T10:43:14.476-04:00",
"state": "resolved",
"title": "[Multiple Deployments] - Issues with User Management in Admin Panel",
"updated_at": "2025-08-26T10:58:15.174-04:00",
"url": "https://stspg.io/6c6k2vpm7fh7"
},
{
"body": "**Summary**\n\nA change in the D322 build triggered high database load by calling an unoptimized query. This resulted in disruptions across several deployments. The system was stabilized after recovery actions.\n\n**Timeline of Events**\n\n08/26/2025 06:47:00 UTC\u00a0- Alert fires that our service latency is above target.\u00a0\n\n08/26/2025 06:58:00 UTC\u00a0- On-call engineer confirms that autoscaling is in progress.\u00a0\n\n08/26/2025 07:00:00 UTC\u00a0- Separate alert fires that our service database CPU utilization is high, and requests backlog starts to grow.\u00a0\n\n08/26/2025 07:37:00 UTC\u00a0- On-call engineer disables certain features of our service to alleviate load.\u00a0\n\n08/26/2025 08:08:00 UTC\u00a0- Status page is published.\u00a0\n\n08/26/2025 08:45:00 UTC\u00a0- Service database is scaled up.\u00a0\n\n08/26/2025 08:50:00 UTC\u00a0- On-call engineer monitors recovery of systems.\n\n08/26/2025 10:40:00 UTC\u00a0- All features of our service are reenabled.\u00a0\n\n08/26/2025 11:44:00 UTC\u00a0- Status page is updated to resolved.\u00a0\n\n**Details**\n\nOur D322 build started calling an unoptimized API endpoint on an internal system which led to high database load, latency and request timeouts. This degraded multiple deployments \\(DUO3, DUO47, DUO57\\).\n\n\u200c\n\nTo alleviate load,\u00a0certain features were\u00a0disabled temporarily. However, because Duo Directory depends on this feature, customers received errors until it was re-enabled. At the same time, the database was scaled up vertically to allow for quicker processing of backlogged requests.\n\n\u200c\n\nOnce the backlog was cleared, all features were reenabled and the incident was resolved.\n\n\u200c\n\nDeep analysis was conducted to determine why the service database CPU utilization was higher than expected. A newly introduced unoptimized query was found and fixed promptly.\n\n\u200c\n\nFurthermore, our teams have plans to implement more rigorous testing and review processes for new database queries that are added to our services.\n\n\u200c\n\nAlso, our teams will work to improve our performance testing capabilities in the development environment to allow more accurate simulation of production load. This will aid us in being able to better detect unoptimized queries before they are released.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-08-26T07:43:56.719-04:00",
"resolved_inferred": false,
"started_at": "2025-08-26T04:08:34.011-04:00",
"state": "postmortem",
"title": "Admin functions impacted when accessing Users and AD Sync on certain deployments",
"updated_at": "2025-08-29T14:54:40.848-04:00",
"url": "https://stspg.io/vh6fl25kmcxq"
},
{
"body": "Duo has confirmed that the issue affecting SMS delivery to phone numbers using T-Mobile services in the US has been fully resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-08-26T06:21:54.554-04:00",
"resolved_inferred": false,
"started_at": "2025-08-26T02:29:19.196-04:00",
"state": "resolved",
"title": "T-Mobile Services SMS Delivery Issue",
"updated_at": "2025-08-26T06:21:54.573-04:00",
"url": "https://stspg.io/pfdh9qcjvsdv"
},
{
"body": "Duo has confirmed that the phone call authentication failures affecting all deployments in India have been fully resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-08-18T11:27:48.356-04:00",
"resolved_inferred": false,
"started_at": "2025-08-18T07:25:26.804-04:00",
"state": "resolved",
"title": "India VoIP Failures",
"updated_at": "2025-08-18T11:27:48.384-04:00",
"url": "https://stspg.io/h6z45mpt5w92"
}
]
}