UITS will introduce Duo Universal Prompt. This new look and functionality for Duo will make logging in to IU systems simpler and more secure by prompting you to use the most secure option, or the last-used authentication method.When you first log-in to a fresh browser session, the Universal Prompt displays the most secure authentication method for the account. If you select a different option than the recommendation, Universal Prompt will remember your last-used authentication method and display that option by default for that browser.
You can see a visual comparison of what’s changing at Upcoming – About Duo Universal Prompt.
Additionally, UITS will remove phone call and SMS functions for logging into Duo. This change responds to an increase in phishing attacks targeting SMS and telephony, aligns IU with best practice recommendations in cybersecurity, and responds to the increase in associated costs. More than 80% of authentications in the past 60 days have been via Duo push, token, or other non-telephony methods. These will not be affected by the change.
We are working on an exception request form which should be available for users who are not able to use another authentication method. Reviews will be based on use-case and evaluated by the Identity Management Systems team.
Users will be notified through an IT News Article on May 23, as well as an email communication to all Duo users sometime next week.