Skip to main content
Ben Test PennKey Banner

See below for highlights of the IAM security initiatives for calendar year 2026 (last updated 4/30/26). All IAM initiatives are available on the IAM program dashboard.

Date Project/EnhancementDescription
1/27/26
Complete
Two-Step Security Enhancements - System ConfigurationEnable Instant Restore, adjust callback keys, passcode expirations, etc.
3/31/26
Complete
Duo Discontinues Older App SupportDuo requires a minimum Duo Mobile app version of 4.85 or greater
4/15/26
Complete
Duo Discontinues Older Mobile OS SupportDuo ends support for older mobile operating systems, including iOS 16 and Android 11.
6/2/26MFA Requirement for Research (RES) AffiliationAll research personnel required to use Two-Step to access PennKey-protected resources
Spring-Summer 2026Phishing-Resistant MFA Best PracticesInfo-sharing, procedures, and strategies for adopting phishing-resistant MFA
Spring-Summer 2026Passwordless Limited PilotInternal ISC pilot to refine passwordless strategy for WebLogin SSO
PlanningTwo-Step Security Enhancements - Discontinue Least Secure MethodsDiscontinue least secure Two-Step Verification/Duo methods - HOTP, SMS, Phone
PlanningSSO for High-Risk AppsIncrease adoption of WebLogin SSO for apps that present higher risk if compromised
PlanningFront Door Auth for High-Risk AppsIncrease adoption of Front Door Authorization for apps that present higher risk if compromised